CiberLATAMbywhalemate

FamousSparrow targets Latin American governments

ESET linked FamousSparrow to SparroWocky campaigns against public agencies in Argentina, Ecuador, Guatemala and other countries.

Whalemate Labs · AI-assisted researchPublished:4 min read

ESET Research found that the Chinese APT FamousSparrow has used a new backdoor, SparroWocky, since at least August 2025 against government agencies and other high-value entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela. The firm's telemetry shows that since mid-2025, 90% of the group's observed targets were in Latin America.

ESET Research found that the Chinese APT FamousSparrow has used a new backdoor, SparroWocky, since at least August 2025 against government agencies and other high-value entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela. The company’s telemetry shows that since mid-2025, 90% of the group’s observed targets were in Latin America.

What changed in FamousSparrow's operation?

FamousSparrow replaced SparrowDoor with SparroWocky as its main tool, according to the technical analysis published on the case. The new backdoor is written in C++ and supports remote command execution, file exfiltration and dynamic module updates, which makes it better suited for long-term espionage.

Specialized outlets that covered ESET’s report added that SparroWocky includes persistence mechanisms in Windows and can abuse legitimate system services to reduce its visible footprint. That combination makes detection and response harder for the public entities under attack.

Who is the campaign aimed at?

The campaign focused on Latin American government agencies, although at least one telecommunications organization in Puerto Rico also appears among the victims. ESET and other technical outlets said the regional shift began in July 2025 and became almost entirely focused on Latin America by mid-year.

DarkReading and BankInfoSecurity linked that shift to entities that manage or oversee Chinese investments under increased political scrutiny from the United States. According to those reports, the campaign appears to have been designed to observe how Latin American governments would react to Washington’s deeper involvement in the region.

How clear is the attribution?

The main attribution points to FamousSparrow, not to other Chinese groups such as Salt Typhoon. That correction appeared in later coverage that revisited ESET’s analysis, helping clear up an initial mix-up about the origin of the implant.

The technical sources following the case say this is a single APT with a history of operations in other regions. Based on the material available, there is no stronger alternative attribution for the campaign observed in Latin America.

What other campaigns are hitting the region?

In parallel, Fortinet identified a Casbaneiro campaign targeting users at financial institutions in Argentina, Peru, Colombia and Mexico. The operation uses emails with invoice or legal notice lures, links to malicious PDFs, and components detected as PDF/Phishing.5BB0!tr, JS/Phishing.IBP!tr and W32/Casbaneiro.EN!tr.spy.

Fortinet also reported infrastructure with IP-based geofencing and distributed C2 servers. Independent coverage said the infection flow begins with an email attaching or linking to a supposed PDF about an unpaid invoice or a legal proceeding, then redirects the user to a site that downloads the banking trojan.

WorldCyberNews also said the campaign combines localized social engineering, including references to legal procedures and banking terms specific to each country, to steal online banking credentials and data. In that case, the objective is clearly criminal and focused on Latin America's financial ecosystem.

What happened in Mexico?

Proofpoint observed mass email campaigns in Mexico during July and August 2026, aimed at stealing credentials, installing malware and gaining unauthorized access. The lures included business and government communications, tax invoices, court summonses and other fake documents.

A regional report that picked up the alert said roughly 275,000 malicious emails circulated between July 19 and July 24, 2026, targeting Mexico. That same report said the actor TA2725 was mainly trying to capture credentials and gain initial access to corporate and government networks, rather than deploy ransomware.

Simalco added that the campaign used routine business communications, digital service notices and everyday paperwork to raise click rates among employees and users with less cybersecurity training. The pattern matches a regional trend that prioritizes access and data theft over extortion through encryption.

Sources

View all