China-Aligned FamousSparrow Deploys New SparroWocky Backdoor in Latin America
ESET researchers uncover modular C++ backdoor used in attacks since August 2025

Key Takeaways
- FamousSparrow, a China-aligned threat actor, is deploying a new modular C++ backdoor named SparroWocky in Latin America since August 2025.
- SparroWocky is a sophisticated backdoor that allows remote control and potential data theft, with modular capabilities for extended espionage.
- ESET researchers reported the findings, but specific victims, infection vectors, and full technical details are not yet public.
- Organizations should hunt for indicators of compromise and apply general hardening measures, as no specific patch is available for this custom malware.
Quick answers
- What happened?
- The China-aligned state-sponsored threat actor FamousSparrow has been observed deploying a previously unreported modular C++ backdoor named SparroWocky in attacks targeting multiple Latin American countries since at least August 2025. ESET researchers reported the findings, highlighting the actor's continued focus on espionage in the region.
- What should defenders do?
- Organizations should monitor for suspicious C++ binaries, review network traffic for unusual outbound connections, and apply general hardening. Since no patch exists, focus on detection and response. Use threat intelligence feeds for indicators of compromise and consider enhanced monitoring for lateral movement.
Security researchers at ESET have identified a new backdoor, dubbed SparroWocky, deployed by the China-aligned threat actor FamousSparrow in attacks against multiple countries in Latin America. The activity has been ongoing since at least August 2025, according to a technical report by ESET researchers Alexandre Côté Cyr and Romain Dumont.
SparroWocky is described as a modular, C++ backdoor, indicating a sophisticated toolset designed for stealth and flexibility. The backdoor's modular nature suggests it can be extended with additional components to suit specific espionage objectives, such as data exfiltration, keylogging, or lateral movement.
FamousSparrow is a known state-sponsored group with a history of targeting government entities, diplomatic missions, and international organizations. The new campaign in Latin America underscores the group's persistent interest in the region, likely for geopolitical intelligence gathering.
While the exact infection vector remains undisclosed, such campaigns typically leverage exploitation of public-facing applications or spear-phishing to gain initial access. Once deployed, SparroWocky could provide attackers with full remote control of compromised systems, enabling data theft and further network compromise.
The report does not specify the number of victims or the exact countries affected, but the regional focus suggests a coordinated espionage effort. ESET's findings highlight the evolving capabilities of state-sponsored actors and the need for heightened vigilance among organizations in Latin America and beyond.
Organizations should treat this as a serious threat and review their security posture, particularly if they operate in sectors commonly targeted by Chinese state-sponsored groups, such as government, telecommunications, or critical infrastructure.
Security Details
SparroWocky is a modular C++ backdoor used by FamousSparrow in attacks against Latin American targets. It provides remote control and data theft capabilities. The infection vector is not disclosed, but likely involves exploitation of public-facing apps or spear-phishing. No CVE or specific exploit is mentioned.
Mitigation
Organizations should monitor for suspicious C++ binaries, review network traffic for unusual outbound connections, and apply general hardening. Since no patch exists, focus on detection and response. Use threat intelligence feeds for indicators of compromise and consider enhanced monitoring for lateral movement.
Sources
The Hacker News
China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
Sep 17, 2026 · 10:05
Original link
Related Security News

Citrix NetScaler Zero-Days Exploited in the Wild; Agencies Urge Immediate Restriction
Cybersecurity agencies, security researchers, and IT providers are warning that two zero-day vulnerabilities in Citrix NetScaler products are being actively exploited in the wild. Exploitation was reported in late September 2026, with private and public advisories issued ahead of patches expected to be released next week. Organizations using unpatched NetScaler appliances face risks of unauthorized access, data exfiltration, and service disruption. Until patches are applied, administrators are advised to shut down or restrict NetScaler appliances.

AI Agents Introduce New Lateral Movement Vectors in Cybersecurity Landscape
A recent analysis published on The Hacker News examines how AI agents differ from deterministic applications in cybersecurity operations, raising concerns about autonomous path discovery and task completion capabilities. The report highlights that AI agents can relentlessly pursue task completion, potentially discovering and exploiting unexpected access paths that traditional least-privilege models may not address.



