Find notable cyber news and cases, enriched with sources, timelines, and signals.

FamousSparrow SparroWocky Latin America government espionage campaign

Campaign
First reported
Last updated
Happening score
H score 32
2 unique sources, 2 articles

Summary

Hide ▲

FamousSparrow has been using the SparroWocky backdoor against government organizations in Latin America since at least August 2025. ESET Research attributed the activity with high confidence and identified government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The group gained access by exploiting publicly reachable Exchange servers, and the malware can run commands, execute files, act as a TCP proxy, collect host and network details, exfiltrate files, and take screenshots. ESET said SparroWocky is a separate family from SparrowDoor, with DLL side-loading, RC4-encrypted exfiltration, and anti-analysis features used to evade detection.

Related Happenings

FamousSparrow SparroWocky backdoor activity against Latin American governments

Malware Activity
H score23 First: 17.09.2026 12:00 Last: 17.09.2026 12:00 Sources 1

How related: The threat actor known as FamousSparrow has replaced its long-running SparrowDoor implant with a new backdoor called SparroWocky, and has been deploying it against governments across Latin America since at least August 2025.

About this happening: FamousSparrow is using the new SparroWocky backdoor against government entities across Latin America, with activity observed since at least August 2025 and a broad...

FishMonger multi-country government espionage campaign

Campaign
H score33 First: 16.06.2026 17:30 Last: 16.06.2026 17:30 Sources 1

About this happening: FishMonger ran a multi-country espionage campaign against government bodies in Honduras, Taiwan, Thailand and Pakistan across 2023 and 2024. The activity point...

Earth Lusca Operation FishMedley espionage campaign

Campaign
H score38 First: 16.06.2026 12:44 Last: 16.06.2026 12:44 Sources 1

About this happening: A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...

FamousSparrow Middle East maritime and energy targeting campaign

Campaign
H score33 First: 29.05.2026 12:00 Last: 29.05.2026 12:00 Sources 1

About this happening: China-aligned FamousSparrow escalated a maritime and energy espionage campaign across the Middle East, putting regional shipping and infrastructure intelligence at gre...

Webworm multi-country targeting campaign against government and enterprise victims

Campaign
H score38 First: 20.05.2026 15:51 Last: 20.05.2026 15:51 Sources 1

About this happening: Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...

Timeline

  1. 17.09.2026 12:00 3 articles · 4d ago

    FamousSparrow deploys SparroWocky against government organizations in Latin America

    Initial Disclosure

    FamousSparrow is using the SparroWocky backdoor in espionage operations against government organizations in Latin America, replacing the earlier SparrowDoor tooling. ESET says the campaign has been active for more than a year, with targeting observed in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela, and researchers identified at least 18 command-and-control addresses communicating with the malware over port 443 or 8080, or through HTTP and SOCKS5 proxies. ESET also described SparroWocky as a modular C++ backdoor delivered through DLL side-loading after RC4-decrypted payload loading, with anti-analysis and persistence features used to evade security products.

    Show sources