ZeroHour
Story · 9 sources · 9 articlesfirst updated ()

FamousSparrow swaps SparrowDoor for new SparroWocky backdoor in espionage on Latin American governments

highThreat actorexploited in the wildimportance 78CVE-2021-26855
What's new: First merged summary for this story — no prior dashboard entry. Key developments established by this merge: (1) FamousSparrow has abandoned SparrowDoor in favor of the new SparroWocky backdoor since August 2025; (2) the group's targeting has pivoted to Latin America, with about 90% of targets since mid-2025 in the region, mostly government organizations; (3) ESET links the regional focus to…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

ESET attributes a previously unreported modular C++ backdoor, SparroWocky, deployed against government entities in eight Latin American countries and territories since at least August 2025 to the China-aligned espionage group FamousSparrow; roughly 90% of the…

ESET Research (report by researcher Alexandre Côté Cyr, published 2026-09-17) attributes the SparroWocky campaign with high confidence to FamousSparrow, a Chinese espionage group active since at least 2019 and first publicly named by ESET in 2021 — partly because early infections were delivered via the group's then-exclusive SparrowDoor implant. Since August 2025 (one report dates targeting to July 2025), the group has replaced SparrowDoor with SparroWocky, a distinct modular C++ backdoor rather than a SparrowDoor variant, found at government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela; one report lists only seven countries. About 90% of the group's targets since mid-2025 are in Latin America, which ESET links to China's response to renewed US engagement in the region, citing a Panamanian entity involved in a dispute over canal-area ports with a China-based company as a likely intelligence objective. SparroWocky is delivered via a three-component DLL side-loading chain (legitimate executable, malicious DLL, RC4-encrypted payload mapped directly in memory) and persists via a ProcAuditManager Windows service or a SnapCart registry Run key. It supports command and file execution, TCP proxying, screenshots, host reconnaissance, file exfiltration, self-deletion, in-memory plugin and Beacon Object File loading (COFF Loader), and embeds nearly 30 commands plus a stanza of Lewis Carroll's 'Jabberwocky.' Evasion includes runtime code patching, API hashing, hooking CreateThread so malicious threads appear as AnimateWindow, and SilentMoonwalk-style call-stack spoofing; it uses Mbed TLS, MinHook, and RC4-encrypted C2 over ports 443 and 8080. Initial access is disputed: several reports state the group exploited publicly reachable Microsoft Exchange servers (ProxyLogon, CVE-2021-26855), while one says the initial access vector is unknown. ESET published IoCs including loader SHA-1 hashes and C2 IP addresses; sources disagree on the count, with one citing at least 18 tracked C2 addresses and another citing IoCs for three C2 servers. Naming should be handled carefully: ESET tracks the group as FamousSparrow, overlapping with Earth Estries and publicly linked to Salt Typhoon, though one outlet framed the activity as Salt Typhoon and reports differ on whether ESET treats it as overlapping with or separate from Salt Typhoon.

  • ESET attributes the SparroWocky backdoor campaign to the China-aligned espionage group FamousSparrow with high confidence, partly because early infections were delivered via the group's exclusive SparrowDoor implant
  • FamousSparrow has been active since at least 2019 and was first publicly named by ESET in 2021; it overlaps with Earth Estries and has been publicly linked to Salt Typhoon, though ESET has reportedly tracked it separately from Salt Typhoon…
  • SparroWocky replaces SparrowDoor as the group's primary implant starting August 2025 and is a distinct modular C++ backdoor family, not a SparrowDoor variant (one report dates targeting to July 2025)
  • Targets are government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela; approximately 90% of the group's targets since mid-2025 are in Latin America (one report lists only seven countries and…
  • ESET assesses the campaign likely responds to renewed US interest and pressure in Latin America; a Panamanian target involved in a dispute over canal-area ports with a China-based company is cited as a likely intelligence objective
  • Delivery uses a three-component DLL side-loading chain (legitimate executable, malicious DLL, encrypted payload) with an RC4-encrypted payload mapped directly into memory; initial access is disputed — several reports cite exploitation of…
  • Persistence is achieved via a ProcAuditManager Windows service or a SnapCart registry Run key
  • Capabilities include command and file execution, TCP proxying, screenshots, host reconnaissance (collecting IP addresses and usernames), file exfiltration, self-deletion, in-memory plugin loading, and Beacon Object File execution, with…

Coverage timeline

  1. · 1d ago
    ESET WeLiveSecurity· 75
    Beware the SparroWock: The backdoor that bites, the commands that catch

    ESET attributes a new modular C++ backdoor, SparroWocky, to China-aligned group FamousSparrow, deployed against government entities across Latin America since August 2025.

