China's FamousSparrow APT Deploys New SparroWocky Backdoor Across Latin America
ID: 4a6990a0-ed12-511a-9b56-1b8521a85947
STIX ID: report--4a6990a0-ed12-511a-9b56-1b8521a85947
Feed Name: CosmicBytez Labs
ESET disclosed a new modular C++ backdoor named SparroWocky, deployed by the China-aligned espionage group FamousSparrow against government networks across Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela since at least August 2025. The malware uses DLL sideloading to load a malicious payload designed to blend with legitimate signed binaries and provides operators with espionage capabilities including arbitrary file execution, TCP proxying for lateral movement, periodic screenshots, and encrypted data exfiltration; ESET interprets the concentrated regional focus as a geopolitically driven, sustained intelligence collection campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
