Threats · 4 days ago

FamousSparrow Shifts to Modular Exchange Footholds

ESET says FamousSparrow has replaced its older SparrowDoor backdoor with a modular C++ implant called SparroWocky, and has been using it against government entities across Latin America since at least August 2025. The group’s latest wave is notable not just for the new malware name, but for the access path: publicly reachable Microsoft Exchange servers are the foothold.

SparroWocky can load extra capabilities as needed and uses anti-analysis tricks to hide what it is doing. In plain terms, that means the operator can add functions without swapping out the whole implant, and an exposed mail server can stay useful as a repeatable entry point for espionage even as the payload changes.

For teams that run internet-facing Exchange, the exposure is in the server layer, not only in the named malware sample. If the same mailbox system stays public, the actor can come back through that door with different tooling, so the lasting risk is the reachable Exchange service itself and the access it gives into the network behind it.

Timeline

Sources

7 sources covering this story

Entities

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-09-18

Editions

Related stories