New: 2026 Gartner® Market Guide for Adversarial Exposure Validation
Learn More
Cymulate named a Customers' Choice in 2025 Gartner® Peer Insights™
Learn More
New Research: The Security Tradeoffs Behind AI Tooling
Learn More
An Inside Look at the Technology Behind Cymulate
Learn More

FamousSparrow: A suspicious hotel guest

September 27, 2021

FamousSparrow is a group that is considered as the only current user of the custom backdoor, SparrowDoor. It also uses two custom versions of Mimikatz that could be used to connect incidents to this group. While they consider FamousSparrow to be a separate entity, they found connections to other known APT groups. In one case, attackers deployed a variant of Motnug that is a loader used by SparklingGoblin. In another case, on a machine compromised by FamousSparrow, they found a running Metasploit with cdn.kkxx888666[.]com as its C&C server. This domain is related to a group known as DRBControl.