CiberLATAMbywhalemate

FamousSparrow Uses SparroWocky Against Latin America

ESET links a regional spying campaign to FamousSparrow and its new SparroWocky backdoor, with Peru among the targets.

Whalemate Labs · AI-assisted researchPublished:42 min read

ESET Research on September 17, 2026, attributed a sustained cyberespionage campaign against Latin American governments to FamousSparrow, centering on a new C++ backdoor called SparroWocky. Based on telemetry cited by the company, activity picked up in July 2025 and, from mid-2025 through 2026, about 90% of observed targets were in the region. Countries repeatedly named by ESET and specialist coverage include Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.

Executive summary

ESET Research attributed a cyberespionage campaign against Latin American governments to FamousSparrow, with SparroWocky replacing SparrowDoor as the group’s main backdoor. Activity was observed since at least August 2025, and telemetry cited by the company shows that nearly 90% of the targets tracked between mid-2025 and 2026 were in the region. The countries most consistently named in the consolidated reporting are Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.

The core technical finding is that SparroWocky is not a minor update to the earlier family, but a new C++ backdoor built for modularity and stealth. The analyses cited describe capabilities to execute arbitrary commands and files, act as a TCP proxy, collect host and network-interface information, exfiltrate files, take periodic screenshots, manipulate files, and remove itself from the compromised system. BleepingComputer added that the code incorporates components from open source projects, while SocPrime reported evasion techniques such as stack spoofing and reflective in-memory loading.

The consolidated timeline places the start of the regional phase no later than July 2025, with SparroWocky deployments seen from August 2025 onward against government entities. The activity remained visible at least through September 2026. That period lines up with multiple specialist outlets that, despite using different labels for the actor, describe the same campaign and the same Latin American victim set. Some refer to FamousSparrow, others to Salt Typhoon, but WindowsForum notes that ESET’s most reliable attribution is FamousSparrow.

For Peru, the reporting is consistent. ESET includes the country in the campaign against regional governments, and the same inclusion appears in Infosecurity Magazine, BleepingComputer, The Hacker News, GBHackers, ZeroHour, The Record, Presseportal, and CyberInsider. The available evidence does not show the local scale of the intrusion or whether publicly confirmed exfiltration took place, but it is enough to establish that Peru was among the documented targets in a regional espionage operation that was still active at least through September 2026.

Context and background

FamousSparrow appears in the material as an APT group that ESET describes as aligned with China, a geopolitical characterization based on its own analysis. That label is not presented as a formal state attribution, but as the framework the company uses to interpret the campaign. At the same time, several international outlets mixed the actor’s name with Salt Typhoon, which led WindowsForum to clarify that, according to ESET, the activity should be associated with FamousSparrow with high confidence.

The tool shift is central to understanding the campaign. SparrowDoor had served as the earlier implant, but SparroWocky took over as the group’s primary backdoor. That replacement does not just signal a technical refresh, it points to operational continuity in the same espionage effort. The consolidated evidence shows that the transition did not interrupt the campaign, it reinforced it from August 2025 onward.

The target selection also fits an intelligence operation focused on state entities. ESET and the outlets that drew from its report point to governments and, in some cases, telecommunications, with a notable concentration in Latin America. The most repeated figure is that about 90% of the targets observed by ESET between mid-2025 and mid-2026 were located in the region. That suggests a sustained redeployment of the actor’s resources toward that operating theater.

On the tactical side, the material places vulnerable Microsoft Exchange servers as the initial access vector. No specific vulnerabilities or detailed exploit chain were published in the consolidated research, but the pattern is clear, access through exposed systems, persistence through a modular backdoor, and deployment of espionage functions aimed at exfiltrating information, mapping networks, and expanding remote control. That pattern matches previous APT campaigns that favor discreet access and long dwell time.

