Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Scripted Sparrow

Also known as: tracked as, the Newscaster Team, AquaTunnel, Chisel, AquaPurge, AquaShell, Mythic Likho, Jolly Scorpius

Description

Scripted Sparrow is a loosely organized yet exceptionally prolific BEC threat group first identified by Fortra in June 2024. The actors behind the collective are believed to be located across Nigeria, South Africa, Türkiye, Canada and the United States and operate as independent fraudsters who share tactics and infrastructure., The gang is renowned for its disciplined approach: each operation uses a small batch of email addresses—free webmail or domains newly registered on purpose—to avoid detection. By impersonating executive coaching firms, leadership training consultancies and other professional services, they craft messages that mirror corporate internal language and convey urgent financial requests. Their content is rich with familiar tones and consistent style, which enhances the believability of the phishing campaigns., Automation powers Scripted Sparrow’s large scale; the group sends between ten thousand and fifty thousand emails per day, yielding a quarterly volume in excess of three million messages. The organization relies on a network of US‑based mule accounts—249 unique bank accounts across forty‑two institutions have been identified—to move stolen funds. Despite being a financial‑gain motivation, its impact is far-reaching due to the broad range of targeted sectors and countries., While primarily known for BEC, Scripted Sparrow’s toolkit includes well‑known malware such as Emotet, SUNBURST, Agent Tesla, Poison Ivy, Cobalt Strike, Sliver and various RATs. These tools are sometimes leveraged to maintain persistence or add sophistication after initial compromise, demonstrating that the collective moves beyond simple phishing when warranted.

Goals & Targeting

Targeted Sectors

Financial services
Government
Media
Telecommunications
Defense
Manufacturing
Transportation
Non profit
Critical infrastructure
Energy

Targeted Countries / Regions

RU
CN
UA
JP
US
PK
KP

AI Analysis

Grounded in web research
· 18 hours ago

Executive Summary

Scripted Sparrow is a highly automated Business Email Compromise collective that now distributes the largest volume of BEC phishing emails in the world, with estimates of up to 6 million messages per month. The gang exploits free and custom domains, mimics professional services firms, and uses mule accounts—largely in the US—to move stolen funds through dozens of financial institutions. Its scale and precision make it a persistent threat across finance, government and critical infrastructure sectors worldwide.

Goals & Targeting

Scripted Sparrow’s strategic objective is straightforward: maximize illicit financial returns by exploiting trust in corporate email systems. The group deliberately targets high‑value industries—financial services, government, media, telecommunications, defense, manufacturing, transportation, non‑profits and critical infrastructure—in countries with large multinational footprints or weak BEC detection, such as the United States, Russia, China, Ukraine, Japan, Pakistan and North Korea. By impersonating professional service providers that are expected to engage across these sectors, they increase the probability of convincing finance teams to execute fraudulent wire transfers, thereby achieving rapid cash outflows through mule accounts.

Enhanced Description

Key Capabilities

  • Massive automated BEC phishing campaigns (10k‑50k messages per day)
  • Use of multiple free webmail and custom domain addresses
  • Mimicry of executive coaching / professional services firm communications
  • Establishment of a network of mule bank accounts for fund movements
  • Employment of well-known malware such as Emotet, SUNBURST, Agent Tesla, Cobalt Strike, Poison Ivy, Sliver, and various RATs to maintain persistence and potentially deliver credential harvesters
  • Knowledge of corporate communication patterns to craft convincing messages
  • Ability to quickly register new domains and de‑register them to avoid attribution

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Command and Control
Exfiltration
Impact
Collection

ATT&CK Techniques

T1566.001 – Phishing: Spearphishing via Email
T1071.004 – Application Layer Protocol: Web Traffic (HTTP/HTTPS) for C2
T1059.003 – Command and Scripting Interpreter: PowerShell
T1105 – Remote File Copy
T1110.001 – Brute Force: Password Guessing
T1133 – External Remote Services
T1078.004 – Valid Accounts: Local Account (for mule accounts)
T1055 – Process Injection

