Scripted Sparrow is a large-scale business email compromise (BEC) threat group focused on direct financial fraud through highly targeted social-engineering campaigns. Active since at least June 2024, the group has been observed sending millions of scam emails per month in industrialized, automated operations spanning three continents. Its campaigns primarily target finance and accounts-payable personnel, especially in North America and Europe, by impersonating executive coaching, leadership training, and other professional-services consultancies. The group’s tradecraft centers on convincing payment-redirection and fraudulent invoice schemes rather than malware deployment or credential theft. Scripted Sparrow commonly uses spoofed or forged reply chains, fabricated executive approvals, polished invoice themes, W-9 documentation, and payment requests deliberately kept below common approval thresholds to increase the likelihood of wire transfers. The actor has also adapted its lures over time, including missing-attachment pretexts intended to bypass email security controls and multilingual messaging to broaden reach. Operational reporting indicates a structured and centrally managed organization rather than a loose affiliate model. Scripted Sparrow uses significant automation for message generation, correspondence handling, and campaign scaling, while rotating infrastructure and financial collection mechanisms to evade blocklists and sustain operations. Analysts have documented extensive campaign variation, repeated template reuse with incremental refinements, clustered infrastructure registration patterns, and a broad laundering network tied to numerous bank accounts. Technical observations also indicate operational-security measures such as geolocation spoofing and likely use of Telegram for internal coordination. The actor’s dominant objective is financial gain. Available reporting characterizes Scripted Sparrow as a prolific global BEC collective with members operating across multiple continents, with some reporting associating elements of the operation with Nigeria, South Africa, Türkiye, Canada, and the United States. High-confidence attribution to a single nation-state sponsor is not supported; Scripted Sparrow is best characterized as a transnational cybercriminal fraud operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prolific BEC collective sending an estimated 6 million highly targeted scam emails each month, impersonating executive coaching firms and using spoofed reply chains, missing attachment lures, and multilingual campaigns to conduct fraud at scale.
Business Email Compromise (BEC) group conducting invoice/W-9 fraud against Accounts Payable using spoofed reply chains and likely automation to scale outreach.
Scripted Sparrow is known for conducting large-scale, industrialized business email compromise (BEC) campaigns, targeting organizations globally with millions of malicious emails.
Large-scale BEC operations using automation and social engineering, targeting organizations globally for financial fraud.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.