Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

FamousSparrow uses SparroWocky backdoor in Latin American government attacks

The China-linked espionage group FamousSparrow has used a new backdoor, SparroWocky, in attacks on government organizations in Latin America for more than a year, according to ESET researchers.

ESET observed the malware targeting organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The researchers believe the activity aimed to collect intelligence about Latin American governments’ responses to increasing U.S. pressure on Chinese economic interests. SparroWocky has replaced the group’s previously used SparrowDoor backdoor.

ESET describes SparroWocky as a modular C++ backdoor that includes code from open-source projects. It uses anti-analysis techniques, including changes to low-level memory structures and runtime code patching. The malware is deployed through DLL side-loading after a loader decrypts an RC4-encoded payload in a .dat file and maps it directly into memory.

Its evasion methods include call-stack and threat-origin spoofing, dynamic API resolution, and disguising malicious in-memory code and DLLs as legitimate Windows components. Using the MinHook library, SparroWocky hooks CreateThread so new threads appear to security products to start at AnimateWindow.

The backdoor maintains persistence through the ProcAuditManager Windows service or a SnapCart registry key under HKLM or HKCU, depending on available privileges. ESET found at least 18 C2 addresses communicating over port 443 or 8080, or through HTTP and SOCKS5 proxies. ESET telemetry indicates that since mid-2025, FamousSparrow has focused primarily on Latin America.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.