FamousSparrow Uses SparroWocky in Latin America
ESET links FamousSparrow to a SparroWocky campaign against Latin American governments, with eight territories and 90% of targets in the region.
ESET has attributed with high confidence a sustained espionage campaign against Latin American governments to FamousSparrow, using a new modular C++ backdoor called SparroWocky. Based on telemetry analyzed between mid-2025 and 2026, about 90% of observed targets were in the region, with activity against government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The finding also marks the retirement of the earlier SparrowDoor implant, which was replaced by a more flexible and harder-to-detect component.
Executive summary
ESET has attributed with high confidence a cyberespionage campaign against Latin American governments to FamousSparrow, based on a new modular C++ backdoor called SparroWocky. Telemetry analyzed by the company between mid-2025 and 2026 shows that about 90% of the observed targets were in the region, with activity in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.
The main technical shift is the replacement of SparrowDoor with SparroWocky. The new implant expands the group’s operational reach and raises the cost of detection. It is delivered through DLL sideloading, uses an RC4-encrypted .dat file that holds both configuration and payload, and loads reflectively in memory. That design keeps the backdoor off disk and makes inspection harder for tools that rely on classic Portable Executable patterns.
The malware’s toolset is broad. Sources agree that SparroWocky can run commands, launch files, open an interactive shell, act as a TCP proxy, exfiltrate data, take periodic screenshots, collect host and network information, and self-delete. It also executes Beacon Object Files in memory, allowing the operators to reuse modules built for offensive frameworks such as Cobalt Strike, Sliver, Metasploit, and Brute Ratel. Several analyses describe it as a separate malware family, not a simple linear evolution of SparrowDoor.
Public attribution also came with an important clarification. Although several media outlets initially linked the activity to Salt Typhoon, ESET says the public technical evidence is not enough to merge Salt Typhoon and FamousSparrow into a single group. WindowsForum and the Spanish version of WeLiveSecurity emphasize that distinction and warn against treating both names as one operation. In practice, that means the reports need to be read carefully: SparroWocky was tied with high confidence to FamousSparrow, while Salt Typhoon appears in some coverage as an editorial comparison, not as a conclusion confirmed by the public sample.
The regional context is widened by two Mirage Security campaigns published in September 2026. One targets Brazilian banks through phishing attachments disguised as résumés, tunneling tools, and remote access malware. The other, identified as CL-CRI-1131, focuses on Mexico with living-off-the-land scripts, data exfiltration, and an AI chatbot called NextChat deployed on infrastructure controlled by the attackers. There is no evidence in the material that either campaign is part of the same cluster as SparroWocky, but they show a region where state espionage, multistage phishing, reusable tooling, and operational AI all coexist.
Context and background
FamousSparrow had already appeared in technical literature as a China-aligned espionage actor, but ESET’s September 2026 report gave that picture far more detail. Telemetry collected since mid-2025 showed a clear shift toward Latin America, which accounted for roughly 90% of the targets observed by the company. That figure underpins the regional nature of the campaign and explains why so many secondary reports repeat the same country list.
The most important detail is not just the volume of targets, but the pattern. The observed victims were government entities, not a scattered set of private companies. Targeting state bodies points to intelligence collection, long-term access, and communications monitoring, not an opportunistic monetization campaign. Dark Reading adds an interpretive layer by saying the campaign is aimed at agencies tied to Chinese investments and political issues involving the United States. That is an analytical reading, not an extra attribution, but it helps explain the strategic interest in the region.
SparroWocky replaced SparrowDoor as the group’s main implant. ESET, Infosecurity Magazine, WeLiveSecurity, The Register, CyberInsider, Mallory.ai, and other secondary analyses all confirm that shift. The overlap across sources suggests this was not an isolated sample, but an update to the group’s operational line. From a defensive standpoint, that matters because each implant change alters artifacts, detection patterns, and in-memory behavior.
The public discussion was also complicated by a naming mix-up. Some media coverage used the Salt Typhoon label, while ESET kept FamousSparrow and Salt Typhoon separate because there are no technical indicators proving they are the same operation. WindowsForum makes that point explicitly, and WeLiveSecurity repeats it in Spanish. The practical takeaway is simple: names should not be merged automatically in internal rules, reports, or attribution matrices.
