ESET Research says the China-aligned threat actor FamousSparrow has replaced its long-running SparrowDoor implant with a new backdoor called SparroWocky in a campaign against government targets across Latin America running since at least August 2025. Researchers Alexandre Cote Cyr and Romain Dumont documented victims in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela, delivered through a DLL side-loading chain ESET calls a “trident loader scheme”: a legitimate executable, a malicious DLL standing in for one that executable expects, and a separate file holding an encrypted payload.
The backdoor itself is capable, not novel. It runs arbitrary commands and files, opens a TCP proxy, loads Cobalt Strike Beacon Object Files, collects host and network data, exfiltrates files and takes screenshots on a repeating schedule, then persists through a Windows service or a registry run key. ESET attributes SparroWocky to FamousSparrow with high confidence because early deployments rode in through the group’s exclusive SparrowDoor implant, and because organizations previously hit with SparrowDoor were later re-targeted with the new tool, the same victims, a new payload.
The detail that matters most for defenders sitting outside Latin America is the targeting logic ESET lays out, not just the malware. One confirmed victim is a Panamanian entity involved in disputes over port concessions operated by Chinese companies, and researchers tie the regional focus to Beijing’s reaction to renewed US initiatives affecting Chinese investment in the region’s energy, mining and telecommunications sectors. That is a template, not a one-off: government and quasi-government bodies sitting inside any dispute that touches Chinese commercial interests, regardless of geography, fit the same targeting logic FamousSparrow is applying here, and SOC teams at those organizations should not assume regional threat intelligence feeds alone will flag them.
CyberTech has tracked the same actor class shifting tools before: see China’s GRIMWEDGE backdoor riding a patched Chrome bug and how Fire Ant showed the limits of quick attribution.
Source: ESET