Bleepingcomputer FamousSparrow's SparroWocky Backdoor Targets Latin American Governments
Article Content
- •FamousSparrow's SparroWocky backdoor targets Latin American governments since August 2025.
- •The malware employs advanced anti-analysis techniques and is delivered via DLL side-loading.
- •ESET attributes the campaign to FamousSparrow with high confidence due to its operational history.
The China-aligned cyberespionage group FamousSparrow has deployed a new modular backdoor named SparroWocky, primarily targeting government organizations in Latin America since August 2025. ESET researchers report that 90% of the group's targets during this period were located in countries such as Argentina, Ecuador, and Venezuela. SparroWocky is a sophisticated C++ backdoor that incorporates anti-analysis techniques and can execute commands, steal files, and manipulate system information. The malware is delivered via a DLL side-loading method that involves a legitimate executable and a malicious DLL. ESET attributes this campaign to FamousSparrow with high confidence due to the malware's origins linked to earlier infections by the SparrowDoor backdoor. The group has shifted its focus to Latin America in response to increased U.S. interest in the region, aiming to collect intelligence on governmental responses to Chinese economic pressures. Current defenses should prioritize monitoring for unusual DLL side-loading and patching vulnerabilities in internet-facing systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Earth Estries and SparrowDoor in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Mexico's Cybersecurity Plan Addresses Rising Ransomware Threats Mexico's National Cybersecurity Plan, introduced in December 2025, aims to tackle increasing cyber threats, particularly ransomware, which has seen 223 incidents involving 64 groups from 2020 to 2026. The plan is a response to the urgent need for improved cyber defenses following the FIFA World Cup 2026, which…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…