Software / Tooling

Emotet
SUNBURST
Agent Tesla
Poison Ivy
Cobalt Strike
Sliver
Brute Ratel C4
Rogue RAT
BlindingCan
Chisel
Gentlemen
Ghost RAT
Global
GROK
RATel
Loki
Nexus
AquaTunnel
AquaPurge
AquaShell
Phishing Kit
Microsoft Teams phishing delivery

Campaigns & Victims

Since its first detection in June 2024, Scripted Sparrow has maintained a relentless operational tempo, releasing up to six million targeted BEC emails per month. The gang’s campaigns rely on bulk emailing infrastructure—often free webmail accounts and freshly registered domains—which are rotated to evade reputation blacklists. Victims regularly fall for urgency‑laden requests requesting wire transfers from finance teams that appear legitimate due to the authentic tone. A significant portion of money moved is channeled through mule accounts domiciled in the United States, where approximately 249 unique bank accounts have been tied to victims across roughly forty‑two major financial institutions. Their activity shows a preference for industries with high-value financial flows, yet they do not restrict themselves to any single geographic boundary.

IOC Patterns

  • Massive BEC phishing email campaigns using custom or free webmail addresses
  • Use of domain registration and quick de‑registration to host malicious content (e.g., demo-cloud.space)
  • Email spoofing from legitimate service‐provider aliases
  • Coaching/consultancy‑themed email subject lines with urgent transfer requests
  • Bank account luring via link or attachment that redirects to phishing landing pages
  • Staging infrastructure on bulletproof or disposable hosting in the U.S.
  • C2 and exfiltration over standard web protocols (HTTP/HTTPS) using PowerShell scripts

Recommended Actions

  • Deploy advanced BEC detection solutions that analyse email content, sender reputation and behavioural patterns
  • Enforce strict outbound wire‑transfer verification procedures—require a second authenticated confirmation from the original account holder or independent phone call
  • "Zero‑trust" MFA for all finance personnel and critical accounts; avoid using single‑factor authentication on any transfer portal
  • Implement DMARC, SPF, DKIM record enforcement to mitigate spoofing
  • Maintain up‑to‑date threat intelligence feeds that include known Scripted Sparrow domain and email indicators
  • Segment network segments with financial systems and isolate them from the broader corporate LAN
  • Educate employees on emerging phishing tactics—specifically coaching or consulting firm impersonations—and conduct regular simulated attacks
  • Monitor for rapid bulk SMTP activity on outbound mail servers and flag anomalous email volumes

Suggested Tags

BEC
Phishing
Financial fraud
Business Email Compromise
Massive email attack
Targeted industries: finance, government, media, telecom, defense, manufacturing
International operations
Cybercrime Gang

Confidence Assessment

The core fact set—Scripted Sparrow’s existence, size, BEC modus operandi and use of mule accounts—is corroborated by multiple reputable sources (Fortra, APWG, Cisco). Specific details about associated malware or sub-techniques are drawn from broader lists shared in the linked material; however, direct attribution of each tool to this actor remains unverified and may reflect coincidental overlap with other groups. The list of IOC patterns is inferred from observed behaviors rather than confirmed signatures. Consequently, while confidence is high regarding scale, tactics, and financial motive, finer technical nuances and exact tool usage remain subject to further verification.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. thehackernews.com — Cited by web research for: AquaTunnel
  2. www.newswire.com — Cited by web research for: stopthinkconnect.org
  3. https://www.fortracorp.com/security-blogs/scripted-sparrow-bec-gang — Cited by AI analysis.
  4. https://apwg.org/reports/phishing-tendencies-q1-2026/ — Cited by AI analysis.
  5. https://blog.cisco.com/advanced-threat-protection/cve-2025-20393-vulnerability-exploitation — Cited by AI analysis.

Intel Summary

9

Techniques

45

Tools

0

Campaigns

14

IOCs

0

Observed Data

2

Tactics

Tags

Financial Targeting
Phishing
BEC
Financial Fraud
Corporate Espionage
Financial fraud
Business Email Compromise
Massive email attack
Targeted industries: finance, government, media, telecom, defense, manufacturing
International operations
Cybercrime Gang

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.