In parallel, Mirage Security published two intrusion studies that are not attributed to the same actor, but still help frame regional trends. In Brazil, case CL-CRI-1163 describes a multistage operation against the financial sector. In Mexico, cluster CL-CRI-1131 combines living-off-the-land techniques, exfiltration, and an infrastructure exposing NextChat, an AI chatbot the attackers used to debug and generate scripts. That second case is especially relevant because it shows a hybrid offensive environment, with automation and accidental exposure of attacker assets.
Key facts table
| Date | Fact | Source | Confidence |
|---|---|---|---|
| 2026-09-17 | ESET attributes a cyberespionage campaign using the SparroWocky backdoor to FamousSparrow. | ESET | confirmed |
| 2026-09-17 | ESET says that since at least August 2025 the group deployed SparroWocky in Latin America and abandoned SparrowDoor. | ESET | confirmed |
| 2026-09-17 | ESET telemetry places about 90% of FamousSparrow’s targets in Latin America between mid-2025 and 2026. | ESET | confirmed |
| 2026-09-17 | ESET observed the backdoor against government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. | ESET | confirmed |
| 2026-09-17 | Cloud Security Alliance describes a loading chain with a legitimate executable, a malicious DLL, and an RC4-encrypted .dat file. | CSA | confirmed |
| 2026-09-17 | Cloud Security Alliance reports more than 30 commands and in-memory execution of Beacon Object Files. | CSA | confirmed |
| 2026-09-17 | BleepingComputer documents screenshots every 500 ms and differential transmission of changes. | BleepingComputer | confirmed |
| 2026-09-17 | Allatra Media and WBOC note RC4 encryption for exfiltration and transport over TLS with Mbed TLS. | Allatra Media, WBOC | confirmed |
| 2026-09-17 | Offseq Radar highlights reflective modules, stack spoofing, and BOF support for offensive tooling integration. | Offseq Radar | confirmed |
| 2026-09-18 | WindowsForum clarifies that ESET attributes SparroWocky to FamousSparrow, not Salt Typhoon. | WindowsForum | confirmed |
| 2026-09-03 | Mirage Security documents campaigns in Brazil and Mexico with phishing, living-off-the-land, exfiltration, and offensive AI use. | Mirage Security | confirmed |
Operation timeline
| Date | Event | Actor/vector | Verified source |
|---|---|---|---|
| 2025-07 | The regional campaign intensifies its focus on Latin American governments, according to Cyberpress. | FamousSparrow, government espionage | Cyberpress |
| 2025-08 | ESET identifies SparroWocky being deployed against public-sector entities in Latin America for the first time. | FamousSparrow, modular malware | ESET, The Register |
| 2025-08 to 2026-09 | Accumulated telemetry places about 90% of FamousSparrow’s targets in Latin America. | Sustained campaign | ESET |
| 2026-09-03 | Mirage Security publishes case CL-CRI-1131, with NextChat AI infrastructure and exfiltration. | Mexico cluster, living-off-the-land | Mirage Security |
| 2026-09-03 | Mirage Security publishes case CL-CRI-1163 against Brazilian banks. | Brazil cluster, phishing and exfiltration | Mirage Security |
| 2026-09-17 | ESET releases the technical analysis of SparroWocky and its replacement of SparrowDoor. | ESET, FamousSparrow | ESET / WeLiveSecurity |
| 2026-09-17 | Secondary reports repeat the finding in security outlets and general press. | Secondary editorial chain | Infosecurity, BleepingComputer, The Register, Dark Reading |
| 2026-09-18 | WindowsForum qualifies the attribution and separates FamousSparrow from Salt Typhoon. | Attribution clarification | WindowsForum |
| 2026-09-22 | Mallory.ai consolidates the technical profile of SparroWocky with capabilities and persistence. | Technical normalization | Mallory.ai |
Attack chain and TTPs
SparroWocky is built to arrive through DLL sideloading and stay in memory. The sequence described by Cloud Security Alliance and Mallory.ai combines a legitimate executable, a malicious patched DLL, and an RC4-encrypted .dat file that holds both configuration and payload. The loader reads that file, decrypts both components, and executes them reflectively, without writing the backdoor to disk.
