China-Aligned FamousSparrow Deploys New SparroWocky Backdoor Across Latin America
ESET researchers uncover SparroWocky, a new modular C++ backdoor used by China-aligned FamousSparrow in cyberespionage attacks targeting governments across Latin America.

Cybersecurity researchers have uncovered a new C++ backdoor called SparroWocky, attributed with high confidence by ESET to the China-aligned cyberespionage group FamousSparrow.
The malware has been deployed against government organizations across Latin America since at least August 2025, with ESET observing targets in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. From mid-2025 into 2026, around 90% of FamousSparrow targets visible in ESET telemetry were located in the region.
SparroWocky Replaces SparrowDoor
FamousSparrow appears to be replacing its older SparrowDoor malware with SparroWocky as its primary implant.
ESET assesses the attribution with high confidence because some early SparroWocky infections were actually deployed through SparrowDoor, a backdoor exclusively associated with FamousSparrow. Researchers also observed the new malware at organizations previously targeted with SparrowDoor.
Importantly, SparroWocky is not simply a new version of SparrowDoor. Researchers describe it as a separate malware family designed with greater modularity, stealth and anti-analysis capabilities.
What Can SparroWocky Do?
Once deployed, SparroWocky gives attackers extensive remote-control capabilities, including:
- Executing arbitrary commands and files
- Uploading and exfiltrating files
- Taking periodic screenshots
- Collecting usernames, hostnames, Windows versions and IP addresses
- Creating, copying, moving and deleting files
- Acting as a TCP proxy
- Establishing persistence
- Executing additional payloads directly in memory
- Loading Beacon Object Files (BOFs) used by various offensive-security frameworks
Stolen information is encrypted using RC4 before being transmitted to command-and-control (C2) infrastructure over TLS.
Designed to Evade Detection
SparroWocky includes several advanced defense-evasion techniques.
The malware can manipulate low-level Windows memory structures, patch code during runtime and spoof call stacks to make malicious activity appear to originate from legitimate code.
Its loader also uses DLL side-loading, combining a legitimate executable, a malicious DLL and an encrypted .dat payload.
The final backdoor is reflectively loaded into memory rather than written normally to disk, potentially making traditional file-based detection more difficult.
FamousSparrow has also integrated code from legitimate open-source projects, including Mbed TLS, MinHook, COFF Loader and techniques derived from SilentMoonwalk/StackMoonwalk.
Government Organizations Heavily Targeted
ESET observed SparroWocky targeting government entities across:
| Region | Observed Targeting |
|---|---|
| Argentina | Government |
| Ecuador | Government |
| Guatemala | Government |
| Honduras | Government |
| Panama | Government |
| Peru | Government |
| Puerto Rico | Government |
| Venezuela | Government |
ESET assesses that the regional concentration may be connected to geopolitical intelligence requirements involving Chinese interests and U.S. activity in Latin America. That interpretation is ESET's assessment of the targeting pattern, rather than independently established evidence of the attackers' specific instructions or motives.
About FamousSparrow
FamousSparrow is a cyberespionage group that ESET describes as China-aligned and active since at least 2019.
The group was publicly documented in 2021 after researchers observed it exploiting Microsoft Exchange ProxyLogon vulnerabilities.
Its historical targets have included governments, hotels, international organizations, engineering companies, trade organizations and law firms. Researchers have reported links between FamousSparrow and Earth Estries, although ESET says the precise relationship remains unclear. FamousSparrow has also been publicly linked with Salt Typhoon, but ESET continues to track the groups separately because it says sufficient technical evidence connecting them is lacking.
Security Takeaway
The emergence of SparroWocky demonstrates a significant evolution in FamousSparrow's cyberespionage capabilities.
The combination of in-memory execution, DLL side-loading, call-stack spoofing, encrypted C2 communications, BOF execution and extensive remote-control functionality makes the malware particularly relevant for SOC and threat-hunting teams.
Organizations—especially government entities in Latin America—should monitor for unusual DLL side-loading, suspicious service or Run-key persistence, unexpected in-memory execution, abnormal TLS connections and unauthorized proxy activity.
Related reporting
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT Malware via ClickFix
Attackers abuse ChatGPT Custom GPTs and sponsored Google results to redirect victims to ClickFix pages that execute PowerShell and install remote access trojan malware.
Star Blizzard Targets 100+ Organizations With Fake Event Invites and CosmicPulse Backdoor
Russia-linked Star Blizzard targets more than 100 organizations using fake event invitations, the new RedFlick malware delivery technique and the CosmicPulse Windows backdoor.
101 Malicious npm Packages Secretly Add Developers to WhatsApp Groups
Researchers uncover 101 malicious npm packages in the PhantomSub campaign that abuse authenticated WhatsApp sessions to secretly add developers to attacker-controlled groups and channels.


