New SparrowDoor variants: Targeting attacks on organizations in the United States and Mexico

New SparrowDoor variants: Targeting attacks on organizations in the United States and Mexico

The Chinese cyber-espionage group known as FamousSparrow It has recently been linked to a series of cyberattacks targeting a trade association in the United States and a research institute in Mexico. These attacks, observed in July 2024, involved the use of two new variants of the malware. SparrowDoor, including a modular version, and the adoption for the first time of ShadowPad, a malware widely used by Chinese state-sponsored actors.

SparrowDoor's Capabilities Evolution

The new SparrowDoor variants represent a significant improvement over previous versions. One of the updated versions features command parallelization capabilities, allowing operations such as file I/O and the launch of interactive shells to be performed simultaneously. This approach improves the malware's efficiency by allowing it to handle multiple instructions simultaneously.

The second variant introduces a modular architecture, with nine distinct plugins offering advanced functionality, including:

  • Running single commands
  • File system operations
  • Keystroke recording (keylogging)
  • Starting TCP Proxy
  • Interactive shell sessions
  • File transfer between the compromised host and the command and control (C&C) server
  • Screenshot capture
  • Managing running processes
  • Tracking changes in the file system

Attack chain and infection vectors

The attacks exploited vulnerabilities in servers Internet Information Services (IIS), where a web shell was installed. This acted as a vector to download a batch script from a remote server, which then launched a Base64-encoded .NET web shell. This ultimately distributed variants of SparrowDoor and ShadowPad.

The affected organizations were using outdated versions of Windows Server And Microsoft Exchange Server, highlighting the importance of keeping systems up to date to prevent such intrusions.

Implications and recommendations

FamousSparrow's adoption of ShadowPad indicates a possible evolution in the group's tactics, with increased tool sharing among various Chinese state-sponsored actors. SparrowDoor's new capabilities, particularly its modular architecture, increase the malware's flexibility and dangerousness.

It is critical that organizations take proactive measures to protect their infrastructure:

  • Regularly update operating systems and applications to fix known vulnerabilities.
  • Implement advanced security solutions to monitor and detect suspicious activity.
  • Conduct periodic security audits to identify and mitigate potential risks

For further details, please consult the original article on The Hacker News

Leonardo Network Contacts

Do you need advice? A quote? Simple information? Call us at 0566 196 63 59 or fill out the contact form. We'll get back to you as soon as possible.

Share on...