China-Linked FamousSparrow Hackers Roll Out New SparroWocky Backdoor Across Latin America
China-Linked FamousSparrow Hackers Roll Out New SparroWocky Backdoor Across Latin America
Researchers at ESET, the Bratislava-headquartered cybersecurity firm, say a China-aligned espionage group known as FamousSparrow has quietly expanded its operations into Latin America, arming itself with a previously unseen backdoor dubbed SparroWocky. According to the company’s threat research team, the tool has been deployed against targets in the region since at least August 2025.
The campaign’s focus appears to be governmental organizations. ESET analysts suggest the timing may reflect a geopolitical dimension: the activity coincides with heightened U.S. engagement in Latin America, and the group’s intensified targeting of government bodies in the region may be a response from Beijing-aligned actors to that increased American attention.
A backdoor with a literary signature
The name SparroWocky is a nod to the malware’s unusual fingerprint. Early samples analyzed by ESET all contained the opening stanza of “Jabberwocky,” the nonsense poem written by English author and mathematician Lewis Carroll, best known for Alice’s Adventures in Wonderland. The poem, embedded in the malicious code, gave researchers a memorable handle for tracking the new tool.
FamousSparrow is not a new name in threat intelligence circles. The group has been on ESET’s radar for some time, and the company describes its continued monitoring as the basis for the latest findings. The emergence of SparroWocky indicates the outfit is actively developing new implant capabilities rather than reusing older tooling, a hallmark of a resourced, state-aligned operation.
The disclosure underscores a broader trend in the threat landscape: advanced persistent threat groups increasingly Treat Latin America as a strategic region for cyber espionage, particularly where diplomatic and economic competition between major powers plays out. Government networks are prized targets because of the intelligence value of their communications and documents.
Organizations in the region, particularly government ministries and agencies, face the practical challenge of detecting implants like SparroWocky, which are typically designed to operate stealthily and exfiltrate data over long periods. ESET has not detailed the full technical capabilities of the backdoor in its initial disclosure, but further research publications are expected to follow.
Market snapshot
In broader technology markets, photonics component maker POET saw its shares trade at $7.92, up 7.32% from the previous close of $7.38, valuing the company at roughly $1.37 billion.
What to watch
- Follow-up technical research from ESET detailing SparroWocky’s capabilities, command-and-control infrastructure, and indicators of compromise.
- Additional disclosures from other cybersecurity vendors identifying victims or overlapping activity in Latin America.
- Government advisories from affected nations’ computer emergency response teams.
- Possible attribution statements or diplomatic responses tied to the campaign.
Source: original release