ZeroHour
Product

SparroWocky

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America

China-aligned espionage group FamousSparrow replaced SparrowDoor with a new modular backdoor, SparroWocky, targeting government entities across eight Latin American countries since August 2025.

ESET researchers report that China-aligned state-sponsored group FamousSparrow, active since at least 2019 and overlapping with Earth Estries and Salt Typhoon, has deployed a previously unreported modular C++ backdoor named SparroWocky in attacks on Latin America since at least August 2025. The implant replaces SparrowDoor as the group's primary tool and supports file execution, TCP proxying, command execution, screenshots, exfiltration, and self-deletion, using Mbed TLS, MinHook, COFF Loader, and SilentMoonwalk-style call-stack spoofing. Delivery occurs via a DLL sideloading chain; the initial access vector is unknown. About 90% of observed targets are in the region, including government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.

The Hacker Newsupdated · 14m agofirst · 5h agoThreat actor in the wild 5 sources

Chinese hackers use SparroWocky malware in govt espionage attacks

ESET reports China-linked FamousSparrow deployed a new modular backdoor, SparroWocky, in year-long espionage attacks on Latin American government organizations.

ESET researchers observed FamousSparrow using SparroWocky, a modular C++ backdoor replacing the earlier SparrowDoor tool, against government targets in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. Deployed via DLL side-loading with an RC4-encrypted payload mapped in memory, it captures screenshots, acts as a TCP proxy, and hooks CreateThread so malicious threads appear as AnimateWindow. Persistence uses a ProcAuditManager Windows service or SnapCart registry key; ESET tracked at least 18 C2 addresses and published IoCs.

BleepingComputerupdated · 14m agofirst · 6h agoThreat actor in the wild 5 sources

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.