That mechanism has two practical effects. First, it reduces forensic footprint, because the main sample lives in memory and does not necessarily appear as a recoverable binary in the file system. Second, it gives operators flexibility, since configuration, modules, or parameters can change without rebuilding the entire chain. HackRead adds that the PE payload may load with its MZ and PE headers removed, which makes memory scanning harder.
Persistence is implemented in two ways, depending on the configuration observed. The implant can create a Windows service or a Run key in the registry. That dual path lets operators adapt to host controls and to the level of stealth they want. In monitored environments, finding these keys alongside unusual DLL paths can be more useful than looking only for the backdoor binary.
The functional set is wide. ESET, Infosecurity Magazine, The Hacker News, Cyware, and Mallory.ai agree that SparroWocky can run commands, launch files, interact with a shell, exfiltrate files, list disks, folders, files, screens, and user sessions, take periodic screenshots, and act as a TCP proxy. It also includes reverse port forwarding and a self-destruction mechanism. In capability terms, this is not a minimal implant but a full remote operations platform.
Visual surveillance deserves its own note. BleepingComputer documented that the malware takes screenshots every 500 milliseconds and, after the first full image, sends only the changed regions. That optimization reduces bandwidth use and lowers network noise. For defenders, the result is a quieter espionage session than a simple raw screenshot dump.
SparroWocky also borrows code and techniques from existing projects. Several sources point to Mbed TLS for encrypted communications, MinHook for API hooking, and evasions associated with SilentMoonwalk and call-stack spoofing. CyberInsider and Offseq Radar add that the backdoor integrates Beacon Object Files and loads modules associated with Cobalt Strike, Metasploit, Sliver, and Brute Ratel. That suggests a modular attack chain, with offensive tooling reuse and a fairly mature integration layer.
TTPs observed in SparroWocky
| TTP | Description | Source |
|---|---|---|
| DLL sideloading | Side-loading with a legitimate executable, malicious DLL, and payload in .dat | CSA, Mallory.ai, Cyware |
| Reflective loading | Payload is decrypted and mapped in memory without being written to disk | CSA, CyberInsider |
| RC4 | Encryption of the .dat file and exfiltrated information | CSA, Allatra Media, WBOC |
| Mbed TLS | TLS channel for C2 and secure transport | Aviatrix, Cyware, Allatra Media |
| MinHook | Windows API hooking | Allatra Media, Cyware |
| SilentMoonwalk | Evasion through call-stack spoofing | Offseq Radar, Cyware |
| BOF | In-memory execution of Beacon Object Files | CSA, CyberInsider |
| Persistence | Windows service or Run key | Allatra Media, HackRead, CyberInsider, Mallory.ai |
| Screenshot capture | Periodic screenshots with differential change transmission | BleepingComputer, Infosecurity Magazine |
| Exfiltration | Collection and theft of host files and data | SecNews, Infosecurity Magazine, Cyware |
Regional impact
Regional overview
The geographic impact is clear. The SparroWocky campaign concentrates on Latin American governments and places the region at the center of ESET’s observed telemetry. The material does not show a uniform spread, but a pattern dominated by public-sector entities and a persistent timeline extending from at least August 2025 through September 2026.
The country list appears repeatedly across multiple outlets and matches ESET’s publication: Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. That repetition gives the fact set more weight. It also supports an operational reading: this is not a mass opportunistic campaign, but a sustained effort to access specific government networks.
One methodological point should be stated clearly. WindowsForum notes that ESET’s public report does not name specific agencies or the number of compromised endpoints. So the evidence confirms targeting and malware deployment, but not broad compromises across every government. That distinction between observed targets and the actual scope of the incident matters for any internal assessment.
