China-aligned FamousSparrow widens Latin America campaign with new backdoor
ESET says the China-aligned FamousSparrow group has been using a new backdoor called SparroWocky against government targets in Latin America since at least August 2025. The activity highlights a sustained cyberespionage push in the region as U.S.-China competition intensifies there.
Why it matters: - FamousSparrow’s focus on Latin American government networks suggests a sustained espionage effort in a region where China and the U.S. are competing for influence. - ESET says 90% of FamousSparrow’s targets in its telemetry were in Latin America from mid-2025 into 2026. - The campaign raises the stakes for governments in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela.
What happened: - ESET Research identified a new FamousSparrow backdoor named SparroWocky and said the malware has been deployed in several Latin American countries since at least August 2025. - The group expanded its targeting of governmental organizations in the region. - ESET researcher Alexandre Côté Cyr uncovered the latest activity during an investigation of the China-aligned group. - ESET said the trend against high-profile targets in Latin America began no later than July 2025 and continued after SparroWocky appeared.
The details: - SparroWocky is a modular C++ backdoor. - The malware can launch arbitrary files, act as a TCP proxy and execute commands. - SparroWocky collects the computer name, username, domain name, Windows version and IP addresses of network interfaces. - The backdoor can exfiltrate files and take screenshots periodically. - Exfiltrated data is encrypted with RC4 and sent over TLS. - SparroWocky can persist by creating a service or adding a registry Run key. - The malware uses anti-analysis tricks, manipulates low-level memory structures and patches code at runtime to avoid detection. - SparroWocky can load and execute Beacon Object Files, a format used by many red-teaming and penetration-testing tools. - ESET said FamousSparrow has also started incorporating code from open-source projects directly into its malware. - ESET said the backdoor’s first samples contained the first stanza of Lewis Carroll’s "Jabberwocky," which inspired the name SparroWocky.
Between the lines: - ESET believes the concentration on Latin America likely reflects China’s response to recent U.S. initiatives in the region. - The U.S. has renewed pressure on China’s long-term interests in energy, mining and telecommunications across Latin America. - ESET said FamousSparrow’s activity may be aimed at helping China monitor and anticipate how local governments react to U.S. pressure. - One targeted Panamanian entity is involved in a commercial dispute over two major ports in the canal area that were until recently operated by a China-based company. - The shift to SparroWocky also shows a deeper in-house development capability, not just the use of off-the-shelf offensive tools.
What's next: - ESET expects FamousSparrow to remain active in Latin America as long as the regional strategic competition continues. - The company said more technical details are available in its blog post, “Beware the SparroWock: The backdoor that bites, the commands that catch,” on WeLiveSecurity.com. - ESET is urging readers to follow its research channels for future updates.
The bottom line: - FamousSparrow is no longer just reusing external tooling; it has built a more advanced custom backdoor while sharpening its focus on Latin American governments.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
LATAM Daily Brief
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.