FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor
China-aligned FamousSparrow deployed its new SparroWocky backdoor against Latin American governments since August 2025, initially accessing networks via exploited Exchange servers.
ESET attributes the SparroWocky campaign to FamousSparrow with high confidence, partly because early infections were delivered via the group's exclusive SparrowDoor implant. Since at least August 2025, the modular C++ backdoor was found at government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela, with 90% of the group's mid-2025 telemetry targets in the region. SparroWocky supports command execution, file execution, TCP proxying, host reconnaissance, screenshot capture, RC4-encrypted TLS exfiltration, and Cobalt Strike BOF loading, using runtime patching and call-stack forging for evasion. ESET links the regional focus to China's response to renewed US interest in Latin America and notes a possible, unclear link to Trend Micro's Earth Estries.
- SparroWocky is a distinct family, not a SparrowDoor variant
- 90% of ESET telemetry targets from mid-2025 were in Latin America
- Initial access achieved via publicly reachable Exchange servers
- Evasion uses runtime code patching and forged Windows API call stacks
- Panamanian target involved in port concession dispute with China-based company
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-26855 | Unauthenticated SSRF/RCE in Microsoft Exchange Server (ProxyLogon) CVE-2021-26855 is a server-side request forgery flaw (CWE-918) in Microsoft Exchange Server that allows an unauthenticated remote attacker to send specially crafted HTTP requests and have the Exchange server process them as itself, disclosing sensitive session information. When chained with sibling Exchange flaws (the 'ProxyLogon' chain), it yields authentication bypass and arbitrary file write, escalating to full remote code execution with SYSTEM-level privileges on the on-premises Exchange server. Any organization running an affected on-premises Exchange server reachable over HTTP/HTTPS (typically outbound webmail) is exposed; Exchange Online was not affected. Exploitation is confirmed in the wild at large scale: the flaw was mass-exploited beginning in early 2021 (notably by the HAFNIUM group), is on the CISA KEV with documented ransomware use, and has a maximum EPSS score of 100% (100th percentile), despite no public PoC listing. Do: Apply the vendor's March 2021 Exchange security updates (or later cumulative updates) immediately, per the CISA required action; until patched, limit Exchange (ECP/OWA) exposure to the internet via firewall/VPN rules. Hunt for compromise: review IIS logs for unrecognized authenticated activity against FrontEnd HttpProxy endpoints, and check for malicious files or webshells under inetpub\wwwroot\aspnet_client, given the known ransomware use. | 9.1 | 100% | KEV ransomware PoC ×4 |
| masshundreds of thousands of on-premises deployments; tens of thousands of internet-exposed Exchange servers |
Full article479 words · extracted from infosecurity-magazine.com · click to collapse
The threat actor known as FamousSparrow has replaced its long-running SparrowDoor implant with a new backdoor called SparroWocky, and has been deploying it against governments across Latin America since at least August 2025.
ESET Research attributed the campaign to the China-aligned group with high confidence, partly because some of the earliest SparroWocky infections were delivered by SparrowDoor, which only FamousSparrow is known to use. It found the backdoor at government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela.
From mid-2025 into 2026, 90% of the group's targets in ESET telemetry sat in the region. The company called that rare among the China-aligned groups it tracks, which are usually seen across several parts of the world over a period that long.
FamousSparrow gained access by exploiting publicly reachable Exchange servers.
A Distinct Family, Not a SparrowDoor Variant
ESET was explicit that SparroWocky is not a SparrowDoor variant but a separate family, though it carries over some of the older backdoor's functions.
The modular C++ backdoor can run commands, execute files, act as a TCP proxy, collect host and network details, exfiltrate files and take screenshots on a repeating cycle. Exfiltrated data is encrypted with RC4 and sent over TLS.
It also loads and executes Beacon Object Files (BOF), a format introduced in Cobalt Strike and since adopted by other red-teaming frameworks. ESET said that marks a shift: FamousSparrow previously ran open-source offensive tools beside its own malware and now builds its code into it.
The developers put significant effort into developing evasion capabilities. SparroWocky patches code at runtime, forges call stacks so Windows API calls appear to come from legitimate thread entry points, and hooks thread creation so its own threads report a harmless start address.
Read more on FamousSparrow: Chinese Spy Group FamousSparrow Back with a Vengeance, Targets US
Latin America the Primary Target
ESET said the group narrowed to almost exclusively targeting the region in July 2025, a month before SparroWocky appeared.
It assessed the focus as China's likely reaction to renewed US interest in the region under Donald Trump's second term, which ESET said could threaten Chinese investments built up over a decade in energy, mining and telecommunications.
One case appeared to support this assessment. A Panamanian entity ESET saw targeted is directly involved in the dispute over two major ports in the canal area, run until recently by a China-based company whose concession the Panamanian government challenged in early 2025.
ESET said it could not tell whether the regional focus reflects a formal geographic mandate or is temporary and driven by current circumstances.
The group has been active since at least 2019 and was first documented in 2021 exploiting ProxyLogon. Trend Micro has linked it to Earth Estries, though ESET said that link is not fully understood, and it tracks FamousSparrow separately from Salt Typhoon for want of technical indicators.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/famoussparrow-sparrowocky-latin/