Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2891+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. China's FamousSparrow APT Deploys New SparroWocky Backdoor Across Latin America
China's FamousSparrow APT Deploys New SparroWocky Backdoor Across Latin America
NEWS

China's FamousSparrow APT Deploys New SparroWocky Backdoor Across Latin America

ESET says China-aligned FamousSparrow deployed a new SparroWocky backdoor against Latin American governments across eight countries.

Dylan H.

News Desk

September 17, 2026
3 min read

ESET Research has revealed a new backdoor, dubbed SparroWocky, deployed by the China-aligned espionage group FamousSparrow across government networks in Latin America since at least August 2025. The disclosure, published September 17, 2026, shows a threat actor once known for scattershot, worldwide targeting now concentrating almost entirely on one region.

The Backdoor: SparroWocky

ESET researchers Alexandre Côté Cyr and Romain Dumont named the malware after "Jabberwocky," Lewis Carroll's nonsense poem — the first stanza turned up in the earliest collected samples. Beyond the name, SparroWocky is technically substantial: "SparroWocky is a modular, C++ backdoor," the researchers wrote, noting that "its architecture and the techniques used by its authors indicate strong knowledge of anti-analysis tricks and Windows internals."

Its infection chain relies on DLL sideloading: a legitimate, signed executable is paired with a malicious wrapper DLL that decrypts and launches the actual backdoor payload, a technique chosen specifically to blend malicious execution into what looks like normal software behavior. Once running, SparroWocky gives operators a full espionage toolkit — arbitrary file execution, TCP proxying for pivoting inside a network, periodic screenshot capture, and encrypted exfiltration of collected data.

Targets

ESET has observed SparroWocky deployed against governmental entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The concentration is the notable part: from mid-2025 into 2026, roughly 90% of FamousSparrow's tracked targets in ESET's telemetry sit in Latin America — a sharp departure from the geographically scattered targeting ESET says is typical of the China-aligned groups it tracks over a comparable stretch of time.

Attribution & Motivation

FamousSparrow is an established cyberespionage actor, historically linked to intrusions against hotels, government agencies, and other organizations where the objective was long-term intelligence access rather than immediate financial gain. ESET's analysts read the current regional focus as geopolitically driven, describing it as likely reflecting "China's reaction to various recent U.S. initiatives" in Latin America — in effect, a state actor's espionage footprint shifting to track a rival power's growing regional interest.

Why It Matters

A sustained, near-exclusive regional focus from a state-nexus APT is a signal worth reading on its own: it suggests a standing collection requirement, not opportunistic tasking, and points to Latin American government networks facing a more persistent, better-resourced adversary than typical financially motivated crimeware. Organizations in the region — particularly ministries and agencies with visibility into U.S. diplomatic, trade, or security engagement — should treat DLL-sideloading detection and monitoring for unusual TCP proxy traffic as immediate priorities, since SparroWocky's authors have specifically engineered the malware to blend into legitimate-looking execution.

Sources

  • The Hacker News — China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
  • GlobeNewswire — ESET Research: China-aligned FamousSparrow expands operations in Latin America
  • The Record — China's FamousSparrow hackers target Latin America with new backdoor
#APT#China#Nation-State#ESET#Backdoor#Latin America

Related Articles

Latin American Cybercriminals Hoover Up Government Data

A reported breach of 5.8M Uruguayan records is the latest in a growing pattern of attackers monetizing Latin American government citizen data.

4 min read

China's 'FamousSparrow' APT Nests in South Caucasus Energy

The China-linked threat group FamousSparrow has expanded its targeting to an Azerbaijani oil and gas company, marking a shift beyond its traditional...

4 min read

Russian APT Deploys 'StockStay' Backdoor Against Ukrainian Targets

Turla, a prolific Russian state-sponsored threat actor, has deployed a previously undocumented backdoor dubbed 'StockStay' in espionage operations...

3 min read
Back to all News