Skip to content
FamousSparrow's SparroWocky Backdoor Targets Latin American Governments

FamousSparrow's SparroWocky Backdoor Targets Latin American Governments

First seen 17 Sep 2026, 09:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 17, 2026 at 10:23 UTC
  • FamousSparrow's SparroWocky backdoor targets Latin American governments since August 2025.
  • The malware employs advanced anti-analysis techniques and is delivered via DLL side-loading.
  • ESET attributes the campaign to FamousSparrow with high confidence due to its operational history.

The China-aligned cyberespionage group FamousSparrow has deployed a new modular backdoor named SparroWocky, primarily targeting government organizations in Latin America since August 2025. ESET researchers report that 90% of the group's targets during this period were located in countries such as Argentina, Ecuador, and Venezuela. SparroWocky is a sophisticated C++ backdoor that incorporates anti-analysis techniques and can execute commands, steal files, and manipulate system information. The malware is delivered via a DLL side-loading method that involves a legitimate executable and a malicious DLL. ESET attributes this campaign to FamousSparrow with high confidence due to the malware's origins linked to earlier infections by the SparrowDoor backdoor. The group has shifted its focus to Latin America in response to increased U.S. interest in the region, aiming to collect intelligence on governmental responses to Chinese economic pressures. Current defenses should prioritize monitoring for unusual DLL side-loading and patching vulnerabilities in internet-facing systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-07-01
FamousSparrow shifts focus
The group increases its targeting of Latin American countries, abandoning previous targets.
ESET
2025-08-01
SparroWocky deployment begins
FamousSparrow starts using the SparroWocky backdoor in attacks targeting Latin American governments.
ESET
2026-09-17
ESET publishes findings
ESET releases a detailed analysis of SparroWocky, outlining its capabilities and targeting.
ESET

More articles in this cluster (4)

Following this threat?

Track Earth Estries and SparrowDoor in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed