logo

GhostEmperor__2021__FamousSparrow_A_suspicious_hotel_guest_WeLiveSecurity.pdf

ID: c3f4bd30-a44d-49b7-8b91-daaa2f62f28d

STIX ID: report--c3f4bd30-a44d-49b7-8b91-daaa2f62f28d

Threat Score

85/100

Uploaded: 2026-08-15

Published Date: 2021-09-27

Last Modified Date: 2021-09-27

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET researchers uncovered FamousSparrow, an espionage-focused APT active since at least 2019 that targets hotels and other organizations worldwide; the report details how the group exploited public-facing application vulnerabilities (including Microsoft Exchange ProxyLogon, SharePoint, and Oracle Opera) to deploy a custom backdoor called SparrowDoor via DLL search-order hijacking, explains its encrypted shellcode, C2 protocol and commands, lists IoCs and sample hashes, and maps observed behaviors to MITRE ATT&CK techniques.