Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory

Scripted Sparrow

Also known asscripted_sparrow

Scripted Sparrow is a newly identified, prolific Business Email Compromise (BEC) threat group. Fortra tracked the group from June 2024 through December 2025 and described it as one of the most active BEC collectives currently operating. The group runs large-scale, highly targeted phishing and fraud campaigns, with reporting indicating it sends millions of scam emails per month and operates across three continents. Scripted Sparrow primarily targets finance and Accounts Payable personnel, including organizations in North America and Europe, by impersonating executive coaching, leadership training, and other professional services consultancies. Its campaigns use well-crafted social engineering rather than malware or credential theft. Common tactics include spoofed or forged reply chains, lookalike domains, fabricated executive approvals, and PDF attachments containing fraudulent invoices and W-9 forms. The invoices often reference fictitious entities such as Catalyst Executive Circle and are crafted just under common approval thresholds, including examples at $49,927.00, to increase the likelihood of payment. The group is notable for industrialized, automated operations at global scale. Reported tradecraft includes sending messages in small targeted batches, reusing templates with minor variations, rotating domains and bank accounts, and adapting lures over time, including missing-attachment prompts intended to bypass security filters. Fortra linked the operation to large supporting infrastructure, including domains, webmail accounts, and bank accounts, and reported that the group continually refines its fraud techniques. Technical observations in the reporting include heavy use of PDF generation via the Skia/PDF library, automated scripting to manage correspondence volume, geolocation-spoofing browser plug-ins, and indications of Telegram use for internal communication. The activity described in the reporting is financially motivated cybercrime focused on inducing wire transfers to fraud-controlled accounts. The content does not provide a confirmed nation-state attribution. Reported possible operator locations include Nigeria, South Africa, Iran, Turkey, and possibly the United States, United Kingdom, and Canada, but these are presented as attribution suggestions rather than confirmed facts. No additional aliases or sub-groups are provided in the content beyond the name Scripted Sparrow.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

2 of 15 tactics4 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
1 technique
T1585
Establish Accounts
T1585.002
Email Accounts
TA0001
Initial Access
1 technique
T1566
Phishing
T1566.001
Spearphishing Attachment
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping4

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.

Scripted Sparrow | Mallory