Adversary Intelligence — 2026-09-18

China-Linked FamousSparrow Deploys New SparroWocky Backdoor Against Latin American Government Agencies

BLUFFamousSparrow's near-total pivot to Latin American governments and its canal-linked targeting reveal a sustained collection posture calibrated to Beijing's regional commercial and diplomatic pressure points.

ESET Research reported that FamousSparrow, a China-aligned cyberespionage group active since at least 2019, has deployed a new C++ backdoor called SparroWocky against government organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela since at least August 2025 12. ESET researcher Alexandre Côté Cyr said the campaign, tracked since August 2025, has replaced the group's older SparrowDoor implant, and that from mid-2025 into 2026 roughly 90 percent of FamousSparrow's recorded targets were located in Latin America 13. The backdoor exfiltrates files, captures screenshots, collects system and network data, and can load Beacon Object Files; ESET found it incorporates code from open-source projects including Mbed TLS and MinHook 14. ESET noted that one targeted Panamanian entity is involved in an ongoing commercial dispute over ports in the canal area previously operated by a China-based company 23, and separately linked FamousSparrow's SparrowDoor tool to Salt Typhoon, though it tracks the two as distinct due to a lack of technical indicators 1.

Analysis
The near-total regional concentration of FamousSparrow's targeting since mid-2025 points to a standing collection mandate rather than a one-off campaign, and the shift from SparrowDoor to the modular SparroWocky backdoor signals investment in stealthier tradecraft built for longer dwell times. This reporting rests on ESET's technical work alone, with The Record and BleepingComputer merely republishing its findings. Targeting a Panamanian entity embroiled in the canal ports dispute shows the group can align cyberespionage with live diplomatic flashpoints, giving Beijing near-real-time visibility into regional responses to US pressure on Chinese investments. The concentration could equally reflect opportunistic exploitation of weaker Latin American network defenses rather than deliberate geopolitical targeting. A publicly floated but ESET-unconfirmed link to Salt Typhoon would, if substantiated, tie a government-facing implant to an operation already implicated in US telecom and Treasury intrusions.
4 sources
  1. Beware the SparroWock: The backdoor that bites, the commands that catch - WeLiveSecurity (ESET Research)
  2. ESET Research: China-aligned FamousSparrow expands operations in Latin America, targets governments with new backdoor - GlobeNewswire (ESET Research press release)
  3. China FamousSparrow hackers target Latin America with new backdoor - The Record
  4. Chinese hackers use SparroWocky malware in govt espionage attacks - BleepingComputer

View in full brief →

UNCLASSIFIED // OPEN SOURCE