Key facts table

Date Event Source Confidence
2025-07 ESET places the start of the high-profile cyberespionage trend in Latin America no later than July 2025. Yahoo, ESET confirmed
2025-08 SparroWocky is observed deployed against government entities in several Latin American countries from at least August 2025. ESET, Business Insider confirmed
2025-08 SparroWocky activity is tied to SparrowDoor being replaced as the group’s main backdoor. ESET, The Register, Infosecurity Magazine confirmed
2025-08 Presence of the backdoor is documented in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. ESET, BleepingComputer confirmed
2026-09-17 ESET publishes the report on FamousSparrow and SparroWocky focused on Latin American governments. ESET confirmed
2026-09-17 BleepingComputer reports that SparroWocky code includes components from open source projects. BleepingComputer confirmed
2026-09-17 Multiple outlets confirm the campaign is active and attribute it to FamousSparrow, although some mislabel it as Salt Typhoon. WindowsForum, The Register, The Hacker News confirmed
2026-09-18 Cyware reports that Salt Typhoon would have shifted its focus to Latin America, citing Argentina, Ecuador, and Venezuela. Cyware confirmed
Cronología de SparroWockyLínea temporal con los hitos principales de la campaña atribuida a FamousSparrow en América Latina.Operation timeline2025-07Start oftheregionalpivot2025-08SparroWocky inLatin Americangovernments2025-08ReplacingSparrowDoor asthe2026-09-17ESET publishesthe regionalreport2026-09-18Cywarestrengthensregionalfocus
SparroWocky Timeline in Latin America — Milestones between July 2025 and September 2026, according to ESET and technical coverage.

Operation timeline

Date Event Actor/vector Verified source
2025-07 The cyberespionage trend against high-profile targets in Latin America begins. FamousSparrow, according to ESET ESET, Yahoo
2025-08 SparroWocky is observed being deployed against government agencies in the region. SparroWocky backdoor ESET, Business Insider
2025-08 The new backdoor replaces SparrowDoor as the main implant. Implant migration ESET, GBHackers, The Register
2025-08 The campaign affects Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. Regional campaign ESET, Infosecurity Magazine, BleepingComputer
2026-09-17 ESET publishes its report on the expansion in Latin America. ESET Research ESET
2026-09-17 Technical outlets detail execution, TCP proxying, exfiltration, and self-deletion capabilities. SparroWocky The Hacker News, BleepingComputer, Infosecurity Magazine
2026-09-18 Cyware publishes a regional take centered on Argentina, Ecuador, and Venezuela. Salt Typhoon, according to Cyware Cyware
2026-09-19 ZeroHour consolidates the timeline and attribution to the actor tracked as FamousSparrow. Malware timeline ZeroHour

Attack chain and TTPs

The attack chain that can be reconstructed from the material does not include a public exploit step by step or a published IOC list, but it does show a clear operational architecture. The most cited initial access vector is vulnerable Microsoft Exchange servers. From there, the actor deploys SparroWocky, a modular C++ backdoor designed to maintain persistent access, remote control, and discreet espionage.

Modularity matters because it allows functions to be packaged without unnecessarily bloating the implant’s core. ESET and technical outlets describe a component that can execute arbitrary commands, launch files, operate as a TCP proxy, and collect host and network-interface information. It can also exfiltrate files, take periodic screenshots, manipulate files, and erase its own presence from the compromised system.

BleepingComputer added that the code incorporates components from open source projects. That can broaden capabilities and also introduce noise for analysis and signature-based detection. SocPrime added two traits that reinforce stealth, stack spoofing and reflective loading in memory, both consistent with a design meant to complicate process tracing, memory inspection, and traditional telemetry.

The replacement of SparrowDoor with SparroWocky suggests that FamousSparrow opted for a more flexible implant to support a long-running regional objective. The material does not support a single universal infection flow, but it does show a repeated logic, initial access, backdoor deployment, environment reconnaissance, collection of sensitive information, file transfer, and selective cleanup.

TTP Description Source
Initial vector Use of vulnerable Microsoft Exchange servers as the entry point. ZeroHour, BleepingComputer
Modular backdoor SparroWocky in C++, with a modular structure aimed at stealth. ESET, The Hacker News, Infosecurity Magazine
Remote execution Execution of arbitrary commands and files on the compromised host. The Hacker News, BleepingComputer
TCP proxy Ability to act as a TCP proxy to support remote operations. The Hacker News, Infosecurity Magazine
Reconnaissance Collection of host information and network-interface data, including IPs. The Hacker News, BleepingComputer
Exfiltration Exfiltration of files and documents from the compromised environment. The Hacker News, BleepingComputer
Screenshot capture Periodic screenshots for remote observation. The Hacker News, BleepingComputer
Evasion Stack spoofing and reflective in-memory loading. SocPrime
Persistence and cleanup File operations and self-deletion from the system. The Hacker News
Flujo operativo de SparroWockyDiagrama de flujo con las etapas descritas en el material consolidado.Attack chain and functionsExchangevulnerableBackdoor deploymentbackdoorReconnaissanceand hostExfiltrationand captureSelf-deletesif possibleDocumented functions: arbitrary execution, TCP proxying, screenshot capture, file operations, and in-memory evasion.
SparroWocky operational chain — Summary flow of initial access, deployment, and backdoor functions.

Regional impact

The operation shows an unusual concentration in Latin America and, within that region, a clear bias toward government entities. ESET said that about 90% of the targets observed in its telemetry between mid-2025 and 2026 were located in the region. Some coverage, including Cyware, also said the focus extended to telecommunications in Argentina, Ecuador, and Venezuela.

The strongest reading of the material is that the campaign was not episodic. It lasted for months, changed implants, and kept the same core interest, access to state networks and extraction of sensitive information. That persistence explains why so many separate outlets, even with different names for the actor, end up describing the same victim surface.

Cobertura regional verificadaMatriz con países citados en el material consolidado y la lectura sectorial principal.Regional coverageConfirmed countriesPrimary sectorBackdoorArgentina, Ecuador, Guatemala, HondurasGovernmentSparroWockyPanama, Peru, Puerto Rico, VenezuelaGovernmentSparroWockyChile, Paraguay, Bolivia, Colombia, Brazil, MexicoNo verifiablefacts
Verified regional coverage — Countries consistently mentioned in the ESET report and technical coverage.

Regional overview

ESET reported activity against government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela, and said SparroWocky had been deployed since at least August 2025. ZeroHour consolidated the same list of countries in its timeline, while Infosecurity Magazine, BleepingComputer, The Hacker News, and GBHackers repeated the victim set and the campaign’s persistence.

The sectoral relevance is centered on the public sector, although Cyware added telecommunications as a second front. The evidence does not support extending the scope to other sectors with the same confidence. The material also does not provide victim counts by country, so the geographic spread should be treated as an observed concentration, not an exhaustive tally.

Argentina

Argentina is among the countries where ESET observed SparroWocky in attacks against government organizations. The country appears repeatedly in coverage from Infosecurity Magazine, BleepingComputer, The Hacker News, GBHackers, CyberInsider, ZeroHour, and The Register, always within the same regional campaign attributed to FamousSparrow.

Peru

Peru appears explicitly in ESET’s report and in virtually all technical follow-up coverage. The material places it among the countries affected by SparroWocky deployments against government entities since August 2025. The Record added that Alexandre Côté Cyr’s tracking of the campaign reached government departments in Peru, along with other countries in the region.

Ecuador

Ecuador is part of the set of countries where ESET observed the backdoor. Cyware also mentioned it in its September 18, 2026, bulletin when describing the shift in focus toward Latin America, along with Argentina and Venezuela. No additional verifiable details are available in the consolidated material about specific Ecuadorian entities.

Guatemala

Guatemala appears on the list of government entities affected by SparroWocky. The overlap among ESET, BleepingComputer, Infosecurity Magazine, The Hacker News, ZeroHour, and The Record reinforces that it was one of the confirmed targets in the regional campaign.

Honduras

Honduras also appears among the countries where the backdoor was observed against public agencies. The mention is consistent across the main follow-up reports derived from ESET’s research and is not paired with a verifiable sector beyond the state focus.

Panama

Panama appears repeatedly on the list of countries attacked. The material includes it both in ESET’s roster and in specialist summaries, always under the same espionage pattern against government entities.

Puerto Rico

Puerto Rico appears as a target in the consolidated material and is treated by ESET and related coverage as part of the Latin American theater of the campaign. The Record and ZeroHour include it in their lists, alongside Argentina, Guatemala, Honduras, Panama, Peru, and Venezuela.

Venezuela

Venezuela appears in ESET’s cited telemetry and in several later reports. Cyware also mentions it in the context of the shift toward Latin America, along with Argentina and Ecuador, although that strategic reading is the outlet’s interpretation rather than a primary finding in the technical report.

Chile

No specific facts were verified about Chile in the material provided.

Paraguay

No specific facts were verified about Paraguay in the material provided.

Bolivia

No specific facts were verified about Bolivia in the material provided.

Colombia

No specific facts were verified about Colombia in the material provided.

Brazil

No specific facts were verified about Brazil in the material provided.

Mexico

No specific facts were verified about Mexico in the material provided.

