ZeroHour
Cyber Security Newspublished ()ingested Tushar Subhra Dutta
Part of a story covered by 3 sources: “China-linked FamousSparrow swaps SparrowDoor for new SparroWocky backdoor in Latin American government espionage” — merged summary and timeline →

FamousSparrow Exploits Public-Facing Exchange Servers to Deploy SparroWocky Backdoor

highThreat actor exploited in the wildimportance 78
AI summary · glm-5.3-flash

ESET attributes a new SparroWocky backdoor to espionage group FamousSparrow, deployed via exploited internet-facing Exchange servers across Latin American governments.

ESET's Welivesecurity team reports FamousSparrow gained initial access by exploiting publicly reachable Microsoft Exchange servers, with roughly 90 percent of targets since mid-2025 in Latin America, including governments in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The group's new modular C-language backdoor SparroWocky replaces SparrowDoor and uses a three-part loader: a legitimate executable, a malicious DLL side-loaded in memory, and an encrypted payload. It persists via Windows services or Registry Run keys, supports screenshots, file operations, TCP proxying, Beacon Object Files, TLS/RC4-encrypted C2, and anti-forensics such as call-stack spoofing. IOCs including loader SHA-1 hashes and C2 IP addresses were published.

  • FamousSparrow active since at least 2019, previously tied to ProxyLogon exploitation
  • SparroWocky replaces SparrowDoor as the group's main implant since August 2025
  • Three-part loader uses DLL side-loading and maps the backdoor directly into memory
  • Backdoor spoofes call stacks and hides thread starts to evade detection
  • ESET published SHA-1 hashes and C2 infrastructure indicators

Indicators of compromiseAll →

TypeIndicatorContext
ipv4130.94.101.82control infrastructure, first seen June 17, 2026 IP address 130.94.101.82 SparroWocky command-and-control infrastructure, first seen
ipv4140.99.164.199rol infrastructure, first seen February 26, 2026 IP address 140.99.164.199 SparroWocky command-and-control infrastructure, first seen
ipv4149.104.87.228rol infrastructure, first seen February 26, 2026 IP address 149.104.87.228 SparroWocky command-and-control infrastructure, first seen
ipv4149.104.90.203rol infrastructure, first seen February 24, 2026 IP address 149.104.90.203 SparroWocky command-and-control infrastructure, first seen
ipv4216.238.105.53rol infrastructure, first seen February 25, 2026 IP address 216.238.105.53 SparroWocky command-and-control infrastructure, first seen
ipv4216.238.110.120trol infrastructure, first seen January 22, 2026 IP address 216.238.110.120 SparroWocky command-and-control infrastructure, first seen
ipv4216.238.121.164rol infrastructure, first seen December 11, 2025 IP address 216.238.121.164 SparroWocky command-and-control infrastructure, first seen
ipv4216.238.92.2trol infrastructure, first seen January 22, 2026 IP address 216.238.92.2 SparroWocky command-and-control infrastructure, first seen
ipv438.54.57.1780CA9DDC8C In-memory SparroWocky backdoor sample IP address 38.54.57.17 SparroWocky command-and-control infrastructure, first seen
ipv438.60.197.55rol infrastructure, first seen February 25, 2026 IP address 38.60.197.55 SparroWocky command-and-control infrastructure, first seen
ipv438.60.209.106ontrol infrastructure, first seen March 16, 2026 IP address 38.60.209.106 SparroWocky command-and-control infrastructure, first seen
ipv438.60.224.235rol infrastructure, first seen February 25, 2026 IP address 38.60.224.235 SparroWocky command-and-control infrastructure, first seen
ipv438.60.224.51rol infrastructure, first seen February 26, 2026 IP address 38.60.224.51 SparroWocky command-and-control infrastructure, first seen
ipv438.60.241.127ontrol infrastructure, first seen March 10, 2026 IP address 38.60.241.127 SparroWocky command-and-control infrastructure, first seen
ipv438.60.241.193control infrastructure, first seen March 4, 2026 IP address 38.60.241.193 SparroWocky command-and-control infrastructure, first seen
ipv438.60.241.65rol infrastructure, first seen February 24, 2026 IP address 38.60.241.65 SparroWocky command-and-control infrastructure, first seen
ipv477.111.101.40trol infrastructure, first seen January 22, 2026 IP address 77.111.101.40 SparroWocky command-and-control infrastructure, first seen
ipv491.148.134.115-control infrastructure, first seen May 20, 2026 IP address 91.148.134.115 SparroWocky command-and-control infrastructure, first seen
sha13209689e509205ccdb7e49062b7b407ddc23cac1ors of compromise (IoCs):- Type Indicator Description SHA-1 3209689E509205CCDB7E49062B7B407DDC23CAC1 winfsp-x64.dll , detected as SparroWocky loader SHA-1 52C66
sha144f0a22b143b79fa760bf31e14c8fff714c8a2a1CB385E91F DukeQt.dll , detected as SparroWocky loader SHA-1 44F0A22B143B79FA760BF31E14C8FFF714C8A2A1 In-memory SparroWocky backdoor sample SHA-1 9AA9FF61BC63CCA
sha152c6646759cf6037bb17466203631c4bd794532f3CAC1 winfsp-x64.dll , detected as SparroWocky loader SHA-1 52C6646759CF6037BB17466203631C4BD794532F winfsp-x64.dll , detected as SparroWocky loader SHA-1 E7070
sha19aa9ff61bc63ccab9074fe837f39c980ca9ddc8c4C8FFF714C8A2A1 In-memory SparroWocky backdoor sample SHA-1 9AA9FF61BC63CCAB9074FE837F39C980CA9DDC8C In-memory SparroWocky backdoor sample IP address 38.54.57.1
Full article995 words · extracted from cybersecuritynews.com · click to collapse

