GhostEmperor__2021__FamousSparrow_A_suspicious_hotel_guest_WeLiveSecurity.pdf
ID: c3f4bd30-a44d-49b7-8b91-daaa2f62f28d
STIX ID: report--c3f4bd30-a44d-49b7-8b91-daaa2f62f28d
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2021-09-27
Last Modified Date: 2021-09-27
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET researchers uncovered FamousSparrow, an espionage-focused APT active since at least 2019 that targets hotels and other organizations worldwide; the report details how the group exploited public-facing application vulnerabilities (including Microsoft Exchange ProxyLogon, SharePoint, and Oracle Opera) to deploy a custom backdoor called SparrowDoor via DLL search-order hijacking, explains its encrypted shellcode, C2 protocol and commands, lists IoCs and sample hashes, and maps observed behaviors to MITRE ATT&CK techniques.
