CiberLATAMbywhalemate

Peru Named in FamousSparrow Campaign

ESET linked FamousSparrow to a campaign using the new SparroWocky backdoor. CYFIRMA said Peru is among the targets.

Whalemate Labs · AI-assisted researchPublished:2 min read

ESET attributed a cyberespionage campaign to FamousSparrow that introduced SparroWocky, a modular C++ backdoor, and said the malware has replaced SparrowDoor in recent operations by the group. CYFIRMA said Peru is among the countries targeted and detailed techniques such as DLL sideloading, reflective execution and file exfiltration.

ESET attributed a cyberespionage campaign to FamousSparrow that introduced SparroWocky, a modular backdoor written in C++, and said the malware has replaced SparrowDoor in the group’s recent operations. The research also says the attribution is highly confident because, in some of the earliest attacks, the new tool was deployed alongside SparrowDoor, which is exclusive to FamousSparrow.

What did ESET find about SparroWocky?

ESET described SparroWocky as a modular backdoor developed in C++ and confirmed that it has taken SparrowDoor’s place in recent FamousSparrow campaigns. The Hacker News also identified it as a previously unreported backdoor and cited researchers Alexandre Côté Cyr and Romain Dumont, who characterized it in the same technical terms.

ESET’s report, published by WeLiveSecurity, places this development within an expansion of the group’s operations in Latin America. Along the same lines, Alam Rakamy, citing ESET Research, said the campaign and the tool are linked with high confidence to FamousSparrow because of the initial coexistence with SparrowDoor.

What regional scope was reported?

CYFIRMA said Peru is among the countries targeted in its Weekly Intelligence Report for Oct. 1, 2026. The report adds that SparroWocky uses DLL sideloading and reflective in-memory execution, along with capabilities to run commands, take screenshots and exfiltrate files.

The mention of Peru adds to the regional focus ESET described for FamousSparrow activity in Latin America. However, the available material does not identify specific Peruvian institutions or confirm the exfiltration of classified information.

What can be said about attribution?

Public attribution points to FamousSparrow, with alignment to China, according to the analysis cited by ESET and reproduced by outlets such as Infobae Perú. That attribution is based, according to the research itself, on the early presence of SparroWocky alongside SparrowDoor, a tool associated with the group.

For now, the material provided shows that Peru appears within the campaign’s observed scope and that the main focus was government entities. The sources provided do not mention specific Peruvian targets or an official confirmation of impact on national systems.

Sources

View all