Famous Sparrow is a China-nexus advanced persistent threat group active since at least 2019 and associated with cyberespionage operations. The group has historically targeted hotels, governments, international organizations, law firms, and more recently telecommunications providers, including critical telecom infrastructure in South America. Cisco Talos has assessed with high confidence that the cluster it tracks as UAT-9244 is closely associated with Famous Sparrow, and reporting also notes overlap with Tropic Trooper. Famous Sparrow is associated with the SparrowDoor malware lineage, and newer activity linked to the group includes CrowDoor-derived tooling and the TernDoor Windows backdoor. Observed tradecraft includes DLL side-loading, in-memory payload execution, process injection into legitimate Windows processes, persistence via scheduled tasks and autorun mechanisms, and use of a malicious driver to suspend or terminate processes for defense evasion. TernDoor supports remote command execution, system information collection, and file manipulation. Linux and embedded-device targeting associated with the same activity includes the PeerTime backdoor, a multi-architecture ELF implant capable of operating on servers, routers, and other telecommunications-relevant systems. PeerTime uses BitTorrent-based peer communications for instruction retrieval and payload delivery, helping obscure attacker infrastructure and complicate detection. Associated operations also used BruteEntry, a Go-based scanner and credential brute-forcing utility that probes exposed services and can turn compromised edge devices into operational relay boxes for mass scanning and access expansion. Taken together, the group’s known operations indicate a focus on long-term persistent access, credential acquisition, and post-compromise control of strategically valuable networks for intelligence collection. Known associated designations and overlaps include UAT-9244, with tooling lineage tied to SparrowDoor and CrowDoor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an associated China-nexus APT actor linked to UAT-9244 activity.
Suspected Chinese APT compromising telecommunications infrastructure across South America using new tooling and backdoors for Windows and Linux.
China-linked espionage actor assessed as overlapping with UAT-9244; historically targets hotels, governments, international organizations, and law firms, and is linked in this reporting via malware lineage (SparrowDoor -> CrowDoor -> TernDoor).
China-linked cyberespionage group active since at least 2019; referenced here as overlapping with UAT-9244 and historically associated with SparrowDoor lineage (via CrowDoor/TernDoor).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.