  2. · 1d ago
    BleepingComputer· 70
    Chinese hackers use SparroWocky malware in govt espionage attacks

    ESET reports China-linked FamousSparrow deployed a new modular backdoor, SparroWocky, in year-long espionage attacks on Latin American government organizations.

  3. · 1d ago
    The Hacker News· 74
    China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America

    China-aligned espionage group FamousSparrow replaced SparrowDoor with a new modular backdoor, SparroWocky, targeting government entities across eight Latin American countries since August 2025.

  4. · 1d ago
    GBHackers· 78
    FamousSparrow Deploys New SparroWocky Backdoor Against Latin American Governments

    China-aligned APT FamousSparrow deployed a new modular backdoor, SparroWocky, against government entities across eight Latin American countries since August 2025, ESET reports.

  5. · 1d ago
    Cyber Security News· 78
    FamousSparrow Exploits Public-Facing Exchange Servers to Deploy SparroWocky Backdoor

    ESET attributes a new SparroWocky backdoor to espionage group FamousSparrow, deployed via exploited internet-facing Exchange servers across Latin American governments.

  6. · 1d ago
    Infosecurity Magazine· 78
    FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor

    China-aligned FamousSparrow deployed its new SparroWocky backdoor against Latin American governments since August 2025, initially accessing networks via exploited Exchange servers.

  7. · 22h ago
    The Record· 78
    China’s FamousSparrow hackers target Latin America with new backdoor

    ESET links a new SparroWocky backdoor campaign against Latin American government agencies to Chinese espionage group FamousSparrow.

  8. · 21h ago
    The Register · Security· 76
    China's Salt Typhoon backdoors Latin American orgs with new snooping malware

    China-linked Salt Typhoon deployed new modular backdoor SparroWocky against Latin American government agencies since August 2025.

  9. · 19h ago
    Dark Reading· 58
    China's FamousSparrow APT Spies on US Politics in Latin America

    China-linked APT FamousSparrow is running a stealthy backdoor espionage campaign targeting US political interests in Latin America.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-26855
Unauthenticated SSRF/RCE in Microsoft Exchange Server (ProxyLogon)

CVE-2021-26855 is a server-side request forgery flaw (CWE-918) in Microsoft Exchange Server that allows an unauthenticated remote attacker to send specially crafted HTTP requests and have the Exchange server process them as itself, disclosing sensitive session information. When chained with sibling Exchange flaws (the 'ProxyLogon' chain), it yields authentication bypass and arbitrary file write, escalating to full remote code execution with SYSTEM-level privileges on the on-premises Exchange server. Any organization running an affected on-premises Exchange server reachable over HTTP/HTTPS (typically outbound webmail) is exposed; Exchange Online was not affected. Exploitation is confirmed in the wild at large scale: the flaw was mass-exploited beginning in early 2021 (notably by the HAFNIUM group), is on the CISA KEV with documented ransomware use, and has a maximum EPSS score of 100% (100th percentile), despite no public PoC listing.

Do: Apply the vendor's March 2021 Exchange security updates (or later cumulative updates) immediately, per the CISA required action; until patched, limit Exchange (ECP/OWA) exposure to the internet via firewall/VPN rules. Hunt for compromise: review IIS logs for unrecognized authenticated activity against FrontEnd HttpProxy endpoints, and check for malicious files or webshells under inetpub\wwwroot\aspnet_client, given the known ransomware use.

9.1100% KEV ransomware PoC ×4
  • Microsoft Exchange Server On-premises Exchange Server editions supported in the vendor's March 2021 guidance (Exchange Server 2013, 2016, and 2019), prior to the March 2021 security upda
masshundreds of thousands of on-premises deployments; tens of thousands of internet-exposed Exchange servers