Chinese hackers use SparroWocky malware in govt espionage attacks
The China-linked espionage group FamousSparrow has been deploying a new, sophisticated C++ backdoor named SparroWocky in attacks against government organizations across Latin America for over a year, aiming to collect intelligence on their responses to U.S. economic press…
Intelligence analysis by Gemini 2.5 Flash

ESET researchers have uncovered a persistent cyber espionage campaign by the China-linked group FamousSparrow, utilizing the advanced SparroWocky malware to infiltrate government networks in Latin American countries. The operation's goal is to monitor regional reactions to U.S. economic policies impacting China, highlighting a strategic intelligence-gathering effort with a new, highly…
Imagine there's a secret club of super-smart spies from China, called FamousSparrow. They've built a new secret tool, like a tiny invisible robot called SparroWocky, to sneak into the computers of governments in countries like Argentina and Peru. Their mission is to listen in and find out what these governments are thinking about how America is dealing with China's businesses. It's like playing a very serious game of hide-and-seek to learn secrets.
Analysis
FamousSparrow
The China-linked espionage group, identified as FamousSparrow, has been actively engaged in cyber operations targeting government entities for an extended period. ESET researchers have attributed the deployment of the sophisticated SparroWocky backdoor to this group, noting that it has replaced their older custom malware, SparrowDoor. This shift indicates a continuous evolution in their toolset and tactics, reflecting a well-resourced and persistent threat actor.
FamousSparrow's primary objective in these recent campaigns appears to be intelligence collection. Specifically, the group is believed to be gathering information on how Latin American governments are responding to increasing economic pressure from the United States directed at Chinese interests. This strategic focus underscores the geopolitical motivations behind their cyber espionage activities, aiming to provide Beijing with insights into regional dynamics and policy reactions.
SparroWocky
SparroWocky is a highly advanced and modular C++ backdoor, incorporating elements from open-source projects to enhance its capabilities. ESET's analysis highlights its extensive feature set, which includes the ability to execute commands, load Beacon Object Files, collect detailed system information, manage files, capture screenshots, and even create processes in other user sessions. These functionalities provide the attackers with comprehensive control over compromised systems.
A key characteristic of SparroWocky is its sophisticated array of anti-analysis and evasion mechanisms. The malware manipulates low-level memory structures, patches code at runtime, and employs techniques like DLL side-loading and call stack spoofing to remain undetected. Notably, it intercepts the Windows thread creation process to disguise its malicious threads as legitimate Windows components, making it particularly challenging for security products to identify and neutralize.
Latin America
The geographical focus of FamousSparrow's recent operations has been predominantly on Latin American government organizations. ESET's telemetry indicates that since mid-2025, the group has concentrated its efforts on targets within this region. Specific countries identified as victims include Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. This broad targeting across multiple nations suggests a wide-ranging intelligence gathering mandate.
The choice of Latin America as a primary target region is significant, aligning with the stated objective of monitoring responses to U.S. economic pressure on China. The region's geopolitical importance and its relationships with both the United States and China make it a critical area for intelligence collection. The sustained nature of these attacks, ongoing for over a year, further emphasizes the strategic value FamousSparrow places on insights from these governments.
Key points
- China-linked group FamousSparrow uses new SparroWocky malware.
- Attacks target government organizations in Latin America for over a year.
- Objective is to collect intelligence on responses to U.S. pressure on Chinese economic interests.
- SparroWocky is a modular C++ backdoor with advanced anti-analysis and evasion techniques.
- Malware establishes persistence via Windows services or registry keys and communicates via C2 addresses.
The detailed analysis by ESET, including the technical breakdown of SparroWocky and the release of Indicators of Compromise (IoCs), provides crucial information for targeted governments and cybersecurity defenders. This intelligence can significantly enhance their ability to detect, prevent, and mitigate future attacks by FamousSparrow, strengthening overall cyber defenses in the region.
Despite ESET's findings, the advanced evasion techniques of SparroWocky and the persistent nature of FamousSparrow suggest that these espionage campaigns could continue undetected in other organizations. The ongoing intelligence gathering could provide China with significant geopolitical advantages, potentially influencing international relations and economic policies in Latin America without public knowledge.



