← Today’s chart
TEC1 sourceIN ×117 SEPT 2026 15:35 IST

China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America

Headline by Prism · from 1 report

The threat actor FamousSparrow is targeting Latin American government entities using a newly discovered backdoor called SparroWocky.

Reader brief

Through the Reader lens: The China-aligned hacking group FamousSparrow has shifted to a new, sophisticated backdoor called SparroWocky to target government organizations throughout Latin America. The malware allows attackers to execute commands, perform file operations, and exfiltrate data from compromised machines. This new tool, which replaces the group's older implant, shows an increased capability to integrate open-source defensive projects to evade detection. The campaign has primarily focused on entities in countries including Argentina, Peru, and Venezuela since July 2025.

What to watch next

  • Determination of whether the group's focus on Latin America is a permanent mandate or temporary geopolitical strategy
  • Identification of the unknown initial access vector used to deploy the DLL sideloading chain

What was said2

Attributed, verbatim. Every quote is checked against the article it came from. One that does not match is not shown.

ESET

2 quotes
  • SparroWocky is a modular, C++ backdoor
    [1]The Hacker News· 17 Sept· opens on the quote
    In the article

    state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025. " SparroWocky is a modular, C++ backdoor ," ESET security researchers Alexandre Côté Cyr and Romain Dumont said in a technical report shared with The Hacker News ahead of publication. "Its architecture and the techniques used by its authors indicate strong

  • It is not clear whether the group’s apparent focus on Latin America may reflect a formal, geographical mandate, or whether this focus is only temporary and dictated by the current geopolitical circumstances
    [1]The Hacker News· 17 Sept· opens on the quote
    In the article

    against governmental entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. ESET said 90% of the group’s targets recorded in its telemetry have been located in the region. " It is not clear whether the group’s apparent focus on Latin America may reflect a formal, geographical mandate, or whether this focus is only temporary and dictated by the current geopolitical circumstances ," the Slovak cybersecurity company said.

Sources1

All filed from IndiaNamed Argentina · Ecuador · Guatemala · Honduras · Panama · Peru · Puerto Rico · Venezuela · Argentina · Ecuador · Guatemala · Honduras · Panama · Peru · Puerto Rico · Venezuela · Alexandre Cote Cyr · Earth Estries · ESET · FamousSparrow

← Today’s chart

China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America | Prism