← All stories
● Covered by 2 sources · 2 reportsMedium impact1 negative1 neutral

China-Aligned FamousSparrow Group Deploys New SparroWocky Backdoor in Latin America

🔄 Updated 6d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • FamousSparrow is deploying a new C++ backdoor, SparroWocky, since August 2025.
  • Targets include government agencies in Guatemala, Honduras, Panama, Venezuela, Peru, Argentina, and Puerto Rico.
  • SparroWocky replaces SparrowDoor as the group's main implant.
  • Capabilities include file execution, TCP proxy, command execution, and information collection.
  • The campaign may monitor Latin American government responses to U.S. pressures.

New Backdoor Identified

The China-aligned state-sponsored threat actor known as FamousSparrow has been observed using a previously unreported backdoor named SparroWocky. This new modular C++ backdoor has been deployed in attacks targeting multiple countries in Latin America since at least August 2025.

Targeted Regions and Capabilities

ESET security researchers Alexandre Côté Cyr and Romain Dumont reported that attacks have been tracked against government departments in Guatemala, Honduras, Puerto Rico, Panama, Venezuela, Peru, and Argentina. SparroWocky is designed with anti-analysis techniques and knowledge of Windows internals.

The backdoor's functionalities include the ability to execute arbitrary files, act as a TCP proxy, run commands, and collect general system information. It has replaced SparrowDoor as FamousSparrow's primary implant.

Attribution and Naming

FamousSparrow has been active since at least 2019 and shares some overlap with other groups like Earth Estries and Salt Typhoon. The name 'SparroWocky' comes from early versions of the malware containing the first stanza of Lewis Carroll's poem 'Jabberwocky'.

Strategic Motivation

Researchers theorize that China's focus on Latin America with this campaign is linked to U.S. President Donald Trump's renewed focus on the region. The campaign is likely intended to help China monitor and anticipate the reactions of local governments to current U.S. pressures regarding Chinese investments in the region.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~26 min · 21 stories · Sep 23

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The Chinese hacking group FamousSparrow is using a new backdoor, dubbed "SparroWocky," to target government agencies across Latin America. This campaign, ongoing since at least August 2025, is believed to be related to monitoring local government reactions to U.S. pressures in the region. The SparroWocky backdoor allows for data exfiltration and system information collection, indicating a sophisticated cyberespionage effort.

The China-aligned threat actor FamousSparrow has been observed using a new C++ backdoor called SparroWocky in attacks targeting Latin American countries since August 2025. This new backdoor replaces SparrowDoor as the group's primary implant and integrates open-source code for enhanced capabilities and evasion techniques.