MITRE ATT&CK @attack.mitre.org · Apr 2

There’s a lot of meat on the bone in this report. While we’re focusing on the deployment of the backdoor, it’s also worth reading the section on FamousSparrow and Salt Typhoon for an interesting and important look at the intricacies — and sometimes the frustrating opacity — in CTI attribution

1 likes 1 replies

?

Replies

MITRE ATT&CK · Apr 2

FamousSparrow’s flagship backdoor is called SparrowDoor. The adversary uses PowerShell to download the files that comprise SparrowDoor’s trident loader which then executes SparrowDoor.