CiberLATAMbywhalemate

FamousSparrow Uses SparroWocky in Latin America

ESET links FamousSparrow to a SparroWocky campaign against Latin American governments, with eight territories and 90% of targets in the region.

Whalemate Labs · AI-assisted researchPublished:38 min read

ESET has attributed with high confidence a sustained espionage campaign against Latin American governments to FamousSparrow, using a new modular C++ backdoor called SparroWocky. Based on telemetry analyzed between mid-2025 and 2026, about 90% of observed targets were in the region, with activity against government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The finding also marks the retirement of the earlier SparrowDoor implant, which was replaced by a more flexible and harder-to-detect component.

Executive summary

ESET has attributed with high confidence a cyberespionage campaign against Latin American governments to FamousSparrow, based on a new modular C++ backdoor called SparroWocky. Telemetry analyzed by the company between mid-2025 and 2026 shows that about 90% of the observed targets were in the region, with activity in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.

The main technical shift is the replacement of SparrowDoor with SparroWocky. The new implant expands the group’s operational reach and raises the cost of detection. It is delivered through DLL sideloading, uses an RC4-encrypted .dat file that holds both configuration and payload, and loads reflectively in memory. That design keeps the backdoor off disk and makes inspection harder for tools that rely on classic Portable Executable patterns.

The malware’s toolset is broad. Sources agree that SparroWocky can run commands, launch files, open an interactive shell, act as a TCP proxy, exfiltrate data, take periodic screenshots, collect host and network information, and self-delete. It also executes Beacon Object Files in memory, allowing the operators to reuse modules built for offensive frameworks such as Cobalt Strike, Sliver, Metasploit, and Brute Ratel. Several analyses describe it as a separate malware family, not a simple linear evolution of SparrowDoor.

Public attribution also came with an important clarification. Although several media outlets initially linked the activity to Salt Typhoon, ESET says the public technical evidence is not enough to merge Salt Typhoon and FamousSparrow into a single group. WindowsForum and the Spanish version of WeLiveSecurity emphasize that distinction and warn against treating both names as one operation. In practice, that means the reports need to be read carefully: SparroWocky was tied with high confidence to FamousSparrow, while Salt Typhoon appears in some coverage as an editorial comparison, not as a conclusion confirmed by the public sample.

The regional context is widened by two Mirage Security campaigns published in September 2026. One targets Brazilian banks through phishing attachments disguised as résumés, tunneling tools, and remote access malware. The other, identified as CL-CRI-1131, focuses on Mexico with living-off-the-land scripts, data exfiltration, and an AI chatbot called NextChat deployed on infrastructure controlled by the attackers. There is no evidence in the material that either campaign is part of the same cluster as SparroWocky, but they show a region where state espionage, multistage phishing, reusable tooling, and operational AI all coexist.

Context and background

FamousSparrow had already appeared in technical literature as a China-aligned espionage actor, but ESET’s September 2026 report gave that picture far more detail. Telemetry collected since mid-2025 showed a clear shift toward Latin America, which accounted for roughly 90% of the targets observed by the company. That figure underpins the regional nature of the campaign and explains why so many secondary reports repeat the same country list.

The most important detail is not just the volume of targets, but the pattern. The observed victims were government entities, not a scattered set of private companies. Targeting state bodies points to intelligence collection, long-term access, and communications monitoring, not an opportunistic monetization campaign. Dark Reading adds an interpretive layer by saying the campaign is aimed at agencies tied to Chinese investments and political issues involving the United States. That is an analytical reading, not an extra attribution, but it helps explain the strategic interest in the region.

SparroWocky replaced SparrowDoor as the group’s main implant. ESET, Infosecurity Magazine, WeLiveSecurity, The Register, CyberInsider, Mallory.ai, and other secondary analyses all confirm that shift. The overlap across sources suggests this was not an isolated sample, but an update to the group’s operational line. From a defensive standpoint, that matters because each implant change alters artifacts, detection patterns, and in-memory behavior.

The public discussion was also complicated by a naming mix-up. Some media coverage used the Salt Typhoon label, while ESET kept FamousSparrow and Salt Typhoon separate because there are no technical indicators proving they are the same operation. WindowsForum makes that point explicitly, and WeLiveSecurity repeats it in Spanish. The practical takeaway is simple: names should not be merged automatically in internal rules, reports, or attribution matrices.

