Back Infosecurity-Magazine FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor
The threat actor known as FamousSparrow has replaced its long-running SparrowDoor implant with a new backdoor called SparroWocky, and has been deploying it against governments across Latin America since at least August 2025.
ESET Research attributed the campaign to the China-aligned group with high confidence, partly because some of the earliest SparroWocky infections were delivered by SparrowDoor, which only FamousSparrow is known to use. It found the backdoor at government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela.
From mid-2025 into 2026, 90% of the group's targets in ESET telemetry sat in the region. The company called that rare among the China-aligned groups it tracks, which are usually seen across several parts of the world over a period that long.
FamousSparrow gained access by exploiting publicly reachable Exchange servers.
A Distinct Family, Not a SparrowDoor Variant
ESET was explicit that SparroWocky is not a SparrowDoor variant but a separate family, though it carries over some of the older backdoor's functions.
The modular C++ backdoor can run commands, execute files, act as a TCP proxy, collect host and network details, exfiltrate files and take screenshots on a repeating cycle. Exfiltrated data is encrypted with RC4 and sent over TLS.
It also loads and executes Beacon Object Files (BOF), a format introduced in Cobalt Strike and since adopted by other red-teaming frameworks. ESET said that marks a shift: FamousSparrow previously ran open-source offensive tools beside its own malware and now builds its code into it.
The developers put significant effort into developing evasion capabilities. SparroWocky patches code at runtime, forges call stacks so Windows API calls appear to come from legitimate thread entry points, and hooks thread creation so its own threads report a harmless start address.
Latin America the Primary Target
ESET said the group narrowed to almost exclusively targeting the region in July 2025, a month before SparroWocky appeared.
It assessed the focus as China's likely reaction to renewed US interest in the region under Donald Trump's second term, which ESET said could threaten Chinese investments built up over a decade in energy, mining and telecommunications.
One case appeared to support this assessment. A Panamanian entity ESET saw targeted is directly involved in the dispute over two major ports in the canal area, run until recently by a China-based company whose concession the Panamanian government challenged in early 2025.
ESET said it could not tell whether the regional focus reflects a formal geographic mandate or is temporary and driven by current circumstances.
The group has been active since at least 2019 and was first documented in 2021 exploiting ProxyLogon . Trend Micro has linked it to Earth Estries , though ESET said that link is not fully understood, and it tracks FamousSparrow separately from Salt Typhoon for want of technical indicators.
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters News 7 September 2026
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
Tortoiseshell Expands Malware Toolset With New Backdoor, SSH Tunnel News 26 August 2026
Tortoiseshell Expands Malware Toolset With New Backdoor, SSH Tunnel
Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day News 12 August 2026
Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day
Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack News 29 July 2026
Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack
Suspected Chinese Threat Group Targets Universities via Vulnerable Roundcube Servers News 7 July 2026
Suspected Chinese Threat Group Targets Universities via Vulnerable Roundcube Servers
What’s Hot on Infosecurity Magazine?
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
AI Agent Carries Out Multi-Stage Data Theft Attack
Most Firms Unable to Recover Quickly from Ransomware
Cisco Warns of Active Exploitation of Critical ISE Flaw
PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
Anthropic Reveals Yet Another Cybersecurity Incident
Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Systems
CRA Reporting Rules Take Effect: How to Ensure Your Organization is Ready
FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors
A CISO's Lessons in Ransomware Response and Recovery After a Real-World LockBit Attack
Frontier AI: How Cyber Defenders Can Harness the Defender’s Window
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Your Security Awareness Programme Isn't Failing, It's Just Not Relevant
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
How to Manage Enterprise Cyber Resilience in the Age of AI
Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
