Back Theregister China's Salt Typhoon backdoors Latin American orgs with new snooping malware
China’s Salt Typhoon gang has developed a new backdoor and dropped it in networks belonging to high-profile organizations in several countries across Central and South America since at least August 2025, according to researchers.
The PRC-backed espionage crew shifted its focus to Latin America a month prior, and from mid-2025 into 2026, the vast majority - 90 percent - of Salt Typhoon’s targets were located in that region, ESET, which tracks the group as FamousSparrow , said in a Thursday report.
Salt Typhoon is the cyber-spy gang that hacked telecommunications and government agencies to gain stealthy, long-term access to victim organizations going back as far as 2019. These hacks, however, weren’t discovered until late 2023.
In August 2025, ESET’s malware hunters found the group’s new backdoor, called SparroWocky, deployed against government agencies in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. While targeting entities in these countries “represents a rare occurrence among the China-aligned APT groups,” ESET believes the focus likely reflects China’s reaction to recent US President Donald Trump’s initiatives in the region, malware researchers Alexandre Côté Cyr and Romain Dumont said .
“Donald Trump’s second presidential term has brought an aggressive reaffirmation of US interests in Latin America, which threatens various long-term investments that China has cultivated throughout the continent in the last decade, in domains such as energy , mining , and telecommunications ,” they wrote. “We suspect that FamousSparrow’s activities are intended to help China better monitor and anticipate the reaction of local governments to current US pressures.”
SparroWocky is a modular C++ backdoor that appeared soon after the Beijing snoops started focusing on Latin America. The new backdoor integrates open source tools and uses techniques designed to evade antivirus and other security software.
The name comes from Lewis Carroll’s Jabberwocky poem - the researchers found the first stanza in several collected samples. (’Twas brillig, and the slithy toves/Did gyre and gimble in the wabe:/All mimsy were the borogoves,/And the mome raths outgrabe.)
ESET based its analysis on a malware sample compiled on November 17, and said it contained the following open source projects:
Mbed TLS , a C library it uses to establish a secure communication channel with its command-and-control (C2) server.
Mbed TLS , a C library it uses to establish a secure communication channel with its command-and-control (C2) server.
MinHook , a Windows API hooking library that hides the start address of newly created threads from security products.
MinHook , a Windows API hooking library that hides the start address of newly created threads from security products.
COFF Loader (or a similar project) to enable dynamic loading and execution of in-memory plugins in the form of COFF objects.
COFF Loader (or a similar project) to enable dynamic loading and execution of in-memory plugins in the form of COFF objects.
Plus, the backdoor incorporates a variant of the SilentMoonwal k technique to spoof the call stacks originating from MinHook routines, and thus escape the watchful eyes of monitoring tools, along with a custom API-hashing algorithm to dynamically resolve Windows API functions.
The gang deploys the backdoor in its usual way: a trident loader scheme consisting of a legitimate executable, a malicious DLL, and a file containing the encrypted malware. The loader resides in the malicious DLL and executes via DLL side-loading.
After establishing communication with its C2 server, the backdoor starts receiving commands handled by a custom class named WinHandler (derived from a ServerHandler custom class), according to the runtime type information in the malware.
The nearly 30 commands include scooping up system details and sending them to the C2, starting and/or terminating a new session and removing persistence, stealing and deleting files, taking periodic screenshots, collecting session IDs and usernames of enumerated remote sessions on the system via WTSEnumerateSessionsW , and spawning new SparrowWocky instances.
It uses TLS encryption to communicate with its C2 servers, connecting directly to their IP addresses, generally on port 443, although ESET also spotted the malware using port 8080 in some cases.
