China-Linked FamousSparrow Unleashes SparroWocky Backdoor in Latin America

Cybersecurity firm ESET has reported the emergence of a new cyberespionage operation linked to the China-aligned group known as FamousSparrow. This group has begun deploying a novel backdoor, dubbed SparroWocky, against government agencies across Latin America. The backdoor is designed to infiltrate and gather sensitive information from a range of targets within the region.

SparroWocky is a modular C++ backdoor equipped with a variety of capabilities that include gathering system information, executing commands, taking screenshots, exfiltrating files, and functioning as a TCP proxy. It also employs sophisticated anti-analysis techniques such as stack spoofing and reflective loading to evade detection and analysis.

ESET’s telemetry data reveals that approximately 90% of the reported targets between mid-2025 and 2026 were located in Latin America, specifically highlighting operations against governmental bodies in countries including Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. This concentrated effort underscores a strategic focus by the group within this geographical area.

The malware’s designation, SparroWocky, is derived from the first stanza of Lewis Carroll’s poem “Jabberwocky,” which was discovered in early samples of the backdoor. The embedded strings indicate that the malware utilizes assets from the Mbed TLS library for secure communications. Importantly, SparroWocky serves to replace the group’s older implant, SparrowDoor, although it does not appear to be derived from the same code base. Researchers have observed that while SparroWocky offers some of the functionality found in its predecessor, it is an evolution of their operational capabilities.

FamousSparrow utilizes a trident loader technique that involves DLL sideloading to deploy the SparroWocky backdoor. In this scheme, a legitimate executable loads a modified DLL, which subsequently retrieves the encrypted payload and configuration data from a .dat file. To further obfuscate its presence, the decrypted Portable Executable (PE) file is stripped of its MZ and PE magic values before being reflectively loaded into memory. ESET speculates that this method may help the backdoor bypass security measures that rely on pattern matching.

The capabilities of SparroWocky provide operators with extensive control over compromised systems. The backdoor is capable of collecting various types of system data, including hostnames, usernames, domain names, Windows versions, and IP addresses. Moreover, it can exfiltrate files using TLS with RC4 encryption, execute commands, and serve as a TCP proxy. Persistence mechanisms are integrated, utilizing services or registry Run keys for ongoing access.

FamousSparrow has been operational since at least 2019, initially targeting hotels but subsequently broadening its scope to include government entities, international organizations, and engineering firms. ESET publicly reported on the group in 2021, noting their initial exploitation of ProxyLogon vulnerabilities. The group’s focused operations in Latin America may reflect both escalating US interests and China’s growing economic involvement in the area, with one incident notably involving a Panamanian organization embroiled in a dispute over two ports in the Panama Canal.

Researchers at ESET expressed concerns that the operational objectives may involve gathering advance intelligence regarding local governmental decisions; however, the specific rationale behind FamousSparrow’s targeted approach in Latin America remains somewhat ambiguous. Given the technical sophistication of the SparroWocky backdoor and the group’s evolution, heightened vigilance is recommended for organizations operating within the region to safeguard against potential intrusions. This incident exemplifies the importance of understanding adversary tactics and techniques, as outlined in the MITRE ATT&CK framework, including initial access, persistence, and command and control methods that could facilitate similar attacks.

Source