By Interestana AI Editorial — AI-drafted, human-overseen. How we report
FamousSparrow Deploys SparroWocky Backdoor in Latin America

The China-aligned state-sponsored threat actor identified as FamousSparrow has been actively deploying a newly discovered backdoor, named SparroWocky, in cyberattacks targeting multiple nations across Latin America. ESET security researchers Alexandre Côté Cyr and Romain Dumont detailed these findings in a technical report shared with The Hacker News, indicating that these operations have been ongoing since at least August 2025. SparroWocky is characterized as a modular backdoor, developed using the C++ programming language, which allows for flexibility and adaptability in its malicious functions. The deployment of this sophisticated tool suggests a persistent and evolving threat landscape in the region, with potential implications for national security and critical infrastructure. The specific countries targeted within Latin America were not explicitly detailed in the initial report, but the scope of the attacks implies a broad strategic interest by the threat actor. The nature of state-sponsored attacks often involves espionage, data theft, or disruption of services, and the use of a custom-built backdoor like SparroWocky facilitates these objectives by providing covert access and control over compromised systems. The modular design of SparroWocky is a significant feature, enabling attackers to load specific modules or functionalities as needed, thereby evading detection and adapting to different target environments. This approach is common among advanced persistent threat (APT) groups, which continuously refine their tools and tactics to maintain access and achieve their long-term objectives. ESET's analysis of SparroWocky likely involved reverse engineering the malware to understand its capabilities, communication protocols, and potential indicators of compromise (IOCs). Such detailed technical analysis is crucial for cybersecurity defenders to develop effective countermeasures and threat intelligence. The attribution of these attacks to FamousSparrow, a group associated with Chinese state interests, aligns with broader geopolitical trends and cyber espionage activities observed globally. The group's focus on Latin America could be driven by various factors, including economic interests, political influence, or intelligence gathering on regional governments and industries. The ongoing nature of these attacks, spanning over a year since August 2025, underscores the challenge of attribution and mitigation in the face of persistent and well-resourced adversaries. The report's release serves as a critical alert to organizations and governments in Latin America to enhance their cybersecurity postures, implement robust detection mechanisms, and prepare for potential follow-on attacks. The specific functionalities of the SparroWocky backdoor, beyond its C++ implementation and modularity, would likely include capabilities such as remote command execution, file system manipulation, data exfiltration, and potentially the deployment of further malicious payloads. The continued monitoring of FamousSparrow's activities and the evolution of the SparroWocky malware will be essential for the cybersecurity community to stay ahead of this significant threat.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.