New SparroWocky Backdoor Targets Latin America
Active since at least August 2025, the malware represents a functional pivot from the threat actor's existing SparrowDoor backdoor.

Active since at least August 2025, the malware represents a functional pivot from the threat actor's existing SparrowDoor backdoor.
September 16, 2026 | 3 min read

Researchers have uncovered a new modular C++ backdoor called SparroWocky that is deployed by the China-aligned APT group FamousSparrow in a broad cyberespionage campaign primarily targeting governmental entities in Latin America.
Active since at least August 2025, the malware represents a functional pivot from the threat actor's existing SparrowDoor backdoor, and includes heightened evasion mechanisms, memory manipulation, and direct integration with open-source offensive software.
Technical Architecture and Anti-Analysis Mechanisms
Architecturally, SparroWocky shows that the attackers behind it have sophisticated knowledge of Windows internals and low-level memory operations. To bypass endpoint security controls and hinder reverse-engineering efforts, the backdoor directly manipulates internal memory structures and patches code at runtime. A notable shift in FamousSparrow’s development approach is the embedded integration of open-source projects into the custom malware base itself, rather than deploying utilities alongside the payload. Furthermore, SparroWocky includes native support for loading and executing Beacon Object Files (BOFs), permitting operators to seamlessly execute red-teaming modules in memory.
“SparroWocky is a full-featured, modular C++ backdoor built with modularity and stealthiness in mind. It appeared shortly after FamousSparrow started focusing on Latin America and quickly became the group’s new flagship implant, replacing SparrowDoor. It should be noted that SparroWocky is not a variant of SparrowDoor, but is rather a distinct malware family. The transition to this new backdoor also came with a greater level of integration of open-source tooling into FamousSparrow’s workflow: while previously, standalone versions of these tools were deployed side by side with SparrowDoor, with SparroWocky, some have been incorporated directly into the Malware,” ESET researchers said in their analysis.
Core Capabilities and Command Functionality
SparroWocky provides remote management, reconnaissance, and proxying functionalities. Its feature set includes launching arbitrary executables, establishing TCP proxies, executing shell commands, taking periodic desktop screenshots, and harvesting host files. Upon initial execution, the backdoor profiles the compromised machine by collecting the computer name, active username, domain, Windows version, and IP configurations across all network interfaces. Depending on system configuration and privileges, persistence is established via a custom Windows service or a registry Run key. Exfiltrated host intelligence and files are encrypted using the RC4 stream cipher and transmitted over TLS-encrypted communications channels.
“FamousSparrow is a China-aligned cyberespionage group believed to have been active since at least 2019. We first publicly documented the group in a blogpost from September 2021 when we observed it exploiting the ProxyLogon vulnerability. The group was initially known for targeting hotels around the world but has also targeted governments, international organizations, trade groups, engineering companies, and law firms. FamousSparrow is the only known user of the SparrowDoor backdoor,” the ESET researchers said.
“Based on our investigation, we attribute the latest campaign and the SparroWocky backdoor to FamousSparrow with high confidence, since in some of the first attacks involving this backdoor, SparroWocky was deployed by the FamousSparrow-exclusive SparrowDoor. Moreover, not only does the victimology match FamousSparrow’s previous targeting, we have also recorded attempts to deploy SparroWocky at many of the same organizations that had previously been targeted with SparrowDoor.”
Telemetry gathered from mid-2025 into 2026 shows that 90 percent of FamousSparrow’s observed targets were located in Latin America, focusing heavily on governmental institutions in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.
ESET researchers assess that this targeting aligns with intelligence-gathering operations designed to monitor regional governmental reactions to geopolitical shifts and commercial disputes. Attribution to FamousSparrow is made with high confidence, confirmed by overlapping infrastructure, historic victimology, and instances where SparroWocky was dropped directly by SparrowDoor on previously compromised networks.
September 16, 2026 | 3 min read
Dennis Fisher is an award-winning journalist and author. He is one of the co-founders of Decipher and Threatpost and has been writing about cybersecurity since 2000. Dennis enjoys finding the stories behind the headlines and digging into the motivations and thinking of both defenders and attackers. He is the author of 2.5 novels and once met Shaq. Contact: dennis at decipher.sc.