China-aligned cyber-espionage group FamousSparrow has been linked to a new backdoor called SparroWocky, which has been used against government organizations across Latin America since at least August 2025. ESET researchers said the group began increasing its focus on high-profile targets in the region around July 2025. From mid-2025 into 2026, about 90% of FamousSparrow targets recorded in ESET telemetry were located in Latin America. The campaign has been observed in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.

SparroWocky is a new modular backdoor written in C++ and has now replaced SparrowDoor as FamousSparrow’s main implant. ESET said the malware is not simply a new version of SparrowDoor but a separate malware family with similar capabilities and concepts. Researchers named it SparroWocky because early samples contained the first stanza of Lewis Carroll’s famous poem Jabberwocky. The malware’s design also shows the use of open-source components directly inside the custom backdoor, marking a change from the group’s earlier approach.

The backdoor provides attackers with several capabilities that can help them maintain access and collect information from compromised systems. It can execute commands and arbitrary files, work as a TCP proxy, collect information about the infected computer, and gather details such as the username, domain, Windows version, computer name, and network interface addresses. SparroWocky can also exfiltrate files and periodically capture screenshots. Stolen information is encrypted using RC4 before being transmitted through TLS-protected communications with the command-and-control infrastructure.

ESET also found that SparroWocky uses several techniques designed to make analysis and detection more difficult. The malware can manipulate low-level memory structures and patch code while running, helping it avoid security controls. It can use MinHook to hide the actual starting address of newly created Windows threads and can load and execute Beacon Object Files, which are supported by various red-team and penetration-testing tools. Depending on the configuration and available privileges, persistence can be achieved through a Windows service or a Windows Registry Run key.

The reason behind FamousSparrow’s strong focus on Latin America is not confirmed, but ESET believes the activity may be connected to changing geopolitical and economic interests in the region. Researchers said the campaign could help China monitor how Latin American governments respond to increasing U.S. pressure and developments involving Chinese interests in areas such as energy, mining, telecommunications, and infrastructure. One targeted organization in Panama was connected to an ongoing dispute involving major ports in the Panama Canal area. ESET stressed that it remains unclear whether the regional focus represents a formal mandate or a temporary response to current circumstances.

FamousSparrow is believed to have been active since at least 2019 and was first publicly documented by ESET in 2021 after exploiting the ProxyLogon vulnerability. The group was initially known for targeting hotels but later expanded its operations to governments, international organizations, trade groups, engineering companies, and law firms. ESET attributes the latest campaign and SparroWocky to FamousSparrow with high confidence because early attacks used the group’s SparrowDoor malware and several targeted organizations had previously been targeted by the group. The discovery shows that FamousSparrow has continued developing its malware while concentrating its recent operations heavily on Latin America.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news