ChinaWidely attributedUnknown

FamousSparrow

China-nexus APT active since 2019, targeting hotels, governments and private companies worldwide. Shares tooling overlaps with Earth Estries and GhostEmperor but assessed as a distinct cluster. Primarily uses SparrowDoor and CrowDoor backdoors.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
6.0
Moderate signal strength
Mentions11
Sources5
High conf.4
Last seenJun 2026
First observed
Last active
Origin
China
Aliases
4
Techniques
0
Campaigns
0
China
TargetsHospitalityGovernmentTechnology
RegionsGlobal

Attribution signals

11 mentions · 5 sources
#1attributedhigh
InfrastructureTTP matchMalware
checkpoint
May 2026

"Researchers attributed a months-long intrusion against an Azerbaijani oil and gas company to the Chinese-linked FamousSparrow group"

#2targetedhigh
Victimology
dark-reading
Jun 2026

"China-linked group FamousSparrow targeted a Venezuelan governmental group focused on maritime affairs"

#3targetinghigh
GeopoliticalVictimology
eset
May 2026

"FamousSparrow embarked on a tour of Latin America, targeting multiple governmental entities in the region."

#4likelyhigh
VictimologyGeopolitical
eset
May 2026

"FamousSparrow targeted a Venezuelan governmental entity connected to maritime affairs, likely to monitor the resilience of oil shipments after the US intervention."

#5China-linkedmoderate
Victimology
dark-reading
May 2026

"this is the first time that China-linked groups have been discovered in Azerbaijanian industries"

#6China-linkedmoderate
VictimologyTTP match
dark-reading
May 2026

"the China-linked FamousSparrow group has targeted an Azerbaijanian oil-and-gas company in the South Caucasus region"

#7also used bymoderate
Malware
cisco-talos
May 2026

"Draculoader: A generic shellcode loader deployed by UAT-8302, also used by the Earth Estries and Earth Naga APT groups who have histories of targeting government agencies in Southeast Asia and elsewhere."

#8assessed with low confidencelow
Unspecified
jpcert-blog
May 2026

"Although potential links to known groups such as Earth Estries were considered, attribution was assessed with low confidence."

#9suggestslow
GeopoliticalVictimology
dark-reading
May 2026

"The latest research suggests that China has begun to focus on South Caucasus with its own cyber operations."

#10unspecified
VictimologyTTP matchMalware
security-affairs
May 2026
#11unspecifiedunspecified
Victimology
security-affairs
May 2026

"FamousSparrow targets Azerbaijani energy sector in multi-wave espionage campaign"

Hedge terms observed

also used byassessed with low confidenceattributedChina-linkedlikelysuggeststargetedtargetingunspecified