The malware researchers also published a full indicators-of-compromise list and samples in ESET’s GitHub repository , so give those a read, too. ®
On Call: Techie fixed Wi-Fi dead zone with a drill
When wires and wireless mix, the combination can be electric
AI risks make some insurers wary of corporate liability
RAND wants better data to price machine-made mishaps, apocalypse not included
HPE makes its “unified storage” claim real as B10000 R6 hits GA
PARTNER CONTENT: Pairs block and adjacent file workloads with independent scaling of performance and capacity
AWS confesses its console causes cloudy confusion for new users
Improved signup experience for ‘AI builders’ hides complexity and includes spending cap
Open weights are not open source: Why AI's favorite label is under dispute
Downloading a model is increasingly easy. Understanding how it was made, or changing a system at its root, is another matter
USA’s Venezuela takeover comes with bonus exposure to Chinese AI surveillance tech
Think tank points out that companies banned by Washington will help run the regime that Uncle Sam now controls
SAAS Salesforce staggers back to feet after global outage
Salesforce staggers back to feet after global outage
databases Oracle celebrates banner quarter with another round of layoffs
Oracle celebrates banner quarter with another round of layoffs
CYBER-CRIME Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars
Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars
cyber-crime Revolut falls for fake government requests, hands over customer data
Revolut falls for fake government requests, hands over customer data
ai and ml Ex-FTC boss Khan urges Uncle Sam to break out the handcuffs for AI CEOs, citing 1934 precedent
Ex-FTC boss Khan urges Uncle Sam to break out the handcuffs for AI CEOs, citing 1934 precedent
devops Microsoft anoints Rust as a 'Tier 1' internal language
Microsoft anoints Rust as a 'Tier 1' internal language
Marvell pushes GlobalFoundries to light up wafer production It might be the trillion-dollar company, but it'll need some help on the supply side to do it
Marvell pushes GlobalFoundries to light up wafer production
It might be the trillion-dollar company, but it'll need some help on the supply side to do it
Huawei's -gen Ascend NPUs could become China's best option 960DT is set to arrive early, boasting performance far exceeding anything the West could offer the Middle Kingdom
Huawei's -gen Ascend NPUs could become China's best option
960DT is set to arrive early, boasting performance far exceeding anything the West could offer the Middle Kingdom
ai and ml AI model watermarking changes agent behavior Lasso Security sees differences in tool handling and model refusals
AI model watermarking changes agent behavior
Lasso Security sees differences in tool handling and model refusals
SYSTEMS Nvidia goes green to keep grid capacity from zapping its revenues GPUzilla woos neoclouds into another walled garden, promising smarter, more efficient, and profitable bit barns
Nvidia goes green to keep grid capacity from zapping its revenues
GPUzilla woos neoclouds into another walled garden, promising smarter, more efficient, and profitable bit barns
cyber-crime Spain gets its first taste of AI-aided cyber attack Data protection chiefs call for 'immediate review' of data protection models
Spain gets its first taste of AI-aided cyber attack
Data protection chiefs call for 'immediate review' of data protection models
Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Russians are posing as Signal support to launch phishing attacks
PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack
PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Black Hat and DEF CON
DEF CON Franklin project enlists hackers to harden critical infrastructure
Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
EQT buys majority in Swiss cybersecurity biz Acronis
Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career
Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight
On the plus side, infosec's a good bet for a long, stable career
Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line Acquisition gives open source CSS framework 'a stable long-term '
Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line
Acquisition gives open source CSS framework 'a stable long-term '
Switzerland tests a FOSS escape route from Microsoft 365 Swiss Army sticks a knife in American cloud apps with its own FOSS push
Switzerland tests a FOSS escape route from Microsoft 365
Swiss Army sticks a knife in American cloud apps with its own FOSS push
Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin
Feel peak Windows was 7? You might like Kumander Linux
Debian and Xfce – solid, sensible choices – with a pretty skin
Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted
Canonical shuttering some of its legacy chat channels
The Ubuntu Pastebin went in June, IRC gets demoted
Audacity audio-editing app no longer looks like it's from the early 2000s The FOSS tool for audio editing has a fresh coat of paint, and new features to boot
Audacity audio-editing app no longer looks like it's from the early 2000s
The FOSS tool for audio editing has a fresh coat of paint, and new features to boot
Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast A real alternative to running some kind of FOSS Unix clone
Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast
A real alternative to running some kind of FOSS Unix clone
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
