FamousSparrow Uses SparroWocky Against Latin America
ESET links a regional spying campaign to FamousSparrow and its new SparroWocky backdoor, with Peru among the targets.
ESET Research on September 17, 2026, attributed a sustained cyberespionage campaign against Latin American governments to FamousSparrow, centering on a new C++ backdoor called SparroWocky. Based on telemetry cited by the company, activity picked up in July 2025 and, from mid-2025 through 2026, about 90% of observed targets were in the region. Countries repeatedly named by ESET and specialist coverage include Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.
Executive summary
ESET Research attributed a cyberespionage campaign against Latin American governments to FamousSparrow, with SparroWocky replacing SparrowDoor as the group’s main backdoor. Activity was observed since at least August 2025, and telemetry cited by the company shows that nearly 90% of the targets tracked between mid-2025 and 2026 were in the region. The countries most consistently named in the consolidated reporting are Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.
The core technical finding is that SparroWocky is not a minor update to the earlier family, but a new C++ backdoor built for modularity and stealth. The analyses cited describe capabilities to execute arbitrary commands and files, act as a TCP proxy, collect host and network-interface information, exfiltrate files, take periodic screenshots, manipulate files, and remove itself from the compromised system. BleepingComputer added that the code incorporates components from open source projects, while SocPrime reported evasion techniques such as stack spoofing and reflective in-memory loading.
The consolidated timeline places the start of the regional phase no later than July 2025, with SparroWocky deployments seen from August 2025 onward against government entities. The activity remained visible at least through September 2026. That period lines up with multiple specialist outlets that, despite using different labels for the actor, describe the same campaign and the same Latin American victim set. Some refer to FamousSparrow, others to Salt Typhoon, but WindowsForum notes that ESET’s most reliable attribution is FamousSparrow.
For Peru, the reporting is consistent. ESET includes the country in the campaign against regional governments, and the same inclusion appears in Infosecurity Magazine, BleepingComputer, The Hacker News, GBHackers, ZeroHour, The Record, Presseportal, and CyberInsider. The available evidence does not show the local scale of the intrusion or whether publicly confirmed exfiltration took place, but it is enough to establish that Peru was among the documented targets in a regional espionage operation that was still active at least through September 2026.
Context and background
FamousSparrow appears in the material as an APT group that ESET describes as aligned with China, a geopolitical characterization based on its own analysis. That label is not presented as a formal state attribution, but as the framework the company uses to interpret the campaign. At the same time, several international outlets mixed the actor’s name with Salt Typhoon, which led WindowsForum to clarify that, according to ESET, the activity should be associated with FamousSparrow with high confidence.
The tool shift is central to understanding the campaign. SparrowDoor had served as the earlier implant, but SparroWocky took over as the group’s primary backdoor. That replacement does not just signal a technical refresh, it points to operational continuity in the same espionage effort. The consolidated evidence shows that the transition did not interrupt the campaign, it reinforced it from August 2025 onward.
The target selection also fits an intelligence operation focused on state entities. ESET and the outlets that drew from its report point to governments and, in some cases, telecommunications, with a notable concentration in Latin America. The most repeated figure is that about 90% of the targets observed by ESET between mid-2025 and mid-2026 were located in the region. That suggests a sustained redeployment of the actor’s resources toward that operating theater.
On the tactical side, the material places vulnerable Microsoft Exchange servers as the initial access vector. No specific vulnerabilities or detailed exploit chain were published in the consolidated research, but the pattern is clear, access through exposed systems, persistence through a modular backdoor, and deployment of espionage functions aimed at exfiltrating information, mapping networks, and expanding remote control. That pattern matches previous APT campaigns that favor discreet access and long dwell time.
Key facts table
| Date | Event | Source | Confidence |
|---|---|---|---|
| 2025-07 | ESET places the start of the high-profile cyberespionage trend in Latin America no later than July 2025. | Yahoo, ESET | confirmed |
| 2025-08 | SparroWocky is observed deployed against government entities in several Latin American countries from at least August 2025. | ESET, Business Insider | confirmed |
| 2025-08 | SparroWocky activity is tied to SparrowDoor being replaced as the group’s main backdoor. | ESET, The Register, Infosecurity Magazine | confirmed |
| 2025-08 | Presence of the backdoor is documented in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. | ESET, BleepingComputer | confirmed |
| 2026-09-17 | ESET publishes the report on FamousSparrow and SparroWocky focused on Latin American governments. | ESET | confirmed |
| 2026-09-17 | BleepingComputer reports that SparroWocky code includes components from open source projects. | BleepingComputer | confirmed |
| 2026-09-17 | Multiple outlets confirm the campaign is active and attribute it to FamousSparrow, although some mislabel it as Salt Typhoon. | WindowsForum, The Register, The Hacker News | confirmed |
| 2026-09-18 | Cyware reports that Salt Typhoon would have shifted its focus to Latin America, citing Argentina, Ecuador, and Venezuela. | Cyware | confirmed |
Operation timeline
| Date | Event | Actor/vector | Verified source |
|---|---|---|---|
| 2025-07 | The cyberespionage trend against high-profile targets in Latin America begins. | FamousSparrow, according to ESET | ESET, Yahoo |
| 2025-08 | SparroWocky is observed being deployed against government agencies in the region. | SparroWocky backdoor | ESET, Business Insider |
| 2025-08 | The new backdoor replaces SparrowDoor as the main implant. | Implant migration | ESET, GBHackers, The Register |
| 2025-08 | The campaign affects Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. | Regional campaign | ESET, Infosecurity Magazine, BleepingComputer |
| 2026-09-17 | ESET publishes its report on the expansion in Latin America. | ESET Research | ESET |
| 2026-09-17 | Technical outlets detail execution, TCP proxying, exfiltration, and self-deletion capabilities. | SparroWocky | The Hacker News, BleepingComputer, Infosecurity Magazine |
| 2026-09-18 | Cyware publishes a regional take centered on Argentina, Ecuador, and Venezuela. | Salt Typhoon, according to Cyware | Cyware |
| 2026-09-19 | ZeroHour consolidates the timeline and attribution to the actor tracked as FamousSparrow. | Malware timeline | ZeroHour |
Attack chain and TTPs
The attack chain that can be reconstructed from the material does not include a public exploit step by step or a published IOC list, but it does show a clear operational architecture. The most cited initial access vector is vulnerable Microsoft Exchange servers. From there, the actor deploys SparroWocky, a modular C++ backdoor designed to maintain persistent access, remote control, and discreet espionage.
Modularity matters because it allows functions to be packaged without unnecessarily bloating the implant’s core. ESET and technical outlets describe a component that can execute arbitrary commands, launch files, operate as a TCP proxy, and collect host and network-interface information. It can also exfiltrate files, take periodic screenshots, manipulate files, and erase its own presence from the compromised system.
BleepingComputer added that the code incorporates components from open source projects. That can broaden capabilities and also introduce noise for analysis and signature-based detection. SocPrime added two traits that reinforce stealth, stack spoofing and reflective loading in memory, both consistent with a design meant to complicate process tracing, memory inspection, and traditional telemetry.
The replacement of SparrowDoor with SparroWocky suggests that FamousSparrow opted for a more flexible implant to support a long-running regional objective. The material does not support a single universal infection flow, but it does show a repeated logic, initial access, backdoor deployment, environment reconnaissance, collection of sensitive information, file transfer, and selective cleanup.
| TTP | Description | Source |
|---|---|---|
| Initial vector | Use of vulnerable Microsoft Exchange servers as the entry point. | ZeroHour, BleepingComputer |
| Modular backdoor | SparroWocky in C++, with a modular structure aimed at stealth. | ESET, The Hacker News, Infosecurity Magazine |
| Remote execution | Execution of arbitrary commands and files on the compromised host. | The Hacker News, BleepingComputer |
| TCP proxy | Ability to act as a TCP proxy to support remote operations. | The Hacker News, Infosecurity Magazine |
| Reconnaissance | Collection of host information and network-interface data, including IPs. | The Hacker News, BleepingComputer |
| Exfiltration | Exfiltration of files and documents from the compromised environment. | The Hacker News, BleepingComputer |
| Screenshot capture | Periodic screenshots for remote observation. | The Hacker News, BleepingComputer |
| Evasion | Stack spoofing and reflective in-memory loading. | SocPrime |
| Persistence and cleanup | File operations and self-deletion from the system. | The Hacker News |
Regional impact
The operation shows an unusual concentration in Latin America and, within that region, a clear bias toward government entities. ESET said that about 90% of the targets observed in its telemetry between mid-2025 and 2026 were located in the region. Some coverage, including Cyware, also said the focus extended to telecommunications in Argentina, Ecuador, and Venezuela.
The strongest reading of the material is that the campaign was not episodic. It lasted for months, changed implants, and kept the same core interest, access to state networks and extraction of sensitive information. That persistence explains why so many separate outlets, even with different names for the actor, end up describing the same victim surface.
Regional overview
ESET reported activity against government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela, and said SparroWocky had been deployed since at least August 2025. ZeroHour consolidated the same list of countries in its timeline, while Infosecurity Magazine, BleepingComputer, The Hacker News, and GBHackers repeated the victim set and the campaign’s persistence.
The sectoral relevance is centered on the public sector, although Cyware added telecommunications as a second front. The evidence does not support extending the scope to other sectors with the same confidence. The material also does not provide victim counts by country, so the geographic spread should be treated as an observed concentration, not an exhaustive tally.
Argentina
Argentina is among the countries where ESET observed SparroWocky in attacks against government organizations. The country appears repeatedly in coverage from Infosecurity Magazine, BleepingComputer, The Hacker News, GBHackers, CyberInsider, ZeroHour, and The Register, always within the same regional campaign attributed to FamousSparrow.
Peru
Peru appears explicitly in ESET’s report and in virtually all technical follow-up coverage. The material places it among the countries affected by SparroWocky deployments against government entities since August 2025. The Record added that Alexandre Côté Cyr’s tracking of the campaign reached government departments in Peru, along with other countries in the region.
Ecuador
Ecuador is part of the set of countries where ESET observed the backdoor. Cyware also mentioned it in its September 18, 2026, bulletin when describing the shift in focus toward Latin America, along with Argentina and Venezuela. No additional verifiable details are available in the consolidated material about specific Ecuadorian entities.
Guatemala
Guatemala appears on the list of government entities affected by SparroWocky. The overlap among ESET, BleepingComputer, Infosecurity Magazine, The Hacker News, ZeroHour, and The Record reinforces that it was one of the confirmed targets in the regional campaign.
Honduras
Honduras also appears among the countries where the backdoor was observed against public agencies. The mention is consistent across the main follow-up reports derived from ESET’s research and is not paired with a verifiable sector beyond the state focus.
Panama
Panama appears repeatedly on the list of countries attacked. The material includes it both in ESET’s roster and in specialist summaries, always under the same espionage pattern against government entities.
Puerto Rico
Puerto Rico appears as a target in the consolidated material and is treated by ESET and related coverage as part of the Latin American theater of the campaign. The Record and ZeroHour include it in their lists, alongside Argentina, Guatemala, Honduras, Panama, Peru, and Venezuela.
Venezuela
Venezuela appears in ESET’s cited telemetry and in several later reports. Cyware also mentions it in the context of the shift toward Latin America, along with Argentina and Ecuador, although that strategic reading is the outlet’s interpretation rather than a primary finding in the technical report.
Chile
No specific facts were verified about Chile in the material provided.
Paraguay
No specific facts were verified about Paraguay in the material provided.
Bolivia
No specific facts were verified about Bolivia in the material provided.
Colombia
No specific facts were verified about Colombia in the material provided.
Brazil
No specific facts were verified about Brazil in the material provided.
Mexico
No specific facts were verified about Mexico in the material provided.
United States
No specific facts were verified about the United States as a direct victim in the material provided. The country appears only as contextual reference in some coverage about Chinese investments and in the strategic reading by Cyware and DarkReading, not as a confirmed target of the campaign.
The countries without additional verifiable coverage in the material are Chile, Paraguay, Bolivia, Colombia, Brazil, and Mexico.
Technical indicators
No concrete IOCs were published in the consolidated material. There are no hashes, domains, IPs, file paths, or mutex names that can be verified from the sources provided. The technical reading therefore has to rest on TTPs and behavioral identification, not on a list of specific indicators.
Analysis for security teams
The immediate priority for defenders in Latin American government organizations is to review Microsoft Exchange exposure and abuse, because that is the initial vector consistently mentioned in the material. Any exposed or poorly patched instance deserves urgent review. The fact that the campaign has remained active since August 2025 and is still appearing in September 2026 suggests this is not a closed incident, but an operational capability the actor sustained over time.
For detection, the focus should be on patterns consistent with modular backdoors, not only on static signatures. SparroWocky can execute arbitrary commands, launch files, act as a TCP proxy, collect host data, take screenshots, exfiltrate files, and self-delete. That combination calls for process telemetry, anomalous outbound connections, unexpected screen-capture activity, and events involving mass access or reading of sensitive files.
The mention of open source components and techniques such as stack spoofing and reflective loading means defenders need a broader view. An EDR that depends only on process names or exact hashes will fall short against a modular family that blends in with legitimate libraries and in-memory loading or injection techniques. Hunting should focus on process trees, lateral connections, service abuse, and file movements that match exfiltration phases.
From a prioritization standpoint, government teams in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela should treat this as persistent espionage, not a one-off outbreak. The coverage is consistent that the main target is the public sector, with a possible second focus on telecommunications. That justifies reviewing privilege controls, segmentation, mail exposure, network ingress and egress monitoring, and alerts for unusual screen capture or packaging of documents.
It is also worth adjusting detection to avoid naming confusion. WindowsForum warns that some publications mislabeled the campaign as Salt Typhoon. If internal rules or playbooks use the wrong name, response can be incomplete. The most consistent operational reference in the material is FamousSparrow, with SparroWocky as the main backdoor.
Frequently asked questions
Is the campaign attributed by ESET to FamousSparrow still active, and where was it seen?
Yes. The consolidated material indicates activity from at least August 2025 through September 2026, with observations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. That timeline runs across the Operation timeline and Regional impact sections.