Argentina
Argentina appears consistently in the list of victims observed by ESET and in coverage from Infosecurity Magazine, The Register, BleepingComputer, Dark Reading, TechRadar Pro, and other secondary outlets. The pattern is the same as in the rest of the region, with focus on government entities and use of the SparroWocky backdoor for sustained access.
Cyware and WindowsForum reinforce that point by including Argentina among the Latin American governments affected by the campaign while also warning that the public attribution remains FamousSparrow, not an automatic merge with Salt Typhoon. For an Argentine defense team, the useful takeaway is twofold: the implant’s presence is plausible, and attribution needs to remain precise.
Peru
Peru appears repeatedly in the material as one of the countries observed by ESET. The Manila Times, The Record, BleepingComputer, Infosecurity Magazine, TechRadar Pro, CyberInsider, WBOC, and Offseq Radar all include it among the governmental targets of SparroWocky. That indicates the campaign was neither marginal nor isolated in the country, but part of the same regional intrusion series.
The repeated mention of Peru in technical and general-interest outlets also suggests continuity over time. The Record places the tracking back to at least August 2025, while TechRadar Pro describes activity between mid-2025 and 2026. From a defensive standpoint, that means the campaign should be treated as prolonged, not as a one-off event.
Mexico
Mexico does not appear in ESET’s telemetry on SparroWocky, and WindowsForum and the Spanish version of WeLiveSecurity state that explicitly. However, Mirage Security documents a separate cluster with a Mexico focus, CL-CRI-1131, which uses living-off-the-land techniques, exfiltration tools, and an infrastructure exposing NextChat, an AI chatbot used to debug and generate scripts.
That case should not be confused with FamousSparrow. The material does not attribute CL-CRI-1131 to that group or to the SparroWocky backdoor. Its value is that it shows a second line of pressure on the region, different from the government espionage campaign but still relevant to Mexico because of the use of native scripts and the accidental exposure of offensive infrastructure.
Brazil
Brazil appears in the material through Mirage Security’s study of a multistage campaign against banks and other financial entities. There the attackers used phishing attachments disguised as résumés, downloaded and executed tunneling tools and remote access malware, and operated in a separate cluster with no public attribution to a specific state actor.
That case is useful as a contrast. While SparroWocky is aimed at Latin American governments, the Brazilian cluster targets the financial sector. Looking at both cases together shows that the region is being hit by campaigns with different goals, vectors, and levels of maturity, which means controls need to be segmented rather than treating every regional intrusion as the same pattern.
United States, Puerto Rico
Puerto Rico appears in ESET’s target list as a territory of the United States. In the available material, the interest in Puerto Rico is not presented as a separate campaign, but as part of the same set of government intrusions across Latin America. That inclusion matters because it extends the geographic impact beyond South and Central America.
The rest of the United States does not appear in the published telemetry for SparroWocky. Puerto Rico’s presence does not change the regional character of the case, but it does show that the espionage reach is not limited to sovereign states on the continent. It also explains why some English-language coverage mixes Latin America with U.S. territories when describing the case.
Countries without specific verifiable coverage
No additional verifiable facts were identified for Chile, Paraguay, Bolivia, Colombia, or Uruguay in the material provided.
Technical indicators
The material does not include hashes, IPs, domains, or directly reusable full IOC filenames for the backdoor. It does, however, provide DLL and component names observed in the loading chain, which can serve as partial indicators in environments where they are not expected legitimately.
| Type | Value | Source |
|---|---|---|
| DLL | winfsp-x64.dll | CyberInsider |
| DLL | DukeQt.dll | CyberInsider |
| Technique | DLL sideloading | CSA, Cyware, Mallory.ai |
| Technique | RC4 in .dat file | CSA, Allatra Media, WBOC |
| Technique | MinHook | Allatra Media, Cyware |
| Technique | Mbed TLS | Aviatrix, Cyware, Allatra Media |
Guidance for security teams
Operational priority should be the loading chain and persistence, not just the final payload. In this case the main sample lives in memory and relies on sideloading, so detection should focus on unusual relationships between legitimate executables, patched DLLs, and RC4-encrypted .dat files. If a workstation exposes winfsp-x64.dll or DukeQt.dll out of context, the full execution path and process tree should be reviewed.
