The China-aligned state-sponsored threat actor known as FamousSparrow has been observed using a previously unreported backdoor named SparroWocky. This new modular C++ backdoor has been deployed in attacks targeting multiple countries in Latin America since at least August 2025.
ESET security researchers Alexandre Côté Cyr and Romain Dumont reported that attacks have been tracked against government departments in Guatemala, Honduras, Puerto Rico, Panama, Venezuela, Peru, and Argentina. SparroWocky is designed with anti-analysis techniques and knowledge of Windows internals.
The backdoor's functionalities include the ability to execute arbitrary files, act as a TCP proxy, run commands, and collect general system information. It has replaced SparrowDoor as FamousSparrow's primary implant.
FamousSparrow has been active since at least 2019 and shares some overlap with other groups like Earth Estries and Salt Typhoon. The name 'SparroWocky' comes from early versions of the malware containing the first stanza of Lewis Carroll's poem 'Jabberwocky'.
Researchers theorize that China's focus on Latin America with this campaign is linked to U.S. President Donald Trump's renewed focus on the region. The campaign is likely intended to help China monitor and anticipate the reactions of local governments to current U.S. pressures regarding Chinese investments in the region.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The Chinese hacking group FamousSparrow is using a new backdoor, dubbed "SparroWocky," to target government agencies across Latin America. This campaign, ongoing since at least August 2025, is believed to be related to monitoring local government reactions to U.S. pressures in the region. The SparroWocky backdoor allows for data exfiltration and system information collection, indicating a sophisticated cyberespionage effort.
The China-aligned threat actor FamousSparrow has been observed using a new C++ backdoor called SparroWocky in attacks targeting Latin American countries since August 2025. This new backdoor replaces SparrowDoor as the group's primary implant and integrates open-source code for enhanced capabilities and evasion techniques.