ZeroHour
Victim

Governments of Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, Venezuela

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

FamousSparrow Exploits Public-Facing Exchange Servers to Deploy SparroWocky Backdoor

ESET attributes a new SparroWocky backdoor to espionage group FamousSparrow, deployed via exploited internet-facing Exchange servers across Latin American governments.

ESET's Welivesecurity team reports FamousSparrow gained initial access by exploiting publicly reachable Microsoft Exchange servers, with roughly 90 percent of targets since mid-2025 in Latin America, including governments in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The group's new modular C-language backdoor SparroWocky replaces SparrowDoor and uses a three-part loader: a legitimate executable, a malicious DLL side-loaded in memory, and an encrypted payload. It persists via Windows services or Registry Run keys, supports screenshots, file operations, TCP proxying, Beacon Object Files, TLS/RC4-encrypted C2, and anti-forensics such as call-stack spoofing. IOCs including loader SHA-1 hashes and C2 IP addresses were published.

Cyber Security Newsupdated · 19m agofirst · 3h agoThreat actor in the wild 5 sources

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.