China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
China-aligned espionage group FamousSparrow replaced SparrowDoor with a new modular backdoor, SparroWocky, targeting government entities across eight Latin American countries since August 2025.
ESET researchers report that China-aligned state-sponsored group FamousSparrow, active since at least 2019 and overlapping with Earth Estries and Salt Typhoon, has deployed a previously unreported modular C++ backdoor named SparroWocky in attacks on Latin America since at least August 2025. The implant replaces SparrowDoor as the group's primary tool and supports file execution, TCP proxying, command execution, screenshots, exfiltration, and self-deletion, using Mbed TLS, MinHook, COFF Loader, and SilentMoonwalk-style call-stack spoofing. Delivery occurs via a DLL sideloading chain; the initial access vector is unknown. About 90% of observed targets are in the region, including government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.