What technically changed between SparrowDoor and SparroWocky?
SparroWocky became the group’s main backdoor rather than a minor variant. Unlike SparrowDoor, it is described as a modular C++ malware with command execution, TCP proxying, exfiltration, screenshot capture, and self-deletion. That crosses the Attack chain and TTPs and Context and background sections.
Which sectors were most exposed according to the material?
The public sector is the clearest documented target. ESET and the reporting based on its research describe attacks against agencies and government organizations, and Cyware adds telecommunications in some countries. This crosses Regional impact, Regional overview, and the Key facts table.
Which country appears most clearly in the coverage besides Argentina?
Peru appears explicitly and repeatedly in ESET, Infosecurity Magazine, BleepingComputer, The Hacker News, GBHackers, ZeroHour, and The Record. The mention crosses Regional impact, the Key facts table, and the Operation timeline, where it appears as a confirmed target in the regional set.
What kind of detection should be prioritized if no IOCs were published?
Behavior-based detection should be prioritized, especially Exchange abuse, unusual remote execution, TCP proxying, unexpected screenshots, file exfiltration, and evasion techniques such as reflective in-memory loading. That crosses Technical indicators with Analysis for security teams and Attack chain and TTPs.
Material limitations
The material provided does not include verifiable IOCs, hashes, domains, IPs, file names, or EDR signatures. It also does not allow a full infection chain to be reconstructed with a confirmed public exploit, nor does it let analysts attribute successful exfiltration to a specific victim with precision. Some secondary reports offer geopolitical interpretation about motives, but those readings are attributed to each outlet and not presented as primary facts in ESET’s report.
Sources and brief coverage for follow-up
Sources
- ESET Research: China-aligned FamousSparrow expands ...markets.businessinsider.com· Business Insider
- ESET Research: China-aligned FamousSparrow expands ...finance.yahoo.com· Yahoo
- ESET Research: China-aligned FamousSparrow expands operations in Latin America, targets governments with new backdoormanilatimes.net· The Manila TimesUnverified URL
- China (Country): news timeline & CVEs · ZeroHourzerohour.day· ZeroHour
- Cyware Weekly Threat Intelligence - September 18, 2026cyware.com· Cyware
- ESET Research: FamousSparrow targets Latin American governments with new SparroWocky backdooreset.com· ESET
- Neue Cyberattacken: FamousSparrow nimmt Lateinamerika ins Visierwelivesecurity.com· ESET (WeLiveSecurity)
- FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor in Latin Americainfosecurity-magazine.com· Infosecurity Magazine
- China-Aligned FamousSparrow Deploys SparroWocky Backdoor in Latin Americathehackernews.com· The Hacker News
- Chinese hackers use SparroWocky malware in govt espionage attacksbleepingcomputer.com· BleepingComputer
- China's FamousSparrow APT Spies on US Politics in Latin Americadarkreading.com· DarkReadingUnverified URL
- SparroWocky Backdoor Linked to FamousSparrow, Not Salt Typhoonwindowsforum.com· WindowsForum
- China's Salt Typhoon backdoors Latin American orgs with new snooping malwaretheregister.com· The Register
- China Hackers Hit Latin American Governments With SparroWocky Backdoorbankinfosecurity.com· BankInfoSecurity
- SparroWocky: FamousSparrow’s New Backdoor Hits Latin Americalabs.cloudsecurityalliance.org· Cloud Security Alliance
- China-nahe Hackergruppe späht Regierungen in Lateinamerika auspresseportal.de· Presseportal / ESET
- FamousSparrow Deploys New SparroWocky Backdoor Against Latin American Governmentsgbhackers.com· GBHackers
- SparroWock: de backdoor die bijt, de commando's die je vangen, zegt ESETcomputable.nl· Computable.nl
- ESET Research: Chinese cyberspionagegroep FamousSparrow richt pijlen op overheden in Latijns-Amerikaeset.com· ESET
- FamousSparrow's SparroWocky Backdoor Targets Latin American Governments Amid US-China Rivalrythreatpaper.com· Threatpaper
- SparrowDoor (Malware): news timeline & CVEszerohour.day· ZeroHour
- Puerto Rico (Country): news timeline & CVEszerohour.day· ZeroHour
- ESET Uncovers New FamousSparrow Backdoor Deployed Against Latin American Governmentsallatra.media· Allatra Media
- New SparroWocky backdoor deployed in attacks on governmentscyberinsider.com· Cyberinsider
- China's FamousSparrow hackers target Latin America with new backdoor SparroWockytherecord.media· The Record
- FamousSparrow Targets Government Networks Across Latin America Using SparroWocky Backdoorcyberpress.org· Cyberpress.org
- SparroWocky Backdoor Targets Latin American Governmentssocprime.com· SocPrime



