Skip to main content
The Wire
CyberNews by Zentrya One
Malware

China-Aligned FamousSparrow Deploys New SparroWocky Backdoor Across Latin America

ESET researchers uncover SparroWocky, a new modular C++ backdoor used by China-aligned FamousSparrow in cyberespionage attacks targeting governments across Latin America.

Cybersecurity researchers have uncovered a new C++ backdoor called SparroWocky, attributed with high confidence by ESET to the China-aligned cyberespionage group FamousSparrow.

The malware has been deployed against government organizations across Latin America since at least August 2025, with ESET observing targets in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. From mid-2025 into 2026, around 90% of FamousSparrow targets visible in ESET telemetry were located in the region.

SparroWocky Replaces SparrowDoor

FamousSparrow appears to be replacing its older SparrowDoor malware with SparroWocky as its primary implant.

ESET assesses the attribution with high confidence because some early SparroWocky infections were actually deployed through SparrowDoor, a backdoor exclusively associated with FamousSparrow. Researchers also observed the new malware at organizations previously targeted with SparrowDoor.

Importantly, SparroWocky is not simply a new version of SparrowDoor. Researchers describe it as a separate malware family designed with greater modularity, stealth and anti-analysis capabilities.

What Can SparroWocky Do?

Once deployed, SparroWocky gives attackers extensive remote-control capabilities, including:

  • Executing arbitrary commands and files
  • Uploading and exfiltrating files
  • Taking periodic screenshots
  • Collecting usernames, hostnames, Windows versions and IP addresses
  • Creating, copying, moving and deleting files
  • Acting as a TCP proxy
  • Establishing persistence
  • Executing additional payloads directly in memory
  • Loading Beacon Object Files (BOFs) used by various offensive-security frameworks

Stolen information is encrypted using RC4 before being transmitted to command-and-control (C2) infrastructure over TLS.

Designed to Evade Detection

SparroWocky includes several advanced defense-evasion techniques.

The malware can manipulate low-level Windows memory structures, patch code during runtime and spoof call stacks to make malicious activity appear to originate from legitimate code.

Its loader also uses DLL side-loading, combining a legitimate executable, a malicious DLL and an encrypted .dat payload.

The final backdoor is reflectively loaded into memory rather than written normally to disk, potentially making traditional file-based detection more difficult.

FamousSparrow has also integrated code from legitimate open-source projects, including Mbed TLS, MinHook, COFF Loader and techniques derived from SilentMoonwalk/StackMoonwalk.

Government Organizations Heavily Targeted

ESET observed SparroWocky targeting government entities across:

Region Observed Targeting
Argentina Government
Ecuador Government
Guatemala Government
Honduras Government
Panama Government
Peru Government
Puerto Rico Government
Venezuela Government

ESET assesses that the regional concentration may be connected to geopolitical intelligence requirements involving Chinese interests and U.S. activity in Latin America. That interpretation is ESET's assessment of the targeting pattern, rather than independently established evidence of the attackers' specific instructions or motives.

About FamousSparrow

FamousSparrow is a cyberespionage group that ESET describes as China-aligned and active since at least 2019.

The group was publicly documented in 2021 after researchers observed it exploiting Microsoft Exchange ProxyLogon vulnerabilities.

Its historical targets have included governments, hotels, international organizations, engineering companies, trade organizations and law firms. Researchers have reported links between FamousSparrow and Earth Estries, although ESET says the precise relationship remains unclear. FamousSparrow has also been publicly linked with Salt Typhoon, but ESET continues to track the groups separately because it says sufficient technical evidence connecting them is lacking.

Security Takeaway

The emergence of SparroWocky demonstrates a significant evolution in FamousSparrow's cyberespionage capabilities.

The combination of in-memory execution, DLL side-loading, call-stack spoofing, encrypted C2 communications, BOF execution and extensive remote-control functionality makes the malware particularly relevant for SOC and threat-hunting teams.

Organizations—especially government entities in Latin America—should monitor for unusual DLL side-loading, suspicious service or Run-key persistence, unexpected in-memory execution, abnormal TLS connections and unauthorized proxy activity.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.