FamousSparrow's New SparroWocky Backdoor Hits Latin American Governments
A China-aligned espionage group is using a previously unknown modular backdoor against government agencies across Latin America.
Researchers have linked a China-aligned threat actor to a new espionage campaign in Latin America. The group, widely identified as FamousSparrow, has been deploying a previously unknown backdoor called SparroWocky since at least August 2025, according to multiple security vendors.
SparroWocky is described as a modular C++ backdoor. Reports agree it has been used to break into government organizations across several Latin American countries. Dark Reading frames the activity in the context of US-China competition for influence in the region, while other outlets focus on the technical details of the malware.
One notable discrepancy: The Register's headline attributes the backdoor to Salt Typhoon, another Chinese APT, whereas the other four sources attribute it to FamousSparrow. The broader consensus is that the campaign is the work of FamousSparrow, but the conflicting attribution highlights how quickly reporting on new malware can diverge.
Sources · 5
- China's FamousSparrow APT Spies on US Politics in Latin America
- China's Salt Typhoon backdoors Latin American orgs with new snooping malware
- China’s FamousSparrow hackers target Latin America with new backdoor
- China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
- Chinese hackers use SparroWocky malware in govt espionage attacks
More in Security & Privacy
WordPress Click2Shell CSRF Flaw Could Let Attackers Run PHP Code
A newly disclosed cross-site request forgery vulnerability in WordPress Core, with a public proof-of-concept, can let attackers execute PHP on the server.
Film Torrents Carry New Malware, Victims Found in Kenya and Uganda
Cybercriminals are using popular movie torrents to distribute fresh malware, with confirmed infections in East Africa.
CrowdSec Breach: TanStack npm Attack Exposed 170 Private Repos
CrowdSec says an attacker used a former employee's still-active GitHub access to copy 170 private repositories, tracing the intrusion to the TanStack npm attack.
CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog
The agency's move signals active attacks and pressures federal agencies to patch quickly.