In parallel, Mirage Security published two intrusion studies that are not attributed to the same actor, but still help frame regional trends. In Brazil, case CL-CRI-1163 describes a multistage operation against the financial sector. In Mexico, cluster CL-CRI-1131 combines living-off-the-land techniques, exfiltration, and an infrastructure exposing NextChat, an AI chatbot the attackers used to debug and generate scripts. That second case is especially relevant because it shows a hybrid offensive environment, with automation and accidental exposure of attacker assets.

Key facts table

Date Fact Source Confidence
2026-09-17 ESET attributes a cyberespionage campaign using the SparroWocky backdoor to FamousSparrow. ESET confirmed
2026-09-17 ESET says that since at least August 2025 the group deployed SparroWocky in Latin America and abandoned SparrowDoor. ESET confirmed
2026-09-17 ESET telemetry places about 90% of FamousSparrow’s targets in Latin America between mid-2025 and 2026. ESET confirmed
2026-09-17 ESET observed the backdoor against government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. ESET confirmed
2026-09-17 Cloud Security Alliance describes a loading chain with a legitimate executable, a malicious DLL, and an RC4-encrypted .dat file. CSA confirmed
2026-09-17 Cloud Security Alliance reports more than 30 commands and in-memory execution of Beacon Object Files. CSA confirmed
2026-09-17 BleepingComputer documents screenshots every 500 ms and differential transmission of changes. BleepingComputer confirmed
2026-09-17 Allatra Media and WBOC note RC4 encryption for exfiltration and transport over TLS with Mbed TLS. Allatra Media, WBOC confirmed
2026-09-17 Offseq Radar highlights reflective modules, stack spoofing, and BOF support for offensive tooling integration. Offseq Radar confirmed
2026-09-18 WindowsForum clarifies that ESET attributes SparroWocky to FamousSparrow, not Salt Typhoon. WindowsForum confirmed
2026-09-03 Mirage Security documents campaigns in Brazil and Mexico with phishing, living-off-the-land, exfiltration, and offensive AI use. Mirage Security confirmed

Operation timeline

Date Event Actor/vector Verified source
2025-07 The regional campaign intensifies its focus on Latin American governments, according to Cyberpress. FamousSparrow, government espionage Cyberpress
2025-08 ESET identifies SparroWocky being deployed against public-sector entities in Latin America for the first time. FamousSparrow, modular malware ESET, The Register
2025-08 to 2026-09 Accumulated telemetry places about 90% of FamousSparrow’s targets in Latin America. Sustained campaign ESET
2026-09-03 Mirage Security publishes case CL-CRI-1131, with NextChat AI infrastructure and exfiltration. Mexico cluster, living-off-the-land Mirage Security
2026-09-03 Mirage Security publishes case CL-CRI-1163 against Brazilian banks. Brazil cluster, phishing and exfiltration Mirage Security
2026-09-17 ESET releases the technical analysis of SparroWocky and its replacement of SparrowDoor. ESET, FamousSparrow ESET / WeLiveSecurity
2026-09-17 Secondary reports repeat the finding in security outlets and general press. Secondary editorial chain Infosecurity, BleepingComputer, The Register, Dark Reading
2026-09-18 WindowsForum qualifies the attribution and separates FamousSparrow from Salt Typhoon. Attribution clarification WindowsForum
2026-09-22 Mallory.ai consolidates the technical profile of SparroWocky with capabilities and persistence. Technical normalization Mallory.ai
SparroWocky Timeline2025Firstobservationsin LATAMAug 2025ESET identifiesSparroWocky ingovernments2025-202690% of targetsin Latin America03 Sep 2026Mirage publishescases in Braziland Mexico17 Sep 2026ESETconfirmsreplacementofSparrowDoor
SparroWocky Timeline in LATAM — Verified milestones of the campaign, from August 2025 to September 2026.

