China’s FamