Chinese Hackers Use Sophisticated Malware in Government Espionage Attacks Across Latin America
A highly skilled and well-resourced Chinese espionage group has been using a powerful new backdoor to infiltrate government organizations across Latin America. The attackers, linked to the China-based threat actor FamousSparrow, have been quietly gathering intelligence on governments’ responses to increased pressure from the US on Chinese economic interests.
The malware, dubbed SparroWocky, has been employed in attacks targeting Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela over the past year. Researchers at ESET discovered that SparroWocky is a highly modular backdoor written in C++, with capabilities that allow it to collect sensitive information, execute commands, and even capture screenshots.
SparroWocky’s arsenal includes features such as running executable files, loading Beacon Object Files, collecting system details, enumerating drives and directories, and uploading or downloading files. The malware also has advanced anti-analysis mechanisms, including the ability to manipulate low-level memory structures and patch code at runtime. These evasion techniques allow SparroWocky to remain undetected by security solutions.
The attackers deploy SparroWocky via a DLL side-loading attack, which involves decrypting an RC4-encoded payload from a .dat file and mapping it directly into memory for stealth purposes. This tactic is designed to evade detection by traditional security tools.
One of the most concerning aspects of SparroWocky is its ability to intercept the Windows thread creation process, altering the start address to conceal malicious activity from security products. By disguising itself as a legitimate Windows component, SparroWocky can operate undetected within compromised systems.
The malware’s persistence mechanism involves creating a Windows service or adding a registry key under HKLM or HKCU, depending on available privileges. ESET researchers note that the architecture and evasion techniques employed by SparroWocky indicate strong knowledge of anti-analysis tricks and Windows internals, consistent with the group’s reputation as a well-resourced and experienced threat actor.
The scope of the attacks suggests that FamousSparrow has been focusing primarily on targets in Latin America since mid-2025. ESET’s analysis also revealed at least 18 command-and-control addresses communicating directly with the malware over port 443 or 8080, or through HTTP and SOCKS5 proxies.
In light of this sophisticated threat, it is essential for organizations to strengthen their security posture, particularly in regions targeted by FamousSparrow. By understanding the tactics and techniques employed by SparroWocky, organizations can take proactive steps to protect themselves against similar attacks. This includes implementing robust network segmentation, conducting regular vulnerability assessments, and staying up-to-date with the latest threat intelligence.
Source: Bleeping Computer — 2026-09-17