Attack chain and TTPs

SparroWocky is built to arrive through DLL sideloading and stay in memory. The sequence described by Cloud Security Alliance and Mallory.ai combines a legitimate executable, a malicious patched DLL, and an RC4-encrypted .dat file that holds both configuration and payload. The loader reads that file, decrypts both components, and executes them reflectively, without writing the backdoor to disk.

That mechanism has two practical effects. First, it reduces forensic footprint, because the main sample lives in memory and does not necessarily appear as a recoverable binary in the file system. Second, it gives operators flexibility, since configuration, modules, or parameters can change without rebuilding the entire chain. HackRead adds that the PE payload may load with its MZ and PE headers removed, which makes memory scanning harder.

Persistence is implemented in two ways, depending on the configuration observed. The implant can create a Windows service or a Run key in the registry. That dual path lets operators adapt to host controls and to the level of stealth they want. In monitored environments, finding these keys alongside unusual DLL paths can be more useful than looking only for the backdoor binary.

The functional set is wide. ESET, Infosecurity Magazine, The Hacker News, Cyware, and Mallory.ai agree that SparroWocky can run commands, launch files, interact with a shell, exfiltrate files, list disks, folders, files, screens, and user sessions, take periodic screenshots, and act as a TCP proxy. It also includes reverse port forwarding and a self-destruction mechanism. In capability terms, this is not a minimal implant but a full remote operations platform.

Visual surveillance deserves its own note. BleepingComputer documented that the malware takes screenshots every 500 milliseconds and, after the first full image, sends only the changed regions. That optimization reduces bandwidth use and lowers network noise. For defenders, the result is a quieter espionage session than a simple raw screenshot dump.

SparroWocky also borrows code and techniques from existing projects. Several sources point to Mbed TLS for encrypted communications, MinHook for API hooking, and evasions associated with SilentMoonwalk and call-stack spoofing. CyberInsider and Offseq Radar add that the backdoor integrates Beacon Object Files and loads modules associated with Cobalt Strike, Metasploit, Sliver, and Brute Ratel. That suggests a modular attack chain, with offensive tooling reuse and a fairly mature integration layer.

TTPs observed in SparroWocky

TTP Description Source
DLL sideloading Side-loading with a legitimate executable, malicious DLL, and payload in .dat CSA, Mallory.ai, Cyware
Reflective loading Payload is decrypted and mapped in memory without being written to disk CSA, CyberInsider
RC4 Encryption of the .dat file and exfiltrated information CSA, Allatra Media, WBOC
Mbed TLS TLS channel for C2 and secure transport Aviatrix, Cyware, Allatra Media
MinHook Windows API hooking Allatra Media, Cyware
SilentMoonwalk Evasion through call-stack spoofing Offseq Radar, Cyware
BOF In-memory execution of Beacon Object Files CSA, CyberInsider
Persistence Windows service or Run key Allatra Media, HackRead, CyberInsider, Mallory.ai
Screenshot capture Periodic screenshots with differential change transmission BleepingComputer, Infosecurity Magazine
Exfiltration Collection and theft of host files and data SecNews, Infosecurity Magazine, Cyware
Load chainExecutableLegitimateDLLPatchedmalicious.dat fileRC4 config+ payloadMemoryReflective payloadfileless
SparroWocky load chain — Technical sequence of DLL sideloading, RC4 decryption, and in-memory execution.

Regional impact

Regional overview

The geographic impact is clear. The SparroWocky campaign concentrates on Latin American governments and places the region at the center of ESET’s observed telemetry. The material does not show a uniform spread, but a pattern dominated by public-sector entities and a persistent timeline extending from at least August 2025 through September 2026.

The country list appears repeatedly across multiple outlets and matches ESET’s publication: Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. That repetition gives the fact set more weight. It also supports an operational reading: this is not a mass opportunistic campaign, but a sustained effort to access specific government networks.

One methodological point should be stated clearly. WindowsForum notes that ESET’s public report does not name specific agencies or the number of compromised endpoints. So the evidence confirms targeting and malware deployment, but not broad compromises across every government. That distinction between observed targets and the actual scope of the incident matters for any internal assessment.

Argentina

Argentina appears consistently in the list of victims observed by ESET and in coverage from Infosecurity Magazine, The Register, BleepingComputer, Dark Reading, TechRadar Pro, and other secondary outlets. The pattern is the same as in the rest of the region, with focus on government entities and use of the SparroWocky backdoor for sustained access.

