SparrowDoor is a Windows backdoor associated with the China-aligned espionage group FamousSparrow and used in long-running cyberespionage operations since at least 2021, with activity linked to compromises dating back to 2019. It has been deployed against hotels, governments, international organizations, engineering companies, law firms, financial-sector organizations, research institutes, and other entities across multiple regions including the Americas, Europe, Africa, the Middle East, and Asia. FamousSparrow has repeatedly used SparrowDoor as a flagship implant, and later variants show continued development and substantial architectural improvements, including modularity and more advanced command handling. Related malware such as CrowDoor and TernDoor have been described as variants derived from the same lineage, and some reporting notes code or functional overlap with tooling associated with Earth Estries and Tropic Trooper, although those overlaps do not by themselves establish common ownership.
SparrowDoor is typically delivered after exploitation of vulnerable internet-facing enterprise applications, especially Microsoft Exchange via the ProxyLogon chain, and in some intrusions likely through IIS web shell deployment on outdated Windows Server and Exchange environments. It has also been staged through DLL side-loading or DLL search-order hijacking using legitimate executables and encrypted payload components. Observed intrusion chains around SparrowDoor have included web shells, PowerShell-based post-exploitation, privilege escalation, and reflective or in-memory loading. The malware establishes persistence through Windows services and Registry Run keys, and some variants use process hollowing or injection into legitimate Windows processes to execute their main backdoor logic.
Its capabilities include host reconnaissance, command execution, interactive shell access, file and directory operations, file exfiltration, proxying, drive enumeration, network configuration changes, persistence management, self-uninstall, and execution under stolen or elevated privileges. Earlier reporting also documented shellcode injection and reverse-shell style interaction via command interpreter and named pipes. Modular variants support in-memory plugins for extended functionality. Communications with command-and-control infrastructure have been observed over encrypted channels including HTTPS and RC4- or XOR-protected traffic.
SparrowDoor is best characterized as an espionage backdoor used for persistent access and post-compromise control in targeted intrusions. Its operational history and victimology strongly indicate intelligence collection rather than financially motivated crime.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Both groups were also early exploiters of the ProxyLogon vulnerability (CVE-2021-26855) and have used some of the same publicly available tools. | the compromised network revealed not one, but two previously undocumented versions of SparrowDoor, FamousSparrow’s flagship backdoor. Both of these versions of SparrowDoor constitute marked progress over earlier ones...
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Chinese state-sponsored group TAG-141 (FamousSparrow) deployed SparrowDoor malware against Mexico's Universidad Nacional Autónoma in early 2025
Chinese state-sponsored group TAG-141 (FamousSparrow) deployed SparrowDoor malware against Mexico's Universidad Nacional Autónoma in early 2025
This attack chain was attempting to load the Crowdoor loader, which is half-named after the SparrowDoor backdoor, detailed by ESET... Also, the command-line argument “2” found in a variant related to Tropic Trooper samples is very similar to SparrowDoor “-k” switch functionality.
CrowDoor is a variant of SparrowDoor, another backdoor attributed to FamousSparrow.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
In order to gain initial access to the affected network, FamousSparrow deployed a webshell on an IIS server. While we were unable to determine the exact exploit used to deploy the webshells, both victims were running outdated versions of Windows Server and Microsoft Exchange, for which there are several publicly available exploits.
ESET's experts found that the China-aligned cyberespionage outfit has hit its targets with two previously undocumented versions of their flagship backdoor called SparrowDoor. Importantly, the group was also observed using the ShadowPad backdoor for the first time.
In the cases we observed, this was used to spawn an interactive remote PowerShell session. Once this session was established, attackers used legitimate Windows tools to obtain information about the host and the Active Directory domains to which it was joined.
First, the backdoor sends back an acknowledgment message... It then spawns a cmd.exe process and uses a pair of threads and named pipes to relay commands and their output between the C&C server and the shell.
When executed with the argument 11 , the backdoor launches the Windows color management tool ( colorcpl.exe ) with a command line argument of 22 and injects its loader into the newly created process.
Table 1. Command line arguments for SparrowDoor Argument Behavior ... 11 Process hollowing of colorcpl.exe .
When executed with the argument 11 , the backdoor launches the Windows color management tool ( colorcpl.exe ) with a command line argument of 22 and injects its loader into the newly created process.
Table 1. Command line arguments for SparrowDoor Argument Behavior ... 11 Process hollowing of colorcpl.exe .
The script contains a base64-encoded .NET webshell that it writes to C:\users\public\s.txt . It then decodes it using certutil.exe and saves the decoded output to C:\users\public\s.ashx .
MITRE ATT&CK techniques ... SparrowDoor launches the process into which it injects the loader, with its window hidden.
The resulting plaintext is the C&C server configuration, which consists of three pairs of addresses and ports... After loading this configuration, the backdoor will try to connect to the first server... then the next server, and so on.
The threat actor initially downloaded a batch script over HTTP from a download server... They then downloaded PowerHub... Finally, the attacker used PowerShell’s built-in Invoke-WebRequest to download three files from the same server.
SparrowDoor uses raw TCP sockets to communicate with its C&C server.
They then downloaded PowerHub, an open-source post-exploitation framework, from an attacker-controlled server... Finally, the attacker used PowerShell’s built-in Invoke-WebRequest to download three files from the same server that comprise SparrowDoor’s trident loader.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware deployed by the FamousSparrow-linked TAG-141 group against a Mexican university.
Mentioned as part of overlapping toolsets and infrastructure attributed to Earth Estries.
Malware used by TAG-141 (FamousSparrow) against entities in multiple LAC countries.
Referenced as the parent backdoor family in the lineage described (Crowdoor is a variant of SparrowDoor); no additional capabilities described in the provided content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.