SparrowDoor is a Windows backdoor associated with the China-aligned cyberespionage group FamousSparrow, also tracked as TAG-141. It enables remote control and intelligence collection from compromised systems. Its operators have targeted hotels, governments, international organizations, engineering companies, law firms, research institutions, and financial-sector organizations worldwide, including victims in the United States and Latin America. Documented deployments followed exploitation of internet-facing applications, notably Microsoft Exchange through the ProxyLogon vulnerability chain.
SparrowDoor is deployed through loaders that use DLL side-loading or DLL search-order hijacking with legitimate executables. It establishes persistence through Windows services or registry-based autostart entries. Observed versions use encrypted configuration or payload data, and later variants employ reflective loading and process hollowing. The backdoor communicates with command-and-control infrastructure over TLS, supports proxy connections, and reports host and user information before receiving commands. Its capabilities include interactive reverse-shell access, file upload and exfiltration, file and directory manipulation, process termination, and system enumeration. It can enable debug privileges through access-token adjustment and provides an uninstall command that removes its persistence and associated files.
Variants identified during investigations of 2024 intrusions introduced substantial architectural changes, including parallelized command handling and a modular implementation using in-memory plugins. SparrowDoor has also been used to deploy additional backdoors, including ShadowPad and SparroWocky. Beginning in August 2025, the distinct SparroWocky family rapidly replaced SparrowDoor as FamousSparrow's primary implant.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
According to ESET telemetry, FamousSparrow started to exploit the vulnerabilities the day following Microsoft’s release of a patch for the problem. In FamousSparrow’s case, it used the bug to deploy SparrowDoor. | FamousSparrow targets hotels, governments and private organizations around the world with a custom backdoor called “SparrowDoor.”
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FamousSparrow targets hotels, governments and private organizations around the world with a custom backdoor called “SparrowDoor.”
Chinese state-sponsored group TAG-141 (FamousSparrow) deployed SparrowDoor malware against Mexico's Universidad Nacional Autónoma in early 2025
This attack chain was attempting to load the Crowdoor loader, which is half-named after the SparrowDoor backdoor, detailed by ESET... Also, the command-line argument “2” found in a variant related to Tropic Trooper samples is very similar to SparrowDoor “-k” switch functionality.
CrowDoor is a variant of SparrowDoor, another backdoor attributed to FamousSparrow.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
Listed in both FamousSparrow ATT&CK matrices. | Listed in both FamousSparrow ATT&CK matrices; the content identifies FamousSparrow C2/download infrastructure.
Listed in the SparroWocky and FamousSparrow ATT&CK tables. | Listed in the MITRE ATT&CK tables for SparroWocky and FamousSparrow.
ESET's experts found that the China-aligned cyberespionage outfit has hit its targets with two previously undocumented versions of their flagship backdoor called SparrowDoor. Importantly, the group was also observed using the ShadowPad backdoor for the first time.
When executed with the argument 11 , the backdoor launches the Windows color management tool ( colorcpl.exe ) with a command line argument of 22 and injects its loader into the newly created process.
Table 1. Command line arguments for SparrowDoor Argument Behavior ... 11 Process hollowing of colorcpl.exe .
Listed in the older FamousSparrow ATT&CK matrix; the artifact list includes encrypted shellcode and decrypted shellcode.
Listed in the later FamousSparrow ATT&CK matrix. | Listed in the 2024 FamousSparrow ATT&CK matrix.
Listed in the SparroWocky and 2024 FamousSparrow ATT&CK tables. | Listed in the ATT&CK matrices for SparroWocky and FamousSparrow.
Listed in the 2024 FamousSparrow ATT&CK matrix; artifacts include names such as WindowsUpdate.exe and taskhosk.exe. | Listed in the later FamousSparrow ATT&CK matrix.
When executed with the argument 11 , the backdoor launches the Windows color management tool ( colorcpl.exe ) with a command line argument of 22 and injects its loader into the newly created process.
Table 1. Command line arguments for SparrowDoor Argument Behavior ... 11 Process hollowing of colorcpl.exe .
Listed in the SparroWocky and 2024 FamousSparrow ATT&CK tables. | Listed in the ATT&CK matrices for SparroWocky and FamousSparrow.
Listed in the ATT&CK matrices for SparroWocky and FamousSparrow. | Listed in the SparroWocky and 2024 FamousSparrow ATT&CK tables.
Listed in the SparroWocky and 2024 FamousSparrow ATT&CK tables; the older FamousSparrow artifacts include encrypted and decrypted shellcode. | Listed in the ATT&CK matrices for SparroWocky and FamousSparrow.
MITRE ATT&CK techniques ... SparrowDoor launches the process into which it injects the loader, with its window hidden.
Listed in the ATT&CK matrices for SparroWocky and FamousSparrow.
Listed in all three ATT&CK technique tables. | Listed in all three ATT&CK matrices.
The resulting plaintext is the C&C server configuration, which consists of three pairs of addresses and ports... After loading this configuration, the backdoor will try to connect to the first server... then the next server, and so on.
Listed in both FamousSparrow ATT&CK matrices; C2 and download servers are identified for FamousSparrow, SparrowDoor, and ShadowPad. | Listed in both FamousSparrow ATT&CK matrices.
Listed in the SparroWocky and 2024 FamousSparrow ATT&CK tables. | Listed in the ATT&CK matrices for SparroWocky and FamousSparrow.
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom FamousSparrow backdoor and the group's historical signature malware. The content states that FamousSparrow is its only known user and that it was superseded as the primary implant by SparroWocky.
An older FamousSparrow backdoor implant that SparroWocky replaced as the group's principal implant. The content states that it shared some functionality and concepts with SparroWocky, but does not provide further technical detail.
A backdoor exclusive to FamousSparrow that was used to initially deploy SparroWocky; SparroWocky is described as its replacement.
FamousSparrow's prior long-running implant, used to deliver early SparroWocky infections. The content distinguishes SparroWocky as a separate malware family rather than a SparrowDoor variant.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.