Emergence of SparroWocky: Chinese Cyber Threat Actor FamousSparrow Targets Latin America
In a significant development in cybersecurity, the threat actor known as FamousSparrow has introduced a new backdoor named SparroWocky, replacing its long-standing SparrowDoor implant. This transition highlights an evolution in tactics, specifically targeting governmental entities across Latin America since at least August 2025.
ESET Research has attributed the newly emerging campaign to FamousSparrow, an actor aligned with Chinese interests, with high confidence. The researchers noted that some of the earliest incidents of SparroWocky infections were linked to the now-obsolete SparrowDoor, a malware strain exclusively utilized by FamousSparrow. Infections have been documented in various government entities in nations including Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.
From mid-2025 to 2026, approximately 90% of the targets identified by ESET telemetry were situated within this specific region. This concentration of attacks is considered unusual for China-aligned groups, which typically demonstrate broader geographic interests across multiple regions over extended durations.
Access for this malicious activity was primarily achieved through the exploitation of publicly accessible Microsoft Exchange servers. This method underscores the ongoing vulnerabilities associated with widely used software and the continuous need for robust cybersecurity measures.
Distinct Characteristics of SparroWocky
ESET made it clear that SparroWocky is not merely a variant of SparrowDoor but a distinct malware family, albeit one that retains some functions of its predecessor. This modular C++ backdoor possesses multiple capabilities, including executing commands, running files, acting as a TCP proxy, collecting host and network information, exfiltrating files, and taking screenshots at regular intervals. Notably, the method of data exfiltration involves encryption using RC4, with transmissions facilitated over Transport Layer Security (TLS) to enhance stealth.
Additionally, SparroWocky has the capability to load and execute Beacon Object Files (BOF). This particular format, initially introduced in the Cobalt Strike framework, has seen adoption by various red-teaming frameworks and represents a strategic shift for FamousSparrow. Previously, the group relied on open-source offensive tools alongside its malware, but the emergence of SparroWocky indicates an attempt to integrate custom capabilities into its development.
The developers of SparroWocky have invested substantial resources into evasion techniques. Specific strategies include runtime code patching, forging call stacks to mislead Windows API calls into appearing as though they originate from legitimate processes, and manipulating thread creation to report unassuming start addresses for its threads. These sophisticated measures reflect an escalating arms race in the cyber domain, where adversaries continue to innovate their methods of breach and concealment.
Strategic Regional Focus
ESET’s findings also noted a shift in FamousSparrow’s operational focus, narrowing its targeting to almost exclusively Latin America by July 2025, a month prior to the first sightings of SparroWocky. The researchers contextualized this shift as a potential reaction from China to renewed U.S. engagement in the region, particularly under the administration of President Donald Trump during his second term of office. Increased U.S. interests could pose a threat to the extensive Chinese investments amassed over the previous decade in sectors such as energy, mining, and telecommunications.
One case underscoring this assertion involved a Panamanian entity targeted by the group, directly linked to disputes over two significant ports in the canal area. These ports were previously operated by a China-based company, whose concession was contested by the Panamanian government in early 2025. This scenario exemplifies the geopolitical tensions at play, where cyber operations could serve as tools for strategic advantage.
While ESET has indicated a discernible regional focus for FamousSparrow, it remains unclear whether this prioritization signals a formal geographic strategy or if it is a temporary response fueled by current geopolitical dynamics.
FamousSparrow has been active in the cyber realm since at least 2019, with its first activities documented in 2021, notably involving the exploitation of ProxyLogon vulnerabilities. Although Trend Micro has drawn links to the group known as Earth Estries, ESET has asserted that these connections are not fully understood. As such, ESET continues to track FamousSparrow independently from Salt Typhoon, citing differentiating technical indicators.
As the landscape of cyber threats evolves, the emergence of SparroWocky represents a significant shift in tactics for FamousSparrow. With targeted nations across Latin America now facing an increased risk, the implications for cybersecurity in the region are profound, warranting vigilant attention from both governmental and private sectors alike.
