A newly discovered cyberespionage group has been targeting hotels worldwide around the world since at least 2019. FamousSparrow has targeted higher-profile targets such as governments, international organizations, law firms, and engineering companies. The group has used multiple attack vectors in Internet-exposed web applications to breach its targets’ networks, including remote code execution vulnerabilities in Microsoft SharePoint, the Oracle Opera hotel management software and the Microsoft Exchange security flaws known as ProxyLogon. In-the-wild exploitation began on January 3rd, way before the bugs were even reported to Microsoft, who released patches on March 2nd.”]

