Chinese hackers use SparroWocky malware in govt espionage attacks
ESET said the modular C++ malware uses stealth techniques and has hit government agencies in eight Latin American jurisdictions since at least August 2025.
- On Thursday, ESET reported that the China-backed Salt Typhoon espionage group deployed a new modular backdoor called SparroWocky against high-profile organizations across Latin America since at least August 2025.
- The PRC-backed group shifted its operational focus to Latin America a month prior, with 90 percent of its targets located in that region from mid-2025 through 2026, ESET said.
- SparroWocky integrates open-source tools including Mbed TLS, MinHook, and COFF Loader alongside API-hashing to evade security software by spoofing call stacks and executing in-memory plugins.
- The backdoor supports nearly 30 commands including stealing files, taking screenshots, and collecting session IDs via WTSEnumerateSessionsW, enabling long-term stealthy access to compromised networks.
- Operating since 2019, Salt Typhoon communicates with command-and-control servers using TLS encryption over port 443 or 8080, enabling persistent stealthy connections within victim organizations.
16 Articles
16 Articles
Salt Typhoon shifts heavily into Latin America with new SparroWocky backdoor
ESET says China-linked Salt Typhoon, tracked as FamousSparrow, has been deploying the new SparroWocky backdoor against government networks in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela since at least August 2025....
China's FamousSparrow Turns to Latin America With Stealthy SparroWocky Backdoor
ESET researchers have exposed FamousSparrow's intense focus on Latin American governments using a new modular backdoor called SparroWocky. The China-aligned group shifted 90% of its targeting to the region since mid-2025, likely to track reactions to U.S. pressure on Chinese interests. The sophisticated memory-resident malware replaces the group's prior SparrowDoor implant and features advanced anti-analysis techniques. This campaign highlights …
Chinese hackers use SparroWocky malware in govt espionage attacks
The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America.
ESET Latin America identified the deployment of the cyber-espionage group linked to China against government entities from Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela, since August 2025. ESET reveals new movements of the cyber-criminal group of the type APT - prolonged and stealthy cyberattack where an intruder gets access to a network and remains hidden [...] The entry Group linked to China spy in Latin Amer…
Coverage Details
Bias Distribution
- 60% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium














