A New Threat in Latin America
In a significant development for regional cybersecurity, researchers at ESET have identified a new, highly capable backdoor being leveraged by the China-aligned Advanced Persistent Threat (APT) group known as FamousSparrow. The malware, named SparroWocky, has been systematically deployed against governmental organizations in Latin America since at least August 2025.
FamousSparrow, active since at least 2019, was historically noted for targeting the hospitality industry. However, this shift toward government entities is viewed by analysts as a strategic reaction to the growing influence and interests of the United States within the Latin American region.
Inside SparroWocky: What Makes It Dangerous
SparroWocky is a modular C++ backdoor designed with deep knowledge of Windows internals. ESET's analysis highlights its ability to evade traditional security software through sophisticated techniques, including memory manipulation and runtime code patching.
- Modular Architecture: The malware is built for flexibility, allowing the group to tailor its capabilities to specific targets.
- Anti-Analysis Tricks: It employs complex techniques specifically designed to complicate reverse engineering and detection by security teams.
- Open-Source Integration: Unlike its predecessors, SparroWocky incorporates open-source project code directly into its malicious framework, signaling an evolution in the group's development capabilities.
- Memory Manipulation: The backdoor operates by patching code at the memory level to avoid triggering standard security alerts.
A Pattern of Escalation
This latest campaign follows a long history of espionage activity by FamousSparrow. Previous operations saw the group utilizing the SparrowDoor backdoor to breach engineering firms, law firms, and research institutes across multiple continents. The transition to SparroWocky represents a marked increase in the technical maturity of the threat actor.
Fortunately, while advanced, SparroWocky’s inner workings are much less arcane than a ‘gyre and gimble in the wabe,’ so a ‘through and through [of] the vorpal blade’ allowed us to bring you a detailed analysis.
— ESET Research
