Beware the SparroWock: The backdoor that bites, the commands that catch
ESET attributes a new modular C++ backdoor, SparroWocky, to China-aligned group FamousSparrow, deployed against government entities across Latin America since August 2025.
ESET Research reports that the China-aligned espionage group FamousSparrow, active since at least 2019, has replaced its SparrowDoor implant with a new custom backdoor dubbed SparroWocky since August 2025. The modular C++ backdoor manipulates low-level memory structures, patches code at runtime to evade detection, and can load and execute Beacon Object Files. Since mid-2025, roughly 90% of the group's targets have been in Latin America, including governmental organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. ESET links the regional pivot to China's response to renewed US interest in the region, citing Panama's dispute over canal-area ports as a likely intelligence objective.