Also known as: tracked as, the Newscaster Team, AquaTunnel, Chisel, AquaPurge, AquaShell, Mythic Likho, Jolly Scorpius
Scripted Sparrow is a loosely organized yet exceptionally prolific BEC threat group first identified by Fortra in June 2024. The actors behind the collective are believed to be located across Nigeria, South Africa, Türkiye, Canada and the United States and operate as independent fraudsters who share tactics and infrastructure., The gang is renowned for its disciplined approach: each operation uses a small batch of email addresses—free webmail or domains newly registered on purpose—to avoid detection. By impersonating executive coaching firms, leadership training consultancies and other professional services, they craft messages that mirror corporate internal language and convey urgent financial requests. Their content is rich with familiar tones and consistent style, which enhances the believability of the phishing campaigns., Automation powers Scripted Sparrow’s large scale; the group sends between ten thousand and fifty thousand emails per day, yielding a quarterly volume in excess of three million messages. The organization relies on a network of US‑based mule accounts—249 unique bank accounts across forty‑two institutions have been identified—to move stolen funds. Despite being a financial‑gain motivation, its impact is far-reaching due to the broad range of targeted sectors and countries., While primarily known for BEC, Scripted Sparrow’s toolkit includes well‑known malware such as Emotet, SUNBURST, Agent Tesla, Poison Ivy, Cobalt Strike, Sliver and various RATs. These tools are sometimes leveraged to maintain persistence or add sophistication after initial compromise, demonstrating that the collective moves beyond simple phishing when warranted.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Scripted Sparrow is a highly automated Business Email Compromise collective that now distributes the largest volume of BEC phishing emails in the world, with estimates of up to 6 million messages per month. The gang exploits free and custom domains, mimics professional services firms, and uses mule accounts—largely in the US—to move stolen funds through dozens of financial institutions. Its scale and precision make it a persistent threat across finance, government and critical infrastructure sectors worldwide.
Goals & Targeting
Scripted Sparrow’s strategic objective is straightforward: maximize illicit financial returns by exploiting trust in corporate email systems. The group deliberately targets high‑value industries—financial services, government, media, telecommunications, defense, manufacturing, transportation, non‑profits and critical infrastructure—in countries with large multinational footprints or weak BEC detection, such as the United States, Russia, China, Ukraine, Japan, Pakistan and North Korea. By impersonating professional service providers that are expected to engage across these sectors, they increase the probability of convincing finance teams to execute fraudulent wire transfers, thereby achieving rapid cash outflows through mule accounts.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since its first detection in June 2024, Scripted Sparrow has maintained a relentless operational tempo, releasing up to six million targeted BEC emails per month. The gang’s campaigns rely on bulk emailing infrastructure—often free webmail accounts and freshly registered domains—which are rotated to evade reputation blacklists. Victims regularly fall for urgency‑laden requests requesting wire transfers from finance teams that appear legitimate due to the authentic tone. A significant portion of money moved is channeled through mule accounts domiciled in the United States, where approximately 249 unique bank accounts have been tied to victims across roughly forty‑two major financial institutions. Their activity shows a preference for industries with high-value financial flows, yet they do not restrict themselves to any single geographic boundary.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The core fact set—Scripted Sparrow’s existence, size, BEC modus operandi and use of mule accounts—is corroborated by multiple reputable sources (Fortra, APWG, Cisco). Specific details about associated malware or sub-techniques are drawn from broader lists shared in the linked material; however, direct attribution of each tool to this actor remains unverified and may reflect coincidental overlap with other groups. The list of IOC patterns is inferred from observed behaviors rather than confirmed signatures. Consequently, while confidence is high regarding scale, tactics, and financial motive, finer technical nuances and exact tool usage remain subject to further verification.
No campaigns linked yet.
No observed data linked yet.
9
Techniques
45
Tools
0
Campaigns
14
IOCs
0
Observed Data
2
Tactics