Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Salt Typhoon targets Latin America with SparroWocky backdoor

Cybersecurity researchers at ESET say the Chinese state-sponsored group Salt Typhoon has focused on Latin America from mid-2025 into 2026, targeting Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela. ESET has tracked the group for years; it has previously been linked to intrusions at telecommunications companies and government agencies in Western countries since at least 2019.

In the Latin American activity, researchers observed a newly developed backdoor called SparroWocky. ESET says it includes around 30 commands for functions including system profiling, file exfiltration and screenshot capture. Around 90% of Salt Typhoon’s recent activity was devoted to the region, according to the researchers.

ESET describes the discovery of China-built malware in Latin America as a rare occurrence. The group, which ESET calls FamousSparrow, is suspected of trying to help China monitor and anticipate local governments’ responses to current US pressure, the researchers said. ESET linked that pressure to Donald Trump’s renewed interest in the continent and his second presidential term, while noting China’s long-term investments in energy, mining and telecommunications.

The backdoor is delivered through a trident loader scheme with a legitimate executable, a malicious DLL and a file containing encrypted malware. ESET says DLL side-loading can allow deployment without detection.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.