On Windows endpoints, monitoring for new services and suspicious Run keys is especially useful. Persistence can take either form, depending on how the implant is configured. Teams should also look for hooking and anti-analysis signals, because MinHook, call-stack spoofing, and SilentMoonwalk-derived techniques appear consistently in the published analyses.
The network also leaves traces. Mbed TLS means traffic may look like legitimate TLS, but that does not remove the need to review destination patterns, beaconing intervals, exfiltration volume, and screenshot behavior. BleepingComputer’s note about differential screenshots every 500 milliseconds is useful for spotting short, repetitive bursts even when each event is small.
Behavior-based detection can be complemented with rules for BOF and COFF loaders, because SparroWocky executes offensive modules in memory. That broadens alerting to code associated with frameworks such as Cobalt Strike, Sliver, Brute Ratel, and Metasploit. Not every BOF use is malicious, but in government or financial environments in the region it deserves closer review.
For prioritization, the logical order is this: 1) look for evidence of sideloading and anomalous DLLs, 2) verify persistence through services or Run keys, 3) review TLS traffic and unusual screen changes, 4) check for RC4 payload decryption or memory mapping, 5) correlate with institutional targets in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. In government networks, any indicator in this set should be treated as espionage rather than an isolated event.
Frequently asked questions
What changed between SparrowDoor and SparroWocky in the FamousSparrow campaign?
SparroWocky replaced SparrowDoor as the group’s main implant and expanded operational capability with a modular C++ architecture, reflective loading, anti-analysis, and in-memory BOF execution. The practical difference is that the new backdoor leaves less disk evidence and offers more commands, as detailed in Attack chain and TTPs and Context and background.
Should the campaign observed by ESET be attributed to Salt Typhoon or FamousSparrow?
ESET’s public attribution is FamousSparrow, not Salt Typhoon. Some outlets used both names, but WindowsForum and WeLiveSecurity say there are no technical indicators strong enough to merge them into one operation. That nuance is explained in Executive summary, Context and background, and the Regional impact section.
Which countries appear with verifiable evidence in this regional operation?
The consolidated evidence mentions Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The material also includes a separate Mirage Security case in Mexico and another campaign in Brazil, but does not link them to SparroWocky. The full list is in the Key facts table and Regional impact.
What specific capabilities does SparroWocky give operators?
The backdoor runs commands and files, works as a TCP proxy, exfiltrates data, captures screens, collects host and network information, lists disks, folders, and sessions, and can remove itself from the system. It also executes Beacon Object Files in memory. That technical detail is covered in Attack chain and TTPs and Technical indicators.
What signals should security teams look for first?
First, look for DLL sideloading, new services or suspicious Run keys, and legitimate binaries loading anomalous DLLs. Then review TLS traffic, periodic screenshots, RC4 activity in memory, and the presence of winfsp-x64.dll or DukeQt.dll outside their normal context. The prioritization is in Guidance for security teams.
Do the Mexico and Brazil campaigns belong to the same actor as SparroWocky?
The available material does not support that conclusion. Mirage Security documents a Mexico-focused cluster with NextChat and a Brazil campaign against banks, but does not publicly attribute either one to FamousSparrow or SparroWocky. The overlap and the distinction are explained in Context and background and Regional impact.
Material limitations
The material does not include hashes, domains, IP addresses, or other full IOCs for a closed detection list. It also does not identify specific government agencies, the number of affected endpoints, or an exact infection timeline by country. The public telemetry summarizes regional scope, but not a country-by-country victim inventory.
In addition, Mirage Security’s campaigns in Mexico and Brazil appear as independent operations and are not publicly attributed to the same actor as SparroWocky. They are used here only as regional context, not as an extension of the FamousSparrow campaign. The confusion between FamousSparrow and Salt Typhoon also means the attribution reported by ESET should be kept exact.
