China-aligned cyberespionage group FamousSparrow has deployed a new modular C++ backdoor, SparroWocky, against government entities across Latin America since at least August 2025. The implant appears to replace the group’s earlier SparrowDoor malware and has disproportionately affected organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela; roughly 90% of observed targeting since mid-2025 has been in the region. The campaign is assessed as intelligence collection, potentially focused on government responses to U.S. pressure affecting Chinese economic interests.
SparroWocky supports host reconnaissance, remote command execution, file collection and manipulation, screenshot capture, proxying, persistence, cross-session process creation, and encrypted exfiltration. Operators deliver it through DLL side-loading: an RC4-encrypted payload stored in a .dat file is loaded directly into memory. The malware incorporates open-source offensive tooling and native Beacon Object File execution, while using runtime patching, dynamic API resolution, stack and threat-origin spoofing, and CreateThread hooking to disguise malicious threads as legitimate AnimateWindow activity.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
FamousSparrow deployed the new modular C++ SparroWocky backdoor in a cyberespionage campaign targeting government entities in Latin America. Victims were identified in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.
Telemetry indicated that FamousSparrow activity became primarily focused on Latin American targets from mid-2025, with government institutions heavily targeted.
FamousSparrow, a China-aligned cyberespionage group, is believed to have operated since at least 2019.
Analysis disclosed that SparroWocky supports reconnaissance, command execution, file exfiltration, screenshots, TCP proxying, reverse port forwarding, and in-memory PE and Beacon Object File execution. It is delivered through DLL side-loading and uses RC4, TLS, API hashing, call-stack spoofing, thread-start concealment, and forged Windows loader structures to evade detection.
SparroWocky was identified as a distinct malware family that appears to have superseded FamousSparrow's SparrowDoor implant. Attribution was supported by overlapping infrastructure and victimology, including SparroWocky deployments by SparrowDoor on previously compromised networks.
Researchers reported that FamousSparrow compromised public-facing Microsoft Exchange servers to gain access and deploy the SparroWocky backdoor against government targets in Latin America. The report also provided loader and backdoor hashes and command-and-control IP indicators.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 22 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
mkd-cirt.mk
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcedecipher.sc
Open sourcebleepingcomputer.com
Open sourcewelivesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.