ZeroHour
Country

Peru

4 mentions in 7 days · 4 in 30 days · 4 total · first seen · last

Timeline

FamousSparrow Exploits Public-Facing Exchange Servers to Deploy SparroWocky Backdoor

ESET attributes a new SparroWocky backdoor to espionage group FamousSparrow, deployed via exploited internet-facing Exchange servers across Latin American governments.

ESET's Welivesecurity team reports FamousSparrow gained initial access by exploiting publicly reachable Microsoft Exchange servers, with roughly 90 percent of targets since mid-2025 in Latin America, including governments in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The group's new modular C-language backdoor SparroWocky replaces SparrowDoor and uses a three-part loader: a legitimate executable, a malicious DLL side-loaded in memory, and an encrypted payload. It persists via Windows services or Registry Run keys, supports screenshots, file operations, TCP proxying, Beacon Object Files, TLS/RC4-encrypted C2, and anti-forensics such as call-stack spoofing. IOCs including loader SHA-1 hashes and C2 IP addresses were published.

Cyber Security News · 3h agoThreat actor in the wild 4 sources

FamousSparrow Deploys New SparroWocky Backdoor Against Latin American Governments

China-aligned APT FamousSparrow deployed a new modular backdoor, SparroWocky, against government entities across eight Latin American countries since August 2025, ESET reports.

ESET reports that China-aligned threat actor FamousSparrow replaced its SparrowDoor implant with SparroWocky, a distinct modular C++ backdoor active against governments in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. Around 90% of the group's targets from mid-2025 into 2026 were in Latin America, which ESET links to regional competition over US influence. The backdoor arrives via a three-component DLL side-loading chain, persists through a Windows service (ProcAuditManager) or Run keys (SnapCart), captures screenshots, and exfiltrates RC4-encrypted data over TLS C2 on ports 443 and 8080. It supports in-memory Beacon Object File execution, API hashing, and SilentMoonwalk-style call-stack spoofing; IOCs for three C2 servers were released.

GBHackersupdated · 3h agofirst · 3h agoThreat actor in the wild 4 sourcesCVE-2021-26855

China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin Americanew

China-aligned espionage group FamousSparrow replaced SparrowDoor with a new modular backdoor, SparroWocky, targeting government entities across eight Latin American countries since August 2025.

ESET researchers report that China-aligned state-sponsored group FamousSparrow, active since at least 2019 and overlapping with Earth Estries and Salt Typhoon, has deployed a previously unreported modular C++ backdoor named SparroWocky in attacks on Latin America since at least August 2025. The implant replaces SparrowDoor as the group's primary tool and supports file execution, TCP proxying, command execution, screenshots, exfiltration, and self-deletion, using Mbed TLS, MinHook, COFF Loader, and SilentMoonwalk-style call-stack spoofing. Delivery occurs via a DLL sideloading chain; the initial access vector is unknown. About 90% of observed targets are in the region, including government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.

The Hacker Newsupdated · 3h agofirst · 4h agoThreat actor in the wild 4 sources

Chinese hackers use SparroWocky malware in govt espionage attacks

ESET reports China-linked FamousSparrow deployed a new modular backdoor, SparroWocky, in year-long espionage attacks on Latin American government organizations.

ESET researchers observed FamousSparrow using SparroWocky, a modular C++ backdoor replacing the earlier SparrowDoor tool, against government targets in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. Deployed via DLL side-loading with an RC4-encrypted payload mapped in memory, it captures screenshots, acts as a TCP proxy, and hooks CreateThread so malicious threads appear as AnimateWindow. Persistence uses a ProcAuditManager Windows service or SnapCart registry key; ESET tracked at least 18 C2 addresses and published IoCs.

BleepingComputerupdated · 3h agofirst · 5h agoThreat actor in the wild 4 sources

Related CVEs

  • Unauthenticated SSRF/RCE in Microsoft Exchange Server (ProxyLogon)
    CVE-2021-26855 is a server-side request forgery flaw (CWE-918) in Microsoft Exchange Server that allows an unauthenticated remote attacker to send specially crafted HTTP requests and have the Exchange server process them as itself, disclosing sensitive session information. When chained with sibling Exchange flaws (the 'ProxyLogon' chain), it yields authentication bypass and arbitrary file write, escalating to full remote code execution with SYSTEM-level privileges on the on-premises Exchange server. Any organization running an affected on-premises Exchange server reachable over HTTP/HTTPS (typically outbound webmail) is exposed; Exchange Online was not affected. Exploitation is confirmed in the wild at large scale: the flaw was mass-exploited beginning in early 2021 (notably by the HAFNIUM group), is on the CISA KEV with documented ransomware use, and has a maximum EPSS score of 100% (100th percentile), despite no public PoC listing.
    · Microsoft Exchange Server On-premises Exchange Server editions supported in the vendor's March 2021 guidance (Exchange Server 2013, 2016, and 2019), prior to the March 2021 security upda KEV ransomware PoC ×4mass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.