Sources
- ESET Research: FamousSparrow targets Latin American governments with new SparroWocky backdooreset.com· ESET
- Resume Phish Hit Brazil Banks; AI Aided Opsmiragesecurity.ai· Mirage Security
- ESET Uncovers New FamousSparrow Backdoor Deployed Against Latin American Governmentsallatra.media· Allatra Media
- SparroWocky (Malware): news timeline & CVEs · ZeroHourzerohour.day· ZeroHour.day
- New SparroWocky Backdoor Targets Latin Americadecipher.sc· Decipher
- Beware the SparroWock: The backdoor that bites, the commands that catchradar.offseq.com· Offseq Radar
- FamousSparrow: SparroWocky Backdoor Targets Government Organizationssecnews.gr· SecNews
- Čínská FamousSparrow přesunula pozornost na Latinskou ...czechcyber.tv· CzechCyber.tv
- FamousSparrow Deploys SparroWocky Backdoor in Latin Americaaviatrix.ai· Aviatrix
- ESET Research: China-aligned FamousSparrow expands operations in Latin America, targets governments with new backdoormanilatimes.net· The Manila Times / TMT Newswire
- China-Linked FamousSparrow Deploys SparroWocky Backdoor in Latin Americahackread.com· HackRead
- Salt Typhoon развернула новый бэкдор SparroWocky в госсетях Латинской Америкиtechora.ru· Techora.ru
- China's Salt Typhoon backdoors Latin American orgs with new snooping malwaretheregister.com· The Register
- China-Aligned FamousSparrow Deploys SparroWocky Backdoor in Latin American Cyber Espionage Campaignthehackernews.com· The Hacker News
- FamousSparrow Swaps SparrowDoor For New ...infosecurity-magazine.com· Infosecurity Magazine
- Grupo cibercriminoso ligado à China mira América Latina com novo vírusestadao.com.br· Tecmundo
- IntelFreed.com | Cybersecurity Intelligence Weather Reportintelfreed.com· IntelFreed
- SparroWocky Backdoor Linked to FamousSparrow, Not Salt Typhoonwindowsforum.com· WindowsForum
- FamousSparrow centra sus operaciones en América Latina y ...welivesecurity.com· WeLiveSecurity (ESET)
- China's Salt Typhoon spotted probing Latin American government with newly developed SparroWocky backdoortechradar.com· TechRadar Pro
- ESET Research: China-aligned FamousSparrow expands operations in Latin America, targets governments with new backdoorfinance.yahoo.com· Yahoo Finance
- FamousSparrow's SparroWocky Backdoor Targets Latin American Governments Amid US-China Rivalrythreatpaper.com· ThreatPaper
- China's FamousSparrow APT Spies on US Politics in Latin Americadarkreading.com· Dark ReadingUnverified URL
- China-Aligned Hackers Target Entity in Panama Canal Port Dispute, ESET Saystheepochtimes.com· The Epoch Times
- FamousSparrow Targets Government Networks Across Latin Americacyberpress.org· Cyberpress
- SparroWocky: FamousSparrow’s New Backdoor Hits Latin Americalabs.cloudsecurityalliance.org· Cloud Security Alliance
- China's FamousSparrow hackers target Latin America with ...therecord.media· The Record
- Beware the SparroWock: The backdoor that bites, the commands that catchwelivesecurity.com· ESET / WeLiveSecurity
- ESET Research: China-aligned FamousSparrow expands operations in Latin America, targets governments with new backdooritnerd.blog· The IT Nerd
- Chinese hackers use SparroWocky malware in govt espionage attacksbleepingcomputer.com· BleepingComputer
- SparroWocky - Mallory.aimallory.ai· Mallory.ai
- FamousSparrow Deploys New SparroWocky Backdoor Against Latin American Governmentsgbhackers.com· GBHackers on Security
- New SparroWocky backdoor deployed in attacks on governmentscyberinsider.com· CyberInsider
- ESET Research: China-aligned FamousSparrow expands operations in Latin America targets governments with new backdoorwboc.com· WBOC
- Chinese hackers use SparroWocky malware in govt espionage attacksground.news· Ground News
- Cyware Weekly Threat Intelligence - September 18, 2026cyware.com· Cyware



