Cyberwarfare / Nation-State Attacks,
Fraud Management & Cybercrime
ESET Reports Significant Shift in Targeting by FamousSparrow Focused on Latin America

In a concerning development, cyber-security researchers from ESET have revealed that hackers linked to the Chinese government have strategically focused their attacks on various government networks throughout Latin America over the past year. This includes targeting territories such as Puerto Rico, employing a novel backdoor that had not been identified prior to this investigation.
According to a detailed report released by ESET on September 18, 2026, the hacking group known as FamousSparrow has significantly shifted its operations, unveiling a new backdoor, referred to as SparroWocky, in August 2025. This shift culminated in the group retiring the original backdoor that its name was based upon. The timing of this strategic focus coincided with an escalating rivalry between Washington and Beijing for influence in Latin America, which has historically been viewed as a zone of U.S. preeminence.
The ESET report highlights that the targeted infections are not limited to one or two countries but span across multiple nations, including Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, and Venezuela. Notably, Puerto Rico—a U.S. territory responsible for administering federal programs and receiving federal funding—was also impacted. However, ESET has refrained from disclosing the exact identities of the organizations that have been targeted in these cyber assaults.
Making sense of the data, ESET observed that a staggering 90 percent of the targets logged in their telemetry since mid-2025 were located within Latin America. This shift in focus, as per ESET’s researchers, correlates directly with the evolving diplomatic and economic contests between the United States and China. During the past decade, China has aggressively invested in Latin American infrastructure, acquiring control over essential sectors such as ports, telecommunications, and energy generation.
One noteworthy example that underscores the implications of these cyber intrusions is Panama. Here, ESET identified targets associated with the Panamanian government while it was embroiled in a legal dispute concerning container ports adjacent to the Panama Canal, which had previously been operated by Chinese interests. The timing of these cyberattacks indicates that the hackers were likely seeking privileged insight into the intentions of local authorities amidst this contentious backdrop.
The intricate relationship between local governance and international cyber espionage is further evidenced by the comments of Panama’s president, who noted the situation surrounding the ports as emblematic of a wider dispute between the U.S. and China.
FamousSparrow has been active in cyber espionage since at least 2019, with ESET documenting the group for the first time in September 2021. Initially, their targets included private enterprises like hotels, but they have gradually expanded their focus to include public sector agencies, legal institutions, and engineering firms. This broadening of targets indicates a strategic pivot to gather intelligence that could be instrumental for the Chinese government.
Notably, Trend Micro has linked FamousSparrow to a different cluster identified as Earth Estries, and other cybersecurity experts have associated the group with Salt Typhoon, linked to significant intrusions in U.S. telecommunications providers in 2024. However, ESET maintains that it tracks Salt Typhoon as an entirely separate entity, given the absence of any technical indicators that connect the two groups.
Adding layers to this narrative, Cisco Talos reported in March 2026 that a separate cluster, overlapping with FamousSparrow, had spent two years infiltrating South American telecom companies—another testament to the pervasive nature of these cyber intrusions.
In attributing the new cyber campaign to FamousSparrow, ESET expressed a high level of confidence, pointing to early indicators that suggest the backdoor named SparroWocky was delivered by an earlier backdoor called SparrowDoor, which is exclusive to this group. This connection hints at a systematic approach used by the hackers to maintain their foothold in these targeted networks.
The functionalities of the newly employed SparroWocky backdoor are advanced; it is capable of executing files, collecting detailed inventory of the host system down to user specifics, and retrieving files stored on disk. For long-term operation, hackers can opt between implementing a Windows service or a registry Run key, allowing them substantial control over infected systems.
Interestingly, preliminary samples of the SparroWocky malware contained a stanza from Lewis Carroll’s “Jabberwocky,” a peculiar note that researchers traced back to cryptographic test vectors. This artistic flair amidst a highly sophisticated cyber operation speaks to the group’s unique characterization, blending creativity with their nefarious intentions—and underscoring the complex, often murky terrain of modern cyber warfare.