Salt Typhoon Deploys New 'SparroWocky' Backdoor Against Latin American Governments
Security researchers at ESET have uncovered a new espionage campaign by Salt Typhoon, a China-linked hacking group also tracked as FamousSparrow, targeting government organisations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela. Since mid-2025, around 90 percent of the group's targets have been located in Latin America, a notable shift for a group that historically focused on telecommunications and government agencies worldwide, with earlier intrusions dating back to 2019 only discovered in late 2023.
The newly identified malware, dubbed SparroWocky, is a modular backdoor written in C++ that incorporates open source tools and evasion techniques designed to bypass antivirus and other security software. ESET researchers believe the regional focus may be linked to China's response to the current US administration's renewed engagement in Latin America, an area where China has invested heavily in energy, mining and telecommunications over the past decade. The researchers suggest the campaign may help Beijing monitor how local governments react to US pressure in the region.
While this campaign currently targets government entities rather than private businesses, it demonstrates how state-backed threat actors continue to evolve their tools and shift focus based on geopolitical developments. Organisations connected to government supply chains or operating in affected regions should remain alert to sophisticated, well-resourced adversaries capable of long-term stealthy access.
Key Takeaway: Even small businesses with government or international supply chain connections should ensure strong endpoint detection and monitoring, as nation-state actors continually develop new tools to evade traditional antivirus defences.