Cyware and WindowsForum reinforce that point by including Argentina among the Latin American governments affected by the campaign while also warning that the public attribution remains FamousSparrow, not an automatic merge with Salt Typhoon. For an Argentine defense team, the useful takeaway is twofold: the implant’s presence is plausible, and attribution needs to remain precise.

Peru

Peru appears repeatedly in the material as one of the countries observed by ESET. The Manila Times, The Record, BleepingComputer, Infosecurity Magazine, TechRadar Pro, CyberInsider, WBOC, and Offseq Radar all include it among the governmental targets of SparroWocky. That indicates the campaign was neither marginal nor isolated in the country, but part of the same regional intrusion series.

The repeated mention of Peru in technical and general-interest outlets also suggests continuity over time. The Record places the tracking back to at least August 2025, while TechRadar Pro describes activity between mid-2025 and 2026. From a defensive standpoint, that means the campaign should be treated as prolonged, not as a one-off event.

Mexico

Mexico does not appear in ESET’s telemetry on SparroWocky, and WindowsForum and the Spanish version of WeLiveSecurity state that explicitly. However, Mirage Security documents a separate cluster with a Mexico focus, CL-CRI-1131, which uses living-off-the-land techniques, exfiltration tools, and an infrastructure exposing NextChat, an AI chatbot used to debug and generate scripts.

That case should not be confused with FamousSparrow. The material does not attribute CL-CRI-1131 to that group or to the SparroWocky backdoor. Its value is that it shows a second line of pressure on the region, different from the government espionage campaign but still relevant to Mexico because of the use of native scripts and the accidental exposure of offensive infrastructure.

Brazil

Brazil appears in the material through Mirage Security’s study of a multistage campaign against banks and other financial entities. There the attackers used phishing attachments disguised as résumés, downloaded and executed tunneling tools and remote access malware, and operated in a separate cluster with no public attribution to a specific state actor.

That case is useful as a contrast. While SparroWocky is aimed at Latin American governments, the Brazilian cluster targets the financial sector. Looking at both cases together shows that the region is being hit by campaigns with different goals, vectors, and levels of maturity, which means controls need to be segmented rather than treating every regional intrusion as the same pattern.

United States, Puerto Rico

Puerto Rico appears in ESET’s target list as a territory of the United States. In the available material, the interest in Puerto Rico is not presented as a separate campaign, but as part of the same set of government intrusions across Latin America. That inclusion matters because it extends the geographic impact beyond South and Central America.

The rest of the United States does not appear in the published telemetry for SparroWocky. Puerto Rico’s presence does not change the regional character of the case, but it does show that the espionage reach is not limited to sovereign states on the continent. It also explains why some English-language coverage mixes Latin America with U.S. territories when describing the case.

Countries without specific verifiable coverage

No additional verifiable facts were identified for Chile, Paraguay, Bolivia, Colombia, or Uruguay in the material provided.

Regional coverageCountries and territories observed in telemetry and verified coverageArgentinaEcuadorGuatemalaHondurasPanamaPeruPuerto Rico
Regional victim coverage — Latin American countries and territories observed in the campaign.

Technical indicators

The material does not include hashes, IPs, domains, or directly reusable full IOC filenames for the backdoor. It does, however, provide DLL and component names observed in the loading chain, which can serve as partial indicators in environments where they are not expected legitimately.

Type Value Source
DLL winfsp-x64.dll CyberInsider
DLL DukeQt.dll CyberInsider
Technique DLL sideloading CSA, Cyware, Mallory.ai
Technique RC4 in .dat file CSA, Allatra Media, WBOC
Technique MinHook Allatra Media, Cyware
Technique Mbed TLS Aviatrix, Cyware, Allatra Media

Guidance for security teams

Operational priority should be the loading chain and persistence, not just the final payload. In this case the main sample lives in memory and relies on sideloading, so detection should focus on unusual relationships between legitimate executables, patched DLLs, and RC4-encrypted .dat files. If a workstation exposes winfsp-x64.dll or DukeQt.dll out of context, the full execution path and process tree should be reviewed.