FamousSparrow has introduced a new backdoor called SparroWocky after breaking into public-facing Microsoft Exchange servers.

The campaign shows how a known espionage group can turn an exposed email system into a quiet, long-term entry point inside a government network.

The impact extends beyond the first host, because email servers commonly hold sensitive messages and trusted network connections.

The activity has concentrated on Latin America since mid-2025, with governments in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela among the observed targets.

Researchers recorded 90 percent of the group’s targets in the region from mid-2025 into 2026, marking a sharp change from its earlier worldwide focus. Analysts at Welivesecurity identified the malware as FamousSparrow’s new main implant, replacing SparrowDoor from August 2025.

The group, active since at least 2019, was previously associated with attacks exploiting ProxyLogon, while recent reporting also detailed FamousSparrow’s Exchange breach of an energy-sector network.

Welivesecurity said in a report shared with Cyber Security News (CSN) that SparroWocky is a modular C-language backdoor designed for stealth and flexible operator control.

Trident loader scheme (Source - Welivesecurity)
Trident loader scheme (Source – Welivesecurity)

Its arrival matters because it combines data theft and remote access with techniques intended to make investigation and detection harder.

FamousSparrow Exploits Public-Facing Exchange Servers

FamousSparrow gained initial access by exploiting publicly reachable Exchange servers, according to the researchers’ mapping of the intrusion.

This is a familiar danger for organizations operating on-premises mail infrastructure: a single internet-facing weakness can provide an attacker with a foothold before normal user protections come into play. The group uses a three-part loader made up of a legitimate executable, a malicious DLL, and an encrypted payload file.

The executable loads the counterfeit library through DLL side-loading, allowing the malicious code to blend in with a trusted program, a technique also seen in this silent Windows backdoor analysis.

The loader decrypts the payload and maps it directly into memory rather than saving the final backdoor to disk. It can establish persistence through a Windows service or a Registry Run key, then collect the computer name, user and domain details, Windows version, and network-interface addresses.

WinDbg call stack view of an obfuscated call to Sleep (Source - Welivesecurity)
WinDbg call stack view of an obfuscated call to Sleep (Source – Welivesecurity)

Once connected, SparroWocky can run commands, move or remove files, capture screenshots, and send stolen material over its command-and-control channel. It can also act as a TCP proxy, potentially giving operators a route to reach other systems from a compromised host.