United States

No specific facts were verified about the United States as a direct victim in the material provided. The country appears only as contextual reference in some coverage about Chinese investments and in the strategic reading by Cyware and DarkReading, not as a confirmed target of the campaign.

The countries without additional verifiable coverage in the material are Chile, Paraguay, Bolivia, Colombia, Brazil, and Mexico.

Technical indicators

No concrete IOCs were published in the consolidated material. There are no hashes, domains, IPs, file paths, or mutex names that can be verified from the sources provided. The technical reading therefore has to rest on TTPs and behavioral identification, not on a list of specific indicators.

Analysis for security teams

The immediate priority for defenders in Latin American government organizations is to review Microsoft Exchange exposure and abuse, because that is the initial vector consistently mentioned in the material. Any exposed or poorly patched instance deserves urgent review. The fact that the campaign has remained active since August 2025 and is still appearing in September 2026 suggests this is not a closed incident, but an operational capability the actor sustained over time.

For detection, the focus should be on patterns consistent with modular backdoors, not only on static signatures. SparroWocky can execute arbitrary commands, launch files, act as a TCP proxy, collect host data, take screenshots, exfiltrate files, and self-delete. That combination calls for process telemetry, anomalous outbound connections, unexpected screen-capture activity, and events involving mass access or reading of sensitive files.

The mention of open source components and techniques such as stack spoofing and reflective loading means defenders need a broader view. An EDR that depends only on process names or exact hashes will fall short against a modular family that blends in with legitimate libraries and in-memory loading or injection techniques. Hunting should focus on process trees, lateral connections, service abuse, and file movements that match exfiltration phases.

From a prioritization standpoint, government teams in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela should treat this as persistent espionage, not a one-off outbreak. The coverage is consistent that the main target is the public sector, with a possible second focus on telecommunications. That justifies reviewing privilege controls, segmentation, mail exposure, network ingress and egress monitoring, and alerts for unusual screen capture or packaging of documents.

It is also worth adjusting detection to avoid naming confusion. WindowsForum warns that some publications mislabeled the campaign as Salt Typhoon. If internal rules or playbooks use the wrong name, response can be incomplete. The most consistent operational reference in the material is FamousSparrow, with SparroWocky as the main backdoor.

Frequently asked questions

Is the campaign attributed by ESET to FamousSparrow still active, and where was it seen?

Yes. The consolidated material indicates activity from at least August 2025 through September 2026, with observations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. That timeline runs across the Operation timeline and Regional impact sections.

What technically changed between SparrowDoor and SparroWocky?

SparroWocky became the group’s main backdoor rather than a minor variant. Unlike SparrowDoor, it is described as a modular C++ malware with command execution, TCP proxying, exfiltration, screenshot capture, and self-deletion. That crosses the Attack chain and TTPs and Context and background sections.

Which sectors were most exposed according to the material?

The public sector is the clearest documented target. ESET and the reporting based on its research describe attacks against agencies and government organizations, and Cyware adds telecommunications in some countries. This crosses Regional impact, Regional overview, and the Key facts table.

Which country appears most clearly in the coverage besides Argentina?

Peru appears explicitly and repeatedly in ESET, Infosecurity Magazine, BleepingComputer, The Hacker News, GBHackers, ZeroHour, and The Record. The mention crosses Regional impact, the Key facts table, and the Operation timeline, where it appears as a confirmed target in the regional set.

What kind of detection should be prioritized if no IOCs were published?

Behavior-based detection should be prioritized, especially Exchange abuse, unusual remote execution, TCP proxying, unexpected screenshots, file exfiltration, and evasion techniques such as reflective in-memory loading. That crosses Technical indicators with Analysis for security teams and Attack chain and TTPs.

Material limitations

The material provided does not include verifiable IOCs, hashes, domains, IPs, file names, or EDR signatures. It also does not allow a full infection chain to be reconstructed with a confirmed public exploit, nor does it let analysts attribute successful exfiltration to a specific victim with precision. Some secondary reports offer geopolitical interpretation about motives, but those readings are attributed to each outlet and not presented as primary facts in ESET’s report.

Sources and brief coverage for follow-up

Concentración regional observadaBarra comparativa que refleja la proporción aproximada citada por ESET en su telemetría.Concentration seen in telemetryLatin America~90% according to ESETOther targets~10%Consolidated data based on telemetry cited by ESET between mid-2025 and 2026.
Observed regional concentration — Qualitative view of target concentration in Latin America, according to ESET.

Sources

View all