
The China-linked threat group FamousSparrow has been running active espionage operations across Latin America for over a year, using a newly developed backdoor named SparroWocky to infiltrate government organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. ESET researchers, who uncovered the campaign, believe the primary goal is gathering intelligence on how Latin American governments are responding to increased U.S. pressure on Chinese economic interests in the region.
SparroWocky replaces FamousSparrow’s earlier custom implant, SparrowDoor, and represents a significant technical upgrade. It is a modular C++ backdoor that borrows code from open-source projects and includes anti-analysis techniques designed to evade modern security tools — including manipulating low-level memory structures, patching code at runtime, and disguising its threads as legitimate Windows processes. Its capabilities span the full range of what a high-end espionage tool needs: command execution, file management, screenshot capture (transmitting only changed screen regions to minimize network noise), session hijacking to operate as another logged-in user, TCP proxying, and self-deletion. The malware arrives through DLL side-loading; the payload is RC4-encrypted inside a .dat file and mapped directly into memory, leaving no executable on disk. ESET found at least 18 command-and-control addresses communicating over port 443 or 8080, with both direct and proxy-relayed connections observed.
