Skip to content
China's Salt Typhoon backdoors Latin American orgs with new snooping malware

China's Salt Typhoon backdoors Latin American orgs with new snooping malware

Theregister • September 17, 2026

China’s Salt Typhoon gang has developed a new backdoor and dropped it in networks belonging to high-profile organizations in several countries across Central and South America since at least August 2025, according to researchers.

The PRC-backed espionage crew shifted its focus to Latin America a month prior, and from mid-2025 into 2026, the vast majority - 90 percent - of Salt Typhoon’s targets were located in that region, ESET, which tracks the group as FamousSparrow , said in a Thursday report.

Salt Typhoon is the cyber-spy gang that hacked telecommunications and government agencies to gain stealthy, long-term access to victim organizations going back as far as 2019. These hacks, however, weren’t discovered until late 2023.

In August 2025, ESET’s malware hunters found the group’s new backdoor, called SparroWocky, deployed against government agencies in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. While targeting entities in these countries “represents a rare occurrence among the China-aligned APT groups,” ESET believes the focus likely reflects China’s reaction to recent US President Donald Trump’s initiatives in the region, malware researchers Alexandre Côté Cyr and Romain Dumont said .

“Donald Trump’s second presidential term has brought an aggressive reaffirmation of US interests in Latin America, which threatens various long-term investments that China has cultivated throughout the continent in the last decade, in domains such as energy , mining , and telecommunications ,” they wrote. “We suspect that FamousSparrow’s activities are intended to help China better monitor and anticipate the reaction of local governments to current US pressures.”

SparroWocky is a modular C++ backdoor that appeared soon after the Beijing snoops started focusing on Latin America. The new backdoor integrates open source tools and uses techniques designed to evade antivirus and other security software.

The name comes from Lewis Carroll’s Jabberwocky poem - the researchers found the first stanza in several collected samples. (’Twas brillig, and the slithy toves/Did gyre and gimble in the wabe:/All mimsy were the borogoves,/And the mome raths outgrabe.)

ESET based its analysis on a malware sample compiled on November 17, and said it contained the following open source projects:

Mbed TLS , a C library it uses to establish a secure communication channel with its command-and-control (C2) server.

Mbed TLS , a C library it uses to establish a secure communication channel with its command-and-control (C2) server.

MinHook , a Windows API hooking library that hides the start address of newly created threads from security products.

MinHook , a Windows API hooking library that hides the start address of newly created threads from security products.

COFF Loader (or a similar project) to enable dynamic loading and execution of in-memory plugins in the form of COFF objects.

COFF Loader (or a similar project) to enable dynamic loading and execution of in-memory plugins in the form of COFF objects.

Plus, the backdoor incorporates a variant of the SilentMoonwal k technique to spoof the call stacks originating from MinHook routines, and thus escape the watchful eyes of monitoring tools, along with a custom API-hashing algorithm to dynamically resolve Windows API functions.

The gang deploys the backdoor in its usual way: a trident loader scheme consisting of a legitimate executable, a malicious DLL, and a file containing the encrypted malware. The loader resides in the malicious DLL and executes via DLL side-loading.

After establishing communication with its C2 server, the backdoor starts receiving commands handled by a custom class named WinHandler (derived from a ServerHandler custom class), according to the runtime type information in the malware.

The nearly 30 commands include scooping up system details and sending them to the C2, starting and/or terminating a new session and removing persistence, stealing and deleting files, taking periodic screenshots, collecting session IDs and usernames of enumerated remote sessions on the system via WTSEnumerateSessionsW , and spawning new SparrowWocky instances.

It uses TLS encryption to communicate with its C2 servers, connecting directly to their IP addresses, generally on port 443, although ESET also spotted the malware using port 8080 in some cases.

