FamousSparrow, a known cyber espionage group, has unveiled a new backdoor named SparroWocky, targeting public-facing Microsoft Exchange servers. This development demonstrates how exposed email systems can serve as long-term infiltration points in government networks.
Focus on Latin American Targets
The campaign, which began in mid-2025, has primarily affected governments in Latin America, including Argentina, Ecuador, and Venezuela. Researchers from Welivesecurity noted that 90 percent of the group’s activities from mid-2025 into 2026 were centered in this region. This marks a significant shift from the group’s previous global operations.
FamousSparrow, active since 2019, has been linked to attacks leveraging ProxyLogon vulnerabilities. The recent focus on Exchange servers continues this trend, as detailed in a report shared with Cyber Security News (CSN).
SparroWocky’s Advanced Features
SparroWocky, identified as FamousSparrow’s main implant since August 2025, is a modular backdoor designed in C language. It combines data exfiltration and remote access with sophisticated techniques to avoid detection, making it a potent tool for stealthy operations.
The backdoor employs a three-part loader, leveraging a legitimate executable, a malicious DLL, and an encrypted payload. This approach ensures the malicious code blends seamlessly with trusted programs, complicating detection efforts.
Defense Strategies Against SparroWocky
To mitigate the threat posed by SparroWocky, organizations must prioritize patching of internet-facing Exchange servers and limit unnecessary public access. The backdoor’s use of TLS and RC4 encryption for communications underscores the need for robust security monitoring.
Security teams should actively look for signs of DLL side-loading, abnormal services, and suspicious network activity. Regularly reviewing logs and isolating compromised systems can help contain the impact of any breaches.
Ultimately, this campaign highlights the importance of maintaining a proactive defense posture, with continuous monitoring and rapid response capabilities to address evolving cyber threats.
