FamousSparrow SparroWocky backdoor activity against Latin American governments
Malware Activity
Summary
Hide ▲
Show ▼
FamousSparrow is using the new SparroWocky backdoor against government entities across Latin America, with activity observed since at least August 2025 and a broader regional focus from mid-2025. ESET Research attributed the campaign to the China-aligned group with high confidence and named targets in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The group gained access by exploiting publicly reachable Exchange servers. SparroWocky is a separate family from SparrowDoor and can run commands, execute files, act as a TCP proxy, exfiltrate files, and take screenshots while using RC4 and TLS for transfer.
Related Happenings
FamousSparrow SparroWocky Latin America government espionage campaign
Campaign
H score32
First: 17.09.2026 12:00
Last: 17.09.2026 12:00
Sources 1
How related:
The threat actor known as FamousSparrow has replaced its long-running SparrowDoor implant with a new backdoor called SparroWocky, and has been deploying it against governments across Latin America since at least August 2025.
About this happening:
FamousSparrow has been using the SparroWocky backdoor against government organizations in Latin America since at least August 2025. ESET Research attributed th...
FamousSparrow SparroWocky Latin America government espionage campaign
CampaignHow related: The threat actor known as FamousSparrow has replaced its long-running SparrowDoor implant with a new backdoor called SparroWocky, and has been deploying it against governments across Latin America since at least August 2025.
About this happening: FamousSparrow has been using the SparroWocky backdoor against government organizations in Latin America since at least August 2025. ESET Research attributed th...
Earth Lusca Operation FishMedley espionage campaign
Campaign
H score38
First: 16.06.2026 12:44
Last: 16.06.2026 12:44
Sources 1
About this happening:
A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
Earth Lusca Operation FishMedley espionage campaign
CampaignAbout this happening: A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
Webworm multi-country targeting campaign against government and enterprise victims
Campaign
H score38
First: 20.05.2026 15:51
Last: 20.05.2026 15:51
Sources 1
About this happening:
Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...
Webworm multi-country targeting campaign against government and enterprise victims
CampaignAbout this happening: Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...
Webworm expanded European government and South Africa university espionage campaign
Campaign
H score24
First: 20.05.2026 14:30
Last: 20.05.2026 14:30
Sources 1
About this happening:
Webworm expanded its 2025 espionage campaign into European government organizations and a university in South Africa, widening the cross-region targeting risk. The ope...
Webworm expanded European government and South Africa university espionage campaign
CampaignAbout this happening: Webworm expanded its 2025 espionage campaign into European government organizations and a university in South Africa, widening the cross-region targeting risk. The ope...
GopherWhisper China-aligned APT campaign targeting Mongolian government institutions
Campaign
H score30
First: 23.04.2026 12:04
Last: 23.04.2026 12:04
Sources 1
About this happening:
The GopherWhisper campaign is a China-aligned APT operation targeting Mongolian governmental institutions, and it now appears to extend beyond a single compromise to *...
GopherWhisper China-aligned APT campaign targeting Mongolian government institutions
CampaignAbout this happening: The GopherWhisper campaign is a China-aligned APT operation targeting Mongolian governmental institutions, and it now appears to extend beyond a single compromise to *...
Timeline
-
17.09.2026 12:00 4 articles · 4d ago
FamousSparrow deploys SparroWocky against Latin American government organizations
Initial DisclosureFamousSparrow is using the new SparroWocky backdoor in espionage attacks against government organizations in Latin America, replacing the previously used SparrowDoor custom backdoor. ESET observed the malware in organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela, and said the operation has been ongoing for more than a year with Latin America as the primary focus from mid-2025. The implant is a modular C++ backdoor that uses DLL side-loading, RC4-encoded .dat payloads, persistence through a Windows service or registry key, and thread-start spoofing via the MinHook library.
Show sources
- Chinese hackers use SparroWocky malware in govt espionage attacks — www.bleepingcomputer.com — 17.09.2026 12:00
- Chinese hackers use SparroWocky malware in govt espionage attacks — www.bleepingcomputer.com — 17.09.2026 12:00
- China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America — thehackernews.com — 17.09.2026 13:05
- FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor — www.infosecurity-magazine.com — 17.09.2026 18:00