The malware researchers also published a full indicators-of-compromise list and samples in ESET’s GitHub repository , so give those a read, too. ®

On Call: Techie fixed Wi-Fi dead zone with a drill

When wires and wireless mix, the combination can be electric

AI risks make some insurers wary of corporate liability

RAND wants better data to price machine-made mishaps, apocalypse not included

HPE makes its “unified storage” claim real as B10000 R6 hits GA

PARTNER CONTENT: Pairs block and adjacent file workloads with independent scaling of performance and capacity

AWS confesses its console causes cloudy confusion for new users

Improved signup experience for ‘AI builders’ hides complexity and includes spending cap

Open weights are not open source: Why AI's favorite label is under dispute

Downloading a model is increasingly easy. Understanding how it was made, or changing a system at its root, is another matter

USA’s Venezuela takeover comes with bonus exposure to Chinese AI surveillance tech

Think tank points out that companies banned by Washington will help run the regime that Uncle Sam now controls

SAAS Salesforce staggers back to feet after global outage

Salesforce staggers back to feet after global outage

databases Oracle celebrates banner quarter with another round of layoffs

Oracle celebrates banner quarter with another round of layoffs

CYBER-CRIME Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars

Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars

cyber-crime Revolut falls for fake government requests, hands over customer data

Revolut falls for fake government requests, hands over customer data

ai and ml Ex-FTC boss Khan urges Uncle Sam to break out the handcuffs for AI CEOs, citing 1934 precedent

Ex-FTC boss Khan urges Uncle Sam to break out the handcuffs for AI CEOs, citing 1934 precedent

devops Microsoft anoints Rust as a 'Tier 1' internal language

Microsoft anoints Rust as a 'Tier 1' internal language

Marvell pushes GlobalFoundries to light up wafer production It might be the trillion-dollar company, but it'll need some help on the supply side to do it

Marvell pushes GlobalFoundries to light up wafer production

It might be the trillion-dollar company, but it'll need some help on the supply side to do it

Huawei's -gen Ascend NPUs could become China's best option 960DT is set to arrive early, boasting performance far exceeding anything the West could offer the Middle Kingdom

Huawei's -gen Ascend NPUs could become China's best option

960DT is set to arrive early, boasting performance far exceeding anything the West could offer the Middle Kingdom

ai and ml AI model watermarking changes agent behavior Lasso Security sees differences in tool handling and model refusals

AI model watermarking changes agent behavior

Lasso Security sees differences in tool handling and model refusals

SYSTEMS Nvidia goes green to keep grid capacity from zapping its revenues GPUzilla woos neoclouds into another walled garden, promising smarter, more efficient, and profitable bit barns

Nvidia goes green to keep grid capacity from zapping its revenues

GPUzilla woos neoclouds into another walled garden, promising smarter, more efficient, and profitable bit barns

cyber-crime Spain gets its first taste of AI-aided cyber attack Data protection chiefs call for 'immediate review' of data protection models

Spain gets its first taste of AI-aided cyber attack

Data protection chiefs call for 'immediate review' of data protection models

Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Russians are posing as Signal support to launch phishing attacks

PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack

PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Black Hat and DEF CON

DEF CON Franklin project enlists hackers to harden critical infrastructure

Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

EQT buys majority in Swiss cybersecurity biz Acronis

Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career

Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight

On the plus side, infosec's a good bet for a long, stable career

Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line Acquisition gives open source CSS framework 'a stable long-term '

Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line

Acquisition gives open source CSS framework 'a stable long-term '

Switzerland tests a FOSS escape route from Microsoft 365 Swiss Army sticks a knife in American cloud apps with its own FOSS push

Switzerland tests a FOSS escape route from Microsoft 365

Swiss Army sticks a knife in American cloud apps with its own FOSS push

Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin

Feel peak Windows was 7? You might like Kumander Linux

Debian and Xfce – solid, sensible choices – with a pretty skin

Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted

Canonical shuttering some of its legacy chat channels

The Ubuntu Pastebin went in June, IRC gets demoted

Audacity audio-editing app no longer looks like it's from the early 2000s The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Audacity audio-editing app no longer looks like it's from the early 2000s

The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast A real alternative to running some kind of FOSS Unix clone

Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast

A real alternative to running some kind of FOSS Unix clone