ZeroHour
Threat actor

Earth Estries

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoornew

China-aligned FamousSparrow deployed its new SparroWocky backdoor against Latin American governments since August 2025, initially accessing networks via exploited Exchange servers.

ESET attributes the SparroWocky campaign to FamousSparrow with high confidence, partly because early infections were delivered via the group's exclusive SparrowDoor implant. Since at least August 2025, the modular C++ backdoor was found at government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela, with 90% of the group's mid-2025 telemetry targets in the region. SparroWocky supports command execution, file execution, TCP proxying, host reconnaissance, screenshot capture, RC4-encrypted TLS exfiltration, and Cobalt Strike BOF loading, using runtime patching and call-stack forging for evasion. ESET links the regional focus to China's response to renewed US interest in Latin America and notes a possible, unclear link to Trend Micro's Earth Estries.

China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America

China-aligned espionage group FamousSparrow replaced SparrowDoor with a new modular backdoor, SparroWocky, targeting government entities across eight Latin American countries since August 2025.

ESET researchers report that China-aligned state-sponsored group FamousSparrow, active since at least 2019 and overlapping with Earth Estries and Salt Typhoon, has deployed a previously unreported modular C++ backdoor named SparroWocky in attacks on Latin America since at least August 2025. The implant replaces SparrowDoor as the group's primary tool and supports file execution, TCP proxying, command execution, screenshots, exfiltration, and self-deletion, using Mbed TLS, MinHook, COFF Loader, and SilentMoonwalk-style call-stack spoofing. Delivery occurs via a DLL sideloading chain; the initial access vector is unknown. About 90% of observed targets are in the region, including government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.

The Hacker Newsupdated · 14m agofirst · 5h agoThreat actor in the wild 5 sources

Related CVEs

  • Unauthenticated SSRF/RCE in Microsoft Exchange Server (ProxyLogon)
    CVE-2021-26855 is a server-side request forgery flaw (CWE-918) in Microsoft Exchange Server that allows an unauthenticated remote attacker to send specially crafted HTTP requests and have the Exchange server process them as itself, disclosing sensitive session information. When chained with sibling Exchange flaws (the 'ProxyLogon' chain), it yields authentication bypass and arbitrary file write, escalating to full remote code execution with SYSTEM-level privileges on the on-premises Exchange server. Any organization running an affected on-premises Exchange server reachable over HTTP/HTTPS (typically outbound webmail) is exposed; Exchange Online was not affected. Exploitation is confirmed in the wild at large scale: the flaw was mass-exploited beginning in early 2021 (notably by the HAFNIUM group), is on the CISA KEV with documented ransomware use, and has a maximum EPSS score of 100% (100th percentile), despite no public PoC listing.
    · Microsoft Exchange Server On-premises Exchange Server editions supported in the vendor's March 2021 guidance (Exchange Server 2013, 2016, and 2019), prior to the March 2021 security upda KEV ransomware PoC ×4mass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.