CHINA-ALIGNED threat actor FamousSparrow has replaced its long-running SparrowDoor implant with a new backdoor called SparroWocky, according to ESET Research. The group has deployed the malware against government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela since at least August 2025.
ESET attributed the campaign to FamousSparrow with high confidence, partly because some early SparroWocky infections were delivered by SparrowDoor, which it said is used only by that group. The attackers gained access by exploiting publicly reachable Microsoft Exchange servers. From mid-2025 into 2026, 90% of FamousSparrow targets recorded in ESET telemetry were in Latin America.
ESET described SparroWocky as a separate malware family rather than a SparrowDoor variant. The modular C++ backdoor can run commands, execute files, operate as a TCP proxy, gather host and network information, exfiltrate files, take recurring screenshots and load Beacon Object Files. Stolen data is encrypted with RC4 and sent over TLS. The malware also includes evasion features such as runtime code patching, forged call stacks and hooks that make its threads report harmless start addresses.
ESET said FamousSparrow had previously run open-source offensive tools alongside its malware, making the integration of this capability into SparroWocky a notable change.
ESET assessed that the group’s near-exclusive focus on Latin America from July 2025 could reflect Chinese strategic interests in the region, although it could not determine whether this represented a formal mandate or a temporary response to events. It cited one Panamanian target involved in a dispute over two canal-area ports. The group has been active since at least 2019; links to Earth Estries remain unclear, and ESET tracks it separately from Salt Typhoon.