Security1 distinct publisher2 min readPublished
Positive Technologies says the East Asian group is injecting JavaScript into legitimate sites to push a bogus certificate that installs SquawkDoor and a reworked SparrowDoor. Four locations are confirmed.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The quoting is the part worth copying into your notes. Positive Technologies records the shortcut's command line as `"C:\Windows\System32\ftp.exe" -""s: _rels\info.dll` [13], and says the Windows parser consumes those quotation marks, which is enough to walk past simple detections written for the `-s` switch [14]. The switch still resolves. The string a rule is looking for is not there.
The archive carrying it was named for an Indonesian-language reference document and held four files: the LNK, `info.dll`, `.rels.log` and `557.pdf` [11]. The hash listed for that PDF is `e3b0c442...b7852b855` [12], which is the SHA-256 of a zero-byte input, so the decoy the victim was supposed to open contained nothing [3]. Anyone triaging the archive by looking at the document finds an empty page and moves on.
The geography deserves a closer read than the summary offers. Positive Technologies names seven primary target countries [2], but says the compromised-site-and-fake-certificate chain is confirmed in four of them: Taiwan, Germany, Indonesia and the Czech Republic [7]. Separately, malicious files were submitted to public sandboxes from Indonesia, the Philippines, Nepal and Taiwan [6]. Only Indonesia and Taiwan appear in both lists [2]. Germany and the Czech Republic rest on the site evidence, Nepal and the Philippines on the submissions, and Egypt on neither of the two [1].
The injected script also carried `/report-url` and `/track-download` functions for collecting infection statistics [9], and the vendor says it did not observe mass infection even though the code would support it [10]. Localised text in both the JavaScript and the SquawkDoor samples points to preparation per country [8]. Counting downloads while holding volume back is how an operator gets conversion data before deciding where the access is worth spending.
The group Positive Technologies also tracks as Salt Typhoon and Earth Estries has been active since 2019, initially against hotels worldwide plus government and international organisations [17], later against telecommunications firms and ISPs in what the vendor reads as a hunt for durable access to lawful intercept systems [18]. A crew with that record serving MSI files from a research library is accepting far more noise than long-term intercept access usually tolerates. The same write-up says the operators made OPSEC mistakes good enough to identify one member involved in preparing the attack [15], and reports overlaps with other East Asian groups [16]. All of it comes from one vendor, and none of it has been corroborated elsewhere in the material we have.
What has not changed is the hinge: a human still has to accept the certificate prompt and run the installer [4]. That step is the only one the operator cannot engineer away.
Ranked by verification strength, evidence, and original report placement.
The primary targets in the observed campaigns were Nepal, the Philippines, Indonesia, Taiwan, Egypt, Germany and the Czech Republic.
Positive Technologies said it discovered a FamousSparrow campaign that used two tools: a new backdoor it named SquawkDoor and an updated version of the SparrowDoor backdoor.
The activity was discovered in the first half of 2026 and targeted several countries in South Asia and Europe.
FamousSparrow compromised websites and injected malicious JavaScript that displayed a fake error message and prompted users to download a certificate; the certificate was in fact a malicious MSI file that infected systems with the SquawkDoor and SparrowDoor backdoors.
Positive Technologies confirmed that FamousSparrow had gained access to an information system belonging to an international research organisation focused on food security, and injected malicious JavaScript delivering fake certificates on that organisation's platform.
In the food security case the likely targets were researchers who use the platform as a library and a place to publish articles.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed first-party artefacts, single unverified source
The report supplies reproducible technical evidence - SHA-256 hashes for the RAR, LNK, BAT, CAB and sideloaded binaries, the exact ftp.exe command line, the injected script tag and the two statistics endpoints - which is well above narrative-only reporting. But it is one vendor's first-person account with no independent corroboration, the supplied body is truncated before the SquawkDoor analysis and detection rules, and the two most consequential conclusions (identifying a group member, overlaps with other East Asian groups) arrive as assertions with no shown workings.
Real but deliberately narrow footprint
Real-world usage of the technique is established rather than theoretical: samples place the fake-certificate chain in at least four locations, sandbox submissions come from four South Asian jurisdictions, and one international food-security research platform is confirmed compromised. Against that, the vendor states plainly that it saw no mass infection, no victim counts or organisation names are given, and the headline seven-country target list exceeds the itemised evidence, so observed scale stays small.
Framing runs ahead of the itemised evidence
The technical core is sober and slightly understated, but the packaging overshoots it: seven countries are presented as primary targets when only four locations are confirmed and Egypt appears in no evidence list, the individual-member identification and the East Asian group overlaps are announced without published support, and the campaign is characterised through scaling potential even though no mass infection was seen. The gap is modest rather than large because the artefact-level material is specific and checkable.
Vendor publishing and naming its own discovery
The sole source is a commercial threat-intelligence vendor writing on its corporate blog about research it conducted, including coining the SquawkDoor name after a mutex and magic value it identified. Such reporting carries a clear reputational and commercial interest in the campaign appearing novel, broad and attributable, and the strongest marketing-adjacent claims - the identified group member and the cross-group overlaps - are exactly the ones left unevidenced in the supplied text. Nothing in the material suggests fabrication; the artefact detail is the kind a vendor stakes credibility on.
Moderate: strong artefacts, one voice, truncated text
Confidence is limited by structure rather than by contradiction. There is a single publisher, so no cross-source triangulation is possible; the supplied body cuts off mid-analysis before the SquawkDoor internals and any hunting guidance; and two summary conclusions cannot be assessed at all from the material. The hash-level, command-line-level specificity of the LNK and injection chains keeps confidence near the middle rather than low.
security
A vCenter bug patched on July 29 is already a ransomware chain, not a ticket1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 23, 2026