China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America

Summary

A China-aligned threat actor, FamousSparrow, has been deploying a new backdoor named SparroWocky in attacks targeting Latin American countries since August 2025. ESET researchers have identified this modular, C++ backdoor.

IFF Assessment

FOE

The discovery of a new backdoor deployed by a state-sponsored threat actor represents an increased risk and capability for malicious actors.

Defender Context

Defenders in Latin America should be aware of the new SparroWocky backdoor and the activity of the FamousSparrow threat actor. This highlights the ongoing threat of state-sponsored espionage and the need for robust endpoint detection and response capabilities to identify and mitigate new malware.

Read Full Story →