Stealth Features Raise Defense Pressure

The backdoor uses TLS for command traffic and RC4 encryption for transmitted content. It can load Beacon Object Files, compact modules used by red-team tools, giving operators a way to extend the implant without deploying a separate full program to disk.

Its authors also built in measures to confuse security monitoring. SparroWocky can disguise call stacks, dynamically locate Windows functions, hide thread start addresses, and create a false record of a loaded module.

These features make routine alerts less reliable and increase the value of memory and behavior-based investigation. The immediate priority is to patch internet-facing Exchange servers, remove or restrict unnecessary public access, and verify that servers run supported, current builds.

Teams should treat public exploit code and reports of exposed Exchange server exploitation as a reminder to inventory external services rather than assume perimeter controls are sufficient.

Command message format (Source – Welivesecurity)

Defenders should also hunt for unexpected DLL side-loading, new services or Registry Run entries, suspicious .dat payload files, and unusual outbound TLS sessions to the listed addresses.

Review Exchange and IIS logs for abnormal activity, isolate suspected hosts, preserve memory evidence, rotate potentially exposed credentials, and investigate nearby systems for follow-on access.

This campaign illustrates a broader shift in which a proven intrusion group is pairing targeted regional espionage with a more capable custom implant.

Organizations that rely on public-facing Exchange systems should make rapid patching, continuous exposure checks, and post-compromise hunting routine parts of their defense plan, especially given recent Exchange vulnerability patch guidance.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
SHA-13209689E509205CCDB7E49062B7B407DDC23CAC1winfsp-x64.dll, detected as SparroWocky loader
SHA-152C6646759CF6037BB17466203631C4BD794532Fwinfsp-x64.dll, detected as SparroWocky loader
SHA-1E7070B5AF24A0FE1E6FEBE5954B03CB385E91FDukeQt.dll, detected as SparroWocky loader
SHA-144F0A22B143B79FA760BF31E14C8FFF714C8A2A1In-memory SparroWocky backdoor sample
SHA-19AA9FF61BC63CCAB9074FE837F39C980CA9DDC8CIn-memory SparroWocky backdoor sample
IP address38.54.57.17SparroWocky command-and-control infrastructure, first seen February 25, 2026
IP address38.60.197.55SparroWocky command-and-control infrastructure, first seen March 16, 2026
IP address38.60.209.106SparroWocky command-and-control infrastructure, first seen February 26, 2026
IP address38.60.224.51SparroWocky command-and-control infrastructure, first seen February 25, 2026
IP address38.60.224.235SparroWocky command-and-control infrastructure, first seen February 24, 2026
IP address38.60.241.65SparroWocky command-and-control infrastructure, first seen March 10, 2026
IP address38.60.241.127SparroWocky command-and-control infrastructure, first seen March 4, 2026
IP address38.60.241.193SparroWocky command-and-control infrastructure, first seen January 22, 2026
IP address77.111.101.40SparroWocky command-and-control infrastructure, first seen May 20, 2026
IP address91.148.134.115SparroWocky command-and-control infrastructure, first seen June 17, 2026
IP address130.94.101.82SparroWocky command-and-control infrastructure, first seen February 26, 2026
IP address140.99.164.199SparroWocky command-and-control infrastructure, first seen February 26, 2026
IP address149.104.87.228SparroWocky command-and-control infrastructure, first seen February 24, 2026
IP address149.104.90.203SparroWocky command-and-control infrastructure, first seen January 22, 2026
IP address216.238.92.2SparroWocky command-and-control infrastructure, first seen February 25, 2026
IP address216.238.105.53SparroWocky command-and-control infrastructure, first seen January 22, 2026
IP address216.238.110.120SparroWocky command-and-control infrastructure, first seen December 11, 2025
IP address216.238.121.164SparroWocky command-and-control infrastructure, first seen March 16, 2026

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/famoussparrow-exploits/