FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoornew
China-aligned FamousSparrow deployed its new SparroWocky backdoor against Latin American governments since August 2025, initially accessing networks via exploited Exchange servers.
ESET attributes the SparroWocky campaign to FamousSparrow with high confidence, partly because early infections were delivered via the group's exclusive SparrowDoor implant. Since at least August 2025, the modular C++ backdoor was found at government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela, with 90% of the group's mid-2025 telemetry targets in the region. SparroWocky supports command execution, file execution, TCP proxying, host reconnaissance, screenshot capture, RC4-encrypted TLS exfiltration, and Cobalt Strike BOF loading, using runtime patching and call-stack forging for evasion. ESET links the regional focus to China's response to renewed US interest in Latin America and notes a possible, unclear link to Trend Micro's Earth Estries.