The threat actor FamousSparrow is targeting Latin American government entities using a newly discovered backdoor called SparroWocky.

Reader brief
Through the Reader lens: The China-aligned hacking group FamousSparrow has shifted to a new, sophisticated backdoor called SparroWocky to target government organizations throughout Latin America. The malware allows attackers to execute commands, perform file operations, and exfiltrate data from compromised machines. This new tool, which replaces the group's older implant, shows an increased capability to integrate open-source defensive projects to evade detection. The campaign has primarily focused on entities in countries including Argentina, Peru, and Venezuela since July 2025.
What to watch next
- Determination of whether the group's focus on Latin America is a permanent mandate or temporary geopolitical strategy
- Identification of the unknown initial access vector used to deploy the DLL sideloading chain
What was said2
Attributed, verbatim. Every quote is checked against the article it came from. One that does not match is not shown.
ESET
2 quotes“SparroWocky is a modular, C++ backdoor”
In the article
…state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025. " SparroWocky is a modular, C++ backdoor ," ESET security researchers Alexandre Côté Cyr and Romain Dumont said in a technical report shared with The Hacker News ahead of publication. "Its architecture and the techniques used by its authors indicate strong…
“It is not clear whether the group’s apparent focus on Latin America may reflect a formal, geographical mandate, or whether this focus is only temporary and dictated by the current geopolitical circumstances”
In the article
…against governmental entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. ESET said 90% of the group’s targets recorded in its telemetry have been located in the region. " It is not clear whether the group’s apparent focus on Latin America may reflect a formal, geographical mandate, or whether this focus is only temporary and dictated by the current geopolitical circumstances ," the Slovak cybersecurity company said.…
Sources1
- [1]The Hacker NewsneutralChina-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America