2 Remove Virus

FamousSparrow deploys new SparroWocky backdoor against Latin American governments

A China-aligned cyberespionage group has introduced a powerful new Windows backdoor in attacks concentrated on government organizations across Latin America.

 

 

The malware, named SparroWocky, has been linked to FamousSparrow, an espionage group operating since at least 2019. Researchers have observed the new tool in attacks dating back to August 2025, when it began replacing the group’s older SparrowDoor malware.

Recent victims have been identified in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela. Around 90% of FamousSparrow targets observed by researchers since mid-2025 have been located in Latin America.

Government organizations appear to be a major focus, although the group has historically targeted a wider range of victims, including international organizations, hotels, engineering companies, trade groups and law firms.

Researchers believe FamousSparrow’s increased attention to Latin America may be connected to China’s interest in political and economic developments across the region, particularly as U.S. pressure on Chinese interests has increased. That assessment reflects the observed targeting rather than confirmed information about instructions given to the attackers.

SparroWocky gives its operators extensive control over compromised Windows computers. Attackers can execute commands and programs, collect information about the infected machine and its network, browse files and directories, and upload or download data. The malware can also capture screenshots, manipulate files, and create proxy connections that allow traffic to pass through an infected computer.

Its screenshot capability is designed to reduce unnecessary data transfers. After taking an initial full-screen capture, SparroWocky can monitor the display every 500 milliseconds and send only portions of the screen that have changed.

The backdoor can also execute Beacon Object Files directly in memory. This allows its operators to use additional capabilities originally developed for security testing frameworks without necessarily installing separate tools in a conventional way.

Researchers found several techniques intended to make the malware harder for security products and analysts to detect. SparroWocky is delivered through DLL side-loading involving a legitimate executable, a modified DLL, and an encrypted payload. The loader decrypts the backdoor and places it directly into memory rather than writing the final malware to disk.

The malware can remain active after a restart by creating a Windows service or adding itself to the Registry. It also manipulates aspects of Windows process and thread behavior in an effort to make malicious activity appear more legitimate to monitoring tools.

Researchers identified at least 18 command-and-control addresses associated with the operation. Communications were observed primarily over port 443, although port 8080 and proxy infrastructure were also used.

Early SparroWocky infections were installed through SparrowDoor, helping researchers connect the new malware to FamousSparrow. Despite that relationship, SparroWocky is considered a separate malware family rather than simply an updated version of the older backdoor.

The shift to SparroWocky marks a significant change in FamousSparrow’s toolset, while its recent targeting shows a strong concentration on Latin American organizations. Researchers have released technical indicators associated with the campaign to help organizations identify potential infections.