HomeSecurityFamousSparrow hackers distribute SparrowDoor & ShadowPad backdoors

FamousSparrow hackers distribute SparrowDoor & ShadowPad backdoors

Chinese hackers FamousSparrow were linked to cyberattacks against an organization in the United States and a research institute in Mexico, with the aim of distributing the SparrowDoor and ShadowPad backdoors.

FamousSparrow Chinese hackers SparrowDoor & ShadowPad backdoor

The malicious activity, observed in July 2024, was also reportedly the first time the group deployed ShadowPad, a malware used by various Chinese groups.

Additionally, according researchers ESET, Chinese hackers FamousSparrow developed two previously unknown versions of the SparrowDoor backdoor (one of which is modular). These two versions of the malware appear to be more sophisticated to allow for more effective attacks.

See also: Betruger: RansomHub ransomware group uses new backdoor

The FamousSparrow group was first documented by cybersecurity firm ESET in September 2021. The group had been linked to a series of attacks targeting hotels, governments, engineering firms, and law firms. The attacks used the SparrowDoor backdoor (used exclusively by the group).

Although there have been reports of similarities between the FamousSparrow hackers and other groups (such as Earth Estries, GhostEmperor, and Salt Typhoon), ESET treats FamousSparrow as a separate group with some loose ties to Earth Estries.

How do Chinese hackers attack FamousSparrow?

The attackers deploy a web shell to an Internet Information Services (IIS) server, although we don't know exactly how they do this. Both victims (in the US and Mexico) are said to be running old versions of Windows Server and Microsoft Exchange Server.

The web shell acts as a conduit for delivering a batch script from a remote server. This in turn launches a Base64-encoded .NET web shell embedded within it. It is this web shell that deploys the SparrowDoor and ShadowPad backdoors.

ESET said that one of the SparrowDoor versions resembles Crowdoor, but both versions have significant improvements over their predecessor (e.g., the ability to execute time-consuming commands simultaneously, which allows the backdoor to process incoming commands while they are being executed).

See also: Lotus Panda targets governments with Sagerunex backdoor

“When the backdoor receives one of these commands, it creates a thread that starts a new connection to the C&C server,” said security researcher Alexandre Côté Cyr. “The unique victim identifier is then sent over the new connection, along with a command identifier indicating the command that led to this new connection.”

This way, the C&C server keeps track of which connections are related to the same victim and what their purposes are.

The SparrowDoor backdoor, used by Chinese hackers FamousSparrow, has a wide range of commands that allow it to activate a proxy, launch interactive shell sessions, perform file operations, inspect the file system, collect host information, and even uninstall itself.

FamousSparrow hackers distribute SparrowDoor & ShadowPad backdoors

In contrast, the second version of the backdoor is modular, adopting a plugin-based approach to implementing its goals. It supports up to nine different modules:

  • Cmd – Execute a single command
  • CFile – Perform file system operations
  • CKeylogPlug – Keystroke logging
  • CSocket – Starting a TCP proxy
  • CShell – Start an interactive shell session
  • CTransf – Initiate file transfer between the compromised Windows host and the C&C server
  • CRdp – Take screenshots
  • CPro – Recording running processes and stopping some processes
  • CFileMoniter – Monitor file system changes for specified directories

Backdoor protection 

Organizations can protect their networks from backdoors by implementing various security. First, it is important to keep their systems up to date. This means they should regularly install the latest updates and security patches on all operating systems and applications.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Additionally, organizations should use security solutions that include intrusion detection and malware protection. These solutions can help detect and prevent attacks.

See also: Iranian hackers target UAE aviation sector with Golang backdoor

Staff training is also critical to avoiding backdoors. Employees need to be aware of the risks associated with cybersecurity  and the tactics used by attackers, such as phishing .

Finally, the principle of least access should be applied . This means that users and devices should only have the necessary access permissions they need to perform their tasks.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS