Scripted Sparrow Uses Automation to Generate and Send their Attack Messages
Scripted Sparrow is a newly identified Business Email Compromise (BEC) group with operations spanning three continents. The group utilizes extensive automation to generate and send attack messages globally.
Scripted Sparrow is a newly identified Business Email Compromise (BEC) group with operations spanning three continents. The group utilizes extensive automation to generate and send attack messages globally.
Scripted Sparrow primarily targets organizations by impersonating executive coaching or leadership training consultancies. The initial attack phase involves sending an email to an Accounts Payable team member, often including a spoofed email thread that mimics a conversation between a vendor and a company executive. The intent is to lend credibility to a fraudulent invoice request, typically for services like "The Catalyst Executive Circle" and accompanied by a W-9 form.
The invoices are generally crafted to be just under $50,000, specifically $49,927.00, to bypass higher-level financial approval processes.
Recent analyses by Fortra have revealed that Scripted Sparrow has adapted its methods to circumvent security filters. Instead of attaching malicious documents directly, they sometimes omit these attachments, prompting recipients to request the missing files. This tactic builds trust before delivering the final payload. The group is estimated to send millions of targeted messages each month, indicating the use of automated scripting tools for managing the high volume of correspondence.
Scripted Sparrow is a newly identified Business Email Compromise (BEC) group with operations spanning three continents.
Further, metadata analysis showed that 76% of their PDF attachments were generated using the Skia/PDF library, highlighting a programmatic approach to document creation.
Operational Security and Evasion Tactics
Scripted Sparrow employs various operational security measures to obscure its activities. During defense engagements, researchers observed the use of browser plug-ins for geolocation spoofing. However, these attempts often exposed a lack of technical sophistication, particularly in configuring Remote Desktop Protocol (RDP) tools. Some actors appeared to operate from improbable remote locations due to poor configuration.
Analysis of browser fingerprints further revealed inconsistencies. In one instance, a threat actor seemingly moved from San Francisco to Toronto within seconds, confirming the use of location-masking software. Additionally, user agent strings analysis identified entries such as "TelegramBot (like TwitterBot)," suggesting the use of Telegram for internal communication and coordination.
These technical missteps provide defenders with valuable indicators to identify and block the group's infrastructure effectively.
Based on reporting by Cyber Security News.
