China-Linked Hackers Deploy New 'SparroWocky' Backdoor in Latin America Campaign
Security researchers at ESET have identified a new backdoor, SparroWocky, being used by the China-aligned threat group FamousSparrow in attacks targeting multiple Latin American countries since at least August 2025. FamousSparrow has links to other known espionage groups, Earth Estries and Salt Typhoon, and has been active since 2019.
SparroWocky is a modular backdoor written in C++ that replaces the group's previous tool, SparrowDoor, as its main implant. It can run commands, execute files, act as a network proxy, gather system and network information, take screenshots, exfiltrate data, and remove itself from an infected machine once it is no longer needed. Notably, the malware also folds open-source code directly into its own build rather than simply running separate tools alongside it, showing a more advanced level of development skill.
The malware is delivered through a technique known as DLL sideloading, where a legitimate program is tricked into loading a malicious file that decrypts and runs the final payload. How attackers first gain access to victim systems is not yet known, but the group's history of stealthy, long-term espionage operations suggests careful planning behind each intrusion.