Researchers assessing an espionage campaign targeting East Asian companies since May 2023 said the activity likely focused on semiconductor and rare-metal sectors and used the Xiangoop Loader to deliver fileless payloads including Cobalt Strike Beacon, EntryShell, and in some cases CrowDoor through SparrowDoor Loader. Malware analysis found strong overlap between EntryShell and the older KeyBoy family, including matching embedded and encrypted strings, leading investigators to assess EntryShell as an updated KeyBoy variant.
The same research identified technical overlap between CrowDoor and SparrowDoor, including identical loader shellcode and shared structural and command features, strengthening the case that Tropic Trooper and FamousSparrow are either the same threat actor or closely aligned operators. Earlier reporting on FamousSparrow described a cyberespionage group active since at least 2019 that exploited internet-facing applications such as Microsoft Exchange via ProxyLogon, Microsoft SharePoint, and Oracle Opera to deploy SparrowDoor, a backdoor capable of persistence, host reconnaissance, file theft, process creation, shellcode injection, and interactive remote shell access.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
ITOCHU researchers observed attacks they estimate are linked to Tropic Trooper targeting East Asian companies from May 2023, with suspected focus on semiconductor and rare-metal sectors.
ESET telemetry indicated FamousSparrow began exploiting Microsoft Exchange ProxyLogon vulnerabilities on March 3, 2021, shortly after patches were released.
ESET assessed the cyberespionage group it named FamousSparrow had been active since at least 2019, with targeting that included hotels, governments, international organizations, engineering companies, and law firms.
The ITOCHU analysis describes Tropic Trooper as a cyber-espionage group that has been active since 2011.
Based on malware and loader similarities, ITOCHU assessed that Tropic Trooper and FamousSparrow are either the same group or have a very close operational relationship.
In their 2023 analysis, ITOCHU researchers documented the Xiangoop Loader campaign and found technical overlap showing EntryShell as an upgraded KeyBoy variant and CrowDoor as closely related to SparrowDoor.
ESET reported a newly identified cyberespionage group it named FamousSparrow and documented its custom SparrowDoor backdoor, along with its use of vulnerable internet-facing applications for initial compromise.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 28 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.