On Windows endpoints, monitoring for new services and suspicious Run keys is especially useful. Persistence can take either form, depending on how the implant is configured. Teams should also look for hooking and anti-analysis signals, because MinHook, call-stack spoofing, and SilentMoonwalk-derived techniques appear consistently in the published analyses.

The network also leaves traces. Mbed TLS means traffic may look like legitimate TLS, but that does not remove the need to review destination patterns, beaconing intervals, exfiltration volume, and screenshot behavior. BleepingComputer’s note about differential screenshots every 500 milliseconds is useful for spotting short, repetitive bursts even when each event is small.

Behavior-based detection can be complemented with rules for BOF and COFF loaders, because SparroWocky executes offensive modules in memory. That broadens alerting to code associated with frameworks such as Cobalt Strike, Sliver, Brute Ratel, and Metasploit. Not every BOF use is malicious, but in government or financial environments in the region it deserves closer review.

For prioritization, the logical order is this: 1) look for evidence of sideloading and anomalous DLLs, 2) verify persistence through services or Run keys, 3) review TLS traffic and unusual screen changes, 4) check for RC4 payload decryption or memory mapping, 5) correlate with institutional targets in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. In government networks, any indicator in this set should be treated as espionage rather than an isolated event.

Frequently asked questions

What changed between SparrowDoor and SparroWocky in the FamousSparrow campaign?

SparroWocky replaced SparrowDoor as the group’s main implant and expanded operational capability with a modular C++ architecture, reflective loading, anti-analysis, and in-memory BOF execution. The practical difference is that the new backdoor leaves less disk evidence and offers more commands, as detailed in Attack chain and TTPs and Context and background.

Should the campaign observed by ESET be attributed to Salt Typhoon or FamousSparrow?

ESET’s public attribution is FamousSparrow, not Salt Typhoon. Some outlets used both names, but WindowsForum and WeLiveSecurity say there are no technical indicators strong enough to merge them into one operation. That nuance is explained in Executive summary, Context and background, and the Regional impact section.

Which countries appear with verifiable evidence in this regional operation?

The consolidated evidence mentions Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The material also includes a separate Mirage Security case in Mexico and another campaign in Brazil, but does not link them to SparroWocky. The full list is in the Key facts table and Regional impact.

What specific capabilities does SparroWocky give operators?

The backdoor runs commands and files, works as a TCP proxy, exfiltrates data, captures screens, collects host and network information, lists disks, folders, and sessions, and can remove itself from the system. It also executes Beacon Object Files in memory. That technical detail is covered in Attack chain and TTPs and Technical indicators.

What signals should security teams look for first?

First, look for DLL sideloading, new services or suspicious Run keys, and legitimate binaries loading anomalous DLLs. Then review TLS traffic, periodic screenshots, RC4 activity in memory, and the presence of winfsp-x64.dll or DukeQt.dll outside their normal context. The prioritization is in Guidance for security teams.

Do the Mexico and Brazil campaigns belong to the same actor as SparroWocky?

The available material does not support that conclusion. Mirage Security documents a Mexico-focused cluster with NextChat and a Brazil campaign against banks, but does not publicly attribute either one to FamousSparrow or SparroWocky. The overlap and the distinction are explained in Context and background and Regional impact.

Material limitations

The material does not include hashes, domains, IP addresses, or other full IOCs for a closed detection list. It also does not identify specific government agencies, the number of affected endpoints, or an exact infection timeline by country. The public telemetry summarizes regional scope, but not a country-by-country victim inventory.

In addition, Mirage Security’s campaigns in Mexico and Brazil appear as independent operations and are not publicly attributed to the same actor as SparroWocky. They are used here only as regional context, not as an extension of the FamousSparrow campaign. The confusion between FamousSparrow and Salt Typhoon also means the attribution reported by ESET should be kept exact.

TTP MatrixTechniqueUseImpactDLL sideloadingInitial loadEvasion and accessRC4 + .datConfiguration and payloadFileless loadingMbed TLS, MinHookEncrypted C2 and hookingAnti-analysisBOF and Cobalt StrikeIn-memory modulesGreater flexibility
SparroWocky TTPs — Observed capabilities and techniques in the malware family.

Sources

View all