VYPR
advisoryPublished Sep 17, 2026· 3 sources

FamousSparrow Deploys New SparroWocky Backdoor via Exchange Server Exploits

The espionage group FamousSparrow is leveraging compromised Microsoft Exchange servers to deploy a new, stealthy backdoor named SparroWocky, primarily targeting governments in Latin America.

The persistent espionage group FamousSparrow has been observed exploiting publicly facing Microsoft Exchange servers to deploy a newly developed backdoor, dubbed SparroWocky. This campaign highlights how threat actors can leverage widely used email infrastructure as a long-term entry point into sensitive government networks. The impact is significant, as compromised email servers often contain confidential communications and maintain trusted network connections, providing attackers with valuable access and intelligence.

Since mid-2025, the campaign has predominantly targeted government entities in Latin America, with observed victims including organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. This regional focus represents a notable shift from FamousSparrow's previously broader, global targeting. Security researchers have identified SparroWocky as the group's primary implant, replacing the older SparrowDoor backdoor, and note its sophisticated design for stealth and operator control.

FamousSparrow, active since at least 2019, has a history of exploiting vulnerabilities in Microsoft Exchange, including ProxyLogon. The group's recent activity also includes the exploitation of an energy sector network. SparroWocky, written in C, is designed for data theft, remote access, and network pivoting, incorporating advanced techniques to evade detection. Its modular nature allows for flexible expansion of its capabilities.

The initial access vector for this campaign involves exploiting internet-facing Microsoft Exchange servers, a common and persistent threat for organizations relying on on-premises email solutions. The attackers utilize a multi-stage loader consisting of a legitimate executable, a malicious DLL, and an encrypted payload. This loader employs DLL side-loading to disguise malicious code within a trusted program, a technique designed to bypass initial security scrutiny.

To further enhance stealth, the SparroWocky backdoor is loaded directly into memory without being written to disk. This in-memory execution makes forensic analysis more challenging. The backdoor can establish persistence through Windows services or Registry Run keys. Once established, it gathers system information such as computer name, user and domain details, Windows version, and network interface addresses.

Upon successful compromise, SparroWocky enables operators to execute commands remotely, manage files, capture screenshots, and exfiltrate stolen data via its command-and-control (C2) channel. Notably, it can also function as a TCP proxy, allowing attackers to pivot to other systems within the compromised network, expanding their reach and operational capabilities.

The backdoor employs TLS for C2 communications and RC4 encryption for transmitted data. It supports the loading of Beacon Object Files (BOFs), which are compact modules often used by red team tools, allowing for extended functionality without deploying separate executables. To further complicate detection, SparroWocky incorporates obfuscation techniques, including disguised call stacks, dynamic function resolution, hidden thread start addresses, and the falsification of loaded module records, making traditional security monitoring less effective.

Defensive recommendations include immediate patching of all internet-facing Exchange servers, restricting unnecessary public access, and ensuring systems are running supported and updated software. Organizations should also conduct diligent threat hunting for suspicious DLL side-loading, new services or Registry Run entries, unusual payload files, and anomalous outbound TLS connections. Reviewing Exchange and IIS logs for suspicious activity, isolating suspected hosts, and preserving memory for forensic analysis are crucial steps in mitigating this threat.

This new report from The Hacker News details the SparroWocky backdoor's technical capabilities, including its use of Mbed TLS for secure C2 communication, MinHook for evading security products, and a variant of SilentMoonwalk for spoofing call stacks. It also highlights the malware's ability to integrate open-source code directly into its custom backdoor, a departure from previous methods where such tools were used alongside custom implants. The article further emphasizes that while the initial access vector remains unknown, the group has been actively targeting governmental entities across Latin America since August 2025, with 90% of its observed victims located in the region.

This new reporting from Infosecurity Magazine provides further detail on the threat actor FamousSparrow's shift from its SparrowDoor implant to the new SparroWocky backdoor. It highlights that SparroWocky is a distinct C++ backdoor family, not merely a variant of SparrowDoor, and details its modular capabilities including command execution, file exfiltration, and the use of Beacon Object Files. The article also emphasizes the group's significant focus on Latin America since mid-2025, attributing this regional concentration to potential geopolitical responses by China.

Synthesized by Vypr AI
FamousSparrow Deploys New SparroWocky Backdoor via Exchange Server Exploits · VYPR