TTO-2026-0918-136 · September 18, 2026 Nation-StateEspionage

China-Linked FamousSparrow Deploys SparroWocky Backdoor Against Latin American Government Entities

eset.comFamousSparrow / China-alignedSparroWocky modular C++ backdoorReplaces SparrowDoor8 countries: Argentina Ecuador Guatemala Honduras Panama Peru Puerto Rico VenezuelaESET attributionActive since August 2025

Summary

ESET researchers have published technical analysis attributing a sustained espionage campaign targeting Latin American government organizations to FamousSparrow, a China-aligned state-sponsored threat actor. The campaign, active since at least August 2025, deploys SparroWocky — a previously undocumented modular C++ backdoor that replaces the group’s earlier SparrowDoor implant. Approximately 90% of FamousSparrow’s observed targeting from mid-2025 into 2026 has been concentrated in Latin America, with affected organizations identified in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. ESET assesses the campaign’s objective as collecting intelligence on Latin American governments’ responses to increasing U.S. pressure on Chinese economic interests.

Timeline

DateEvent
August 2025SparroWocky backdoor first observed in attacks against Latin American government entities; ESET telemetry records targeting across eight countries
Mid-2025 to 2026FamousSparrow shifts approximately 90% of observed targeting to Latin America; SparroWocky replaces SparrowDoor as primary implant
Sep 17, 2026ESET publishes full technical attribution report including indicators of compromise and complete SparroWocky capability analysis

What Happened

SparroWocky is a modular, full-featured C++ backdoor that incorporates code from open-source projects alongside custom development. The implant is delivered via DLL side-loading: a loader decrypts an RC4-encoded payload stored in a .dat file and maps it directly into memory to evade static analysis and file-based detection. Anti-analysis mechanisms include manipulation of low-level memory structures, runtime code patching, thread creation interception disguising malicious threads as legitimate Windows functions using MinHook, call stack spoofing, and dynamic API resolution.

Once established, SparroWocky provides operators with a comprehensive remote access capability including executing commands and arbitrary files, loading and executing Beacon Object Files in memory, complete system and user enumeration, full file system operations, screenshot capture at 500-millisecond intervals transmitting only changed screen regions, process creation in other logged-in user sessions, TCP proxy operation, and self-deletion on command. ESET identified two persistence mechanisms: a Windows service named ProcAuditManager and a registry key named SnapCart. Command-and-control traffic runs over ports 443 and 8080 or via HTTP/SOCKS5 proxies.

Domain Intelligence

eset.com — 62.32

eset.com scores in the low-trust range at 62.32. ESET is the security research organization that discovered, analyzed, and attributed the SparroWocky campaign. One threat intelligence source has flagged eset.com but the observation has not been independently corroborated.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 18, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026