Skip to content
New SparroWocky backdoor deployed in attacks on governments

New SparroWocky backdoor deployed in attacks on governments

Cyberinsider Bill Mann September 17, 2026

The China-aligned FamousSparrow cyberespionage group has begun deploying a new modular backdoor named SparroWocky in attacks focused heavily on Latin America.

The malware provides extensive remote-control capabilities while using low-level Windows manipulation and anti-analysis techniques to evade security tools.

ESET researchers discovered SparroWocky through the company’s ongoing monitoring of FamousSparrow, observing the malware in attacks from at least August 2025. ESET says 90% of FamousSparrow targets seen in its telemetry from mid-2025 into 2026 were in Latin America, with SparroWocky deployed against government and other organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.

FamousSparrow is a cyberespionage group that ESET says has operated since at least 2019. It was previously known for compromising hotels worldwide, but has also targeted governments, international organizations, trade groups, engineering companies, and law firms. ESET attributes the new campaign and malware to FamousSparrow with high confidence, partly because early SparroWocky infections were installed by SparrowDoor, a backdoor associated exclusively with the group.

SparroWocky is a separate malware family rather than an evolution of SparrowDoor. Written in C++, it can execute arbitrary files and commands, create TCP proxies, steal files, collect system information, enumerate user sessions, and capture screenshots. It can also load Beacon Object Files (BOFs) directly into memory, allowing attackers to run modules originally designed for red-team frameworks such as Cobalt Strike, Metasploit, Sliver, and Brute Ratel.

The malware is delivered using a three-part DLL side-loading chain consisting of a legitimate executable, a patched malicious DLL, and an encrypted .dat payload. Observed loader names include winfsp-x64.dll and DukeQt.dll. After decrypting the payload with RC4, the loader reflectively maps SparroWocky into memory without writing the backdoor itself to disk.

Persistence can be established through a Windows service or Registry Run key. One configuration analyzed by ESET used the service name ProcAuditManager, while registry-based persistence used the value SnapCart.

SparroWocky also incorporates several techniques intended to interfere with endpoint monitoring. These include a variant of SilentMoonwalk to forge call stacks, MinHook-based manipulation that disguises newly created thread start addresses, API hashing, and creation of fake Windows loader structures to make reflectively loaded programs appear more legitimate.

Command-and-control traffic runs over TLS, while transferred command data can additionally be encrypted with RC4. ESET observed C2 servers primarily on port 443, although port 8080 was also used.

Defenders should prioritize patching internet-facing Exchange servers, as ESET associates FamousSparrow access with exploitation of publicly reachable Exchange systems. Monitoring for unusual DLL side-loading, unexpected services or Run-key entries, reflectively loaded code, suspicious BOF execution, and the network indicators published with ESET’s report can also help identify intrusions.

100,000+ WordPress sites infected via Brevo supply chain attack

Revolut hackers used infostealer to hijack Italian government emails

Apple uses secure camera hardware to verify photos are real captures

Google patches Pixel modem zero-day exploited in targeted attacks

Iranian malware steals Telegram and WhatsApp data from targets

Steam client flaw with no fix enables privilege elevation on Windows

Bill specializes in explaining complex technical topics to a non-technical audience. In his 30+ year career, he has covered many of the technological advances that shape our lives. Today, Bill uses those skills to help people protect their privacy and security against the ever-growing assaults on both.