ESET Research has revealed a new backdoor, dubbed SparroWocky, deployed by the China-aligned espionage group FamousSparrow across government networks in Latin America since at least August 2025. The disclosure, published September 17, 2026, shows a threat actor once known for scattershot, worldwide targeting now concentrating almost entirely on one region.
The Backdoor: SparroWocky
ESET researchers Alexandre Côté Cyr and Romain Dumont named the malware after "Jabberwocky," Lewis Carroll's nonsense poem — the first stanza turned up in the earliest collected samples. Beyond the name, SparroWocky is technically substantial: "SparroWocky is a modular, C++ backdoor," the researchers wrote, noting that "its architecture and the techniques used by its authors indicate strong knowledge of anti-analysis tricks and Windows internals."
Its infection chain relies on DLL sideloading: a legitimate, signed executable is paired with a malicious wrapper DLL that decrypts and launches the actual backdoor payload, a technique chosen specifically to blend malicious execution into what looks like normal software behavior. Once running, SparroWocky gives operators a full espionage toolkit — arbitrary file execution, TCP proxying for pivoting inside a network, periodic screenshot capture, and encrypted exfiltration of collected data.
Targets
ESET has observed SparroWocky deployed against governmental entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The concentration is the notable part: from mid-2025 into 2026, roughly 90% of FamousSparrow's tracked targets in ESET's telemetry sit in Latin America — a sharp departure from the geographically scattered targeting ESET says is typical of the China-aligned groups it tracks over a comparable stretch of time.
Attribution & Motivation
FamousSparrow is an established cyberespionage actor, historically linked to intrusions against hotels, government agencies, and other organizations where the objective was long-term intelligence access rather than immediate financial gain. ESET's analysts read the current regional focus as geopolitically driven, describing it as likely reflecting "China's reaction to various recent U.S. initiatives" in Latin America — in effect, a state actor's espionage footprint shifting to track a rival power's growing regional interest.
Why It Matters
A sustained, near-exclusive regional focus from a state-nexus APT is a signal worth reading on its own: it suggests a standing collection requirement, not opportunistic tasking, and points to Latin American government networks facing a more persistent, better-resourced adversary than typical financially motivated crimeware. Organizations in the region — particularly ministries and agencies with visibility into U.S. diplomatic, trade, or security engagement — should treat DLL-sideloading detection and monitoring for unusual TCP proxy traffic as immediate priorities, since SparroWocky's authors have specifically engineered the malware to blend into legitimate-looking execution.