Chinese APT Deploys 'SparroWocky' Backdoor Against Latin American Governments
A new backdoor dubbed 'SparroWocky' is being used by alleged Chinese state-sponsored hackers to infiltrate government agencies across Latin America. Cybersecurity researchers at **ESET** have been tracking the campaign, attributing it to the long-running **FamousSparrow** operation, which targets critical infrastructure and political entities.
Alleged Chinese state-sponsored hackers are actively breaching government agencies across Latin America using a novel backdoor identified by researchers as β**SparroWocky**.β
**ESET** researcher **Alexandre CΓ΄tΓ© Cyr** has been monitoring this campaign since at least August 2025, observing attacks on government departments in Guatemala, Honduras, Puerto Rico, Panama, Venezuela, Peru, and Argentina.
CΓ΄tΓ© Cyr noted the campaign's regional focus as a βrare occurrenceβ for Chinese government-backed operations, which typically target multiple regions when sustained over such a long period.
In a comprehensive report, **ESET** theorized that Chinaβs concentrated focus on Latin America is linked to the renewed emphasis on the region by U.S. President **Donald Trump** since taking office. His administration has directly challenged long-term Chinese investments in the area.
**ESET** suggests the campaign, attributed to the established Chinese operation known as **FamousSparrow**, is likely βintended to help China better monitor and anticipate the reaction of local governments to current U.S. pressures.β
One of the organizations targeted in Panama is directly involved in an ongoing commercial dispute concerning two major ports in the canal area. President Trump has previously expressed concerns about Chinese companies operating these ports and has sought to disrupt Beijingβs alleged control over parts of the canal.
## Understanding 'SparroWocky'
**ESET** named the malware **SparroWocky** because early samples of the backdoor incorporated the opening stanza of βJabberwocky,β a poem by English author **Lewis Carroll**.
This backdoor is engineered to impede analysis and demonstrates the group's profound understanding of internal **Windows** systems. The malware reportedly integrates code from various open-source projects.
**SparroWocky** enables attackers to exfiltrate files, capture screenshots, and collect extensive information about compromised systems, including IP addresses and usernames.
## The FamousSparrow Threat Group
**FamousSparrow** has been operational since at least 2019, conducting Chinese cyberespionage campaigns across multiple regions by exploiting various vulnerabilities. Initially, the group targeted hotels but has since evolved to breach governments, trade groups, international organizations, and law firms.
**ESET** has publicly linked **FamousSparrow** to **Salt Typhoon**, another Chinese group that U.S. law enforcement agencies have accused of breaching the **Treasury Department**, several large U.S. telecoms, and an email platform utilized by Congressional staffers.
