The cybersecurity landscape in Latin America is facing a new threat as the China-aligned group, FamousSparrow, has been detected deploying a previously unreported backdoor known as SparroWocky. This development targets several Latin American nations since August 2025, marking a significant move in the cyber espionage arena.
Technical Insights into SparroWocky
According to researchers Alexandre Côté Cyr and Romain Dumont from ESET, SparroWocky is a modular backdoor crafted in C++. This malware demonstrates advanced understanding of anti-analysis techniques and Windows internals, underscoring the sophistication of its authors. Its name is inspired by its inclusion of a stanza from Lewis Carroll’s poem, Jabberwocky.
ESET’s recent analysis suggests that FamousSparrow has transitioned from using SparrowDoor to SparroWocky as its principal implant. Active since at least 2019, this group shares similarities with Earth Estries and Salt Typhoon, enhancing its notoriety in the cyber espionage field.
Capabilities and Techniques of SparroWocky
SparroWocky is designed with multiple capabilities, including executing arbitrary files, acting as a TCP proxy, and running commands. It can gather information from compromised systems, exfiltrate files, and manage file operations. Additionally, it uses public projects like Mbed TLS for secure communications and MinHook to evade security products.
The malware employs DLL sideloading to initiate its activities, with a legitimate executable launching a loader DLL to decrypt and execute the main payload. Despite the transition to a new malware family, the group maintains consistent techniques. The initial access method remains unidentified.
Strategic Targeting in Latin America
FamousSparrow’s operations are notably concentrated on high-profile targets in Latin America, beginning in July 2025. Governmental entities across countries like Argentina, Ecuador, and Peru are among those affected. ESET’s telemetry indicates that 90% of the group’s targets are within this region.
The focus on Latin America raises questions about whether this is a strategic decision influenced by geopolitical factors or a temporary shift in operations. The cybersecurity firm ESET has highlighted this as an ongoing area of interest.
Understanding the implications of FamousSparrow’s activities is crucial for cybersecurity professionals and organizations in the region. As the group continues to evolve its tactics, vigilance and advanced security measures remain essential to counteract such sophisticated cyber threats.
