China‑Linked ‘FamousSparrow’ Deploys New SparroWocky Backdoor in Latin America Spy Campaign
Researchers say a China‑aligned group known as FamousSparrow is using a new backdoor called SparroWocky in attacks across Latin America. The malware can run commands, steal files, take screenshots and load extra modules in memory, with government entities among the victims.
A China‑aligned hacking group is upgrading its tools as it targets government and other sensitive networks across Latin America.
Cybersecurity research cited by The Hacker News links the group known as FamousSparrow to a new backdoor dubbed SparroWocky. The recent campaign includes intrusions into government entities, indicating an intelligence‑gathering focus.
Once SparroWocky is installed, operators can execute commands on the victim machine, exfiltrate files, capture screenshots and load additional plugins directly into memory. Running extra code this way leaves fewer traces on disk, making it harder for traditional antivirus systems to spot.
Shifting to a new backdoor helps FamousSparrow evade existing defenses tuned to its older tools. That gives the attackers more time inside networks to map systems and quietly collect documents.
For Latin American governments, compromise of internal email, file servers or workstations in ministries handling trade, infrastructure, security or energy can hand foreign services insight into policy debates and negotiation plans. Compromised public‑sector systems can also be used as stepping stones into private contractors’ networks.
The campaign fits a pattern of Chinese‑aligned groups focusing on regions where Beijing’s economic and political interests are growing. Access to state networks can offer early warning of regulatory changes and leverage in disputes.
The next things to watch are whether more Latin American states publicly acknowledge intrusions tied to FamousSparrow or SparroWocky, how quickly technical indicators for the malware are incorporated into national defenses, and whether the group rotates to fresh tooling now that this backdoor has been exposed.
Sources
- OSINT