Summary
ESET researchers have published technical analysis attributing a sustained espionage campaign targeting Latin American government organizations to FamousSparrow, a China-aligned state-sponsored threat actor. The campaign, active since at least August 2025, deploys SparroWocky — a previously undocumented modular C++ backdoor that replaces the group’s earlier SparrowDoor implant. Approximately 90% of FamousSparrow’s observed targeting from mid-2025 into 2026 has been concentrated in Latin America, with affected organizations identified in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. ESET assesses the campaign’s objective as collecting intelligence on Latin American governments’ responses to increasing U.S. pressure on Chinese economic interests.
Timeline
| Date | Event |
|---|---|
| August 2025 | SparroWocky backdoor first observed in attacks against Latin American government entities; ESET telemetry records targeting across eight countries |
| Mid-2025 to 2026 | FamousSparrow shifts approximately 90% of observed targeting to Latin America; SparroWocky replaces SparrowDoor as primary implant |
| Sep 17, 2026 | ESET publishes full technical attribution report including indicators of compromise and complete SparroWocky capability analysis |
What Happened
SparroWocky is a modular, full-featured C++ backdoor that incorporates code from open-source projects alongside custom development. The implant is delivered via DLL side-loading: a loader decrypts an RC4-encoded payload stored in a .dat file and maps it directly into memory to evade static analysis and file-based detection. Anti-analysis mechanisms include manipulation of low-level memory structures, runtime code patching, thread creation interception disguising malicious threads as legitimate Windows functions using MinHook, call stack spoofing, and dynamic API resolution.
Once established, SparroWocky provides operators with a comprehensive remote access capability including executing commands and arbitrary files, loading and executing Beacon Object Files in memory, complete system and user enumeration, full file system operations, screenshot capture at 500-millisecond intervals transmitting only changed screen regions, process creation in other logged-in user sessions, TCP proxy operation, and self-deletion on command. ESET identified two persistence mechanisms: a Windows service named ProcAuditManager and a registry key named SnapCart. Command-and-control traffic runs over ports 443 and 8080 or via HTTP/SOCKS5 proxies.
Domain Intelligence
eset.com — 62.32
eset.com scores in the low-trust range at 62.32. ESET is the security research organization that discovered, analyzed, and attributed the SparroWocky campaign. One threat intelligence source has flagged eset.com but the observation has not been independently corroborated.
The Trust Observatory · thetrustobservatory.com · September 18, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026