Skip to main content
Emerging ThreatsMalware & Ransomware

FamousSparrow Deploys SparroWocky Backdoor in Latin America Push

Government building in Latin America with subtle tech integration details.

Since at least August 2025, the China-aligned threat actor FamousSparrow has been deploying a new backdoor called SparroWocky against government targets across Latin America, according to analysis published by ESET Research.

SparroWocky: a distinct backdoor family

ESET Research was explicit that SparroWocky is not a SparrowDoor variant but a separate family, even though it carries over some of SparrowDoor’s functions. The new implant is a modular C++ backdoor capable of a broad set of actions — running commands, executing files, acting as a TCP proxy, collecting host and network details, exfiltrating files and taking screenshots on a repeating cycle. ESET found SparroWocky at government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela.

Evasion techniques and a move toward embedded offensive code

ESET’s write-up emphasizes significant effort by the developers to evade detection. SparroWocky patches code at runtime, forges call stacks so Windows API calls appear to originate from legitimate thread entry points, and hooks thread creation so its own threads report a harmless start address. Exfiltrated data is encrypted with RC4 and transmitted over TLS.

Notably, SparroWocky can load and execute Beacon Object Files (BOF) — a format introduced in Cobalt Strike and since adopted by other frameworks. ESET interprets that capability as a change in tradecraft: where FamousSparrow previously ran open-source offensive tools alongside its own malware, it now embeds that functionality directly into its backdoor.

Delivery and attribution tied to SparrowDoor and Exchange exploitation

In ESET’s telemetry, some of the earliest SparroWocky infections were delivered by SparrowDoor, an implant that ESET says only FamousSparrow is known to use. That overlap contributed to ESET’s high-confidence attribution of the campaign to the China-aligned group. ESET also reported that FamousSparrow gained access by exploiting publicly reachable Exchange servers.

Latin America as a concentrated target set

ESET found that from mid-2025 into 2026, 90% of FamousSparrow’s targets in its telemetry sat in Latin America — a pattern ESET called rare among China-aligned groups it tracks, which are usually seen across several regions over comparable periods. The company said the group narrowed to almost exclusively targeting the region in July 2025, a month before SparroWocky first appeared.

ESET proposed a geopolitical reading of that focus: it assessed the targeting as "China's likely reaction to renewed US interest in the region under Donald Trump's second term," a dynamic ESET said could threaten Chinese investments built up over a decade in energy, mining and telecommunications. One case that appears to support the assessment involved a Panamanian entity targeted by the campaign; that entity is directly involved in the dispute over two major ports in the canal area, previously run by a China-based company whose concession the Panamanian government challenged in early 2025. ESET said it could not determine whether the regional focus reflects a formal geographic mandate or is temporary and driven by current circumstances.

What this means for technologists, policymakers, and affected governments

  • Technologists and security teams: ESET’s findings point to Exchange servers as a primary access vector and to a backdoor that embeds BOF execution and advanced evasion. Teams should be alert for evidence of both SparrowDoor and SparroWocky behaviors — notably RC4-encrypted exports over TLS, unusual thread start addresses, and forged call stacks — when investigating intrusions.
  • Policymakers and regulators: The concentration of intrusions in Latin America and the connection ESET draws to regional economic disputes highlight how cyber operations can map onto diplomatic and commercial frictions. Policymakers will need to weigh incident response and disclosure choices alongside geopolitical and commercial considerations specific to affected ports and infrastructure.
  • Affected governments and enterprises: Governments in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela should treat ESET’s telemetry as a direct warning of targeted activity. The reported use of Exchange exploitation and SparrowDoor as a delivery stage implies that discovery of one implant could indicate follow-on SparroWocky presence.

FamousSparrow’s switch from SparrowDoor to a distinct, stealthier family that incorporates embedded offensive tooling, combined with a tight geographic focus, raises a pointed operational question ESET could not resolve: is this a tasking-driven pivot tied to specific regional disputes, or a temporary campaign shaped by the moment? The answer will determine whether SparroWocky is the start of a broader strategic effort in Latin America or a shorter-term campaign linked to discrete diplomatic and commercial tensions.

Source: Infosecurity Magazine — FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor