China-Linked FamousSparrow Deploys New SparroWocky Backdoor Against Latin American Government Agencies
ESET Research reported that FamousSparrow, a China-aligned cyberespionage group active since at least 2019, has deployed a new C++ backdoor called SparroWocky against government organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela since at least August 2025
The near-total regional concentration of FamousSparrow's targeting since mid-2025 points to a standing collection mandate rather than a one-off campaign, and the shift from SparrowDoor to the modular SparroWocky backdoor signals investment in stealthier tradecraft built for longer dwell times. This reporting rests on ESET's technical work alone, with The Record and BleepingComputer merely republishing its findings. Targeting a Panamanian entity embroiled in the canal ports dispute shows the group can align cyberespionage with live diplomatic flashpoints, giving Beijing near-real-time visibility into regional responses to US pressure on Chinese investments. The concentration could equally reflect opportunistic exploitation of weaker Latin American network defenses rather than deliberate geopolitical targeting. A publicly floated but ESET-unconfirmed link to Salt Typhoon would, if substantiated, tie a government-facing implant to an operation already implicated in US telecom and Treasury intrusions.
4 sources
- Beware the SparroWock: The backdoor that bites, the commands that catch -
WeLiveSecurity (ESET Research) - ESET Research: China-aligned FamousSparrow expands operations in Latin America, targets governments with new backdoor -
GlobeNewswire (ESET Research press release) - China FamousSparrow hackers target Latin America with new backdoor -
The Record - Chinese hackers use SparroWocky malware in govt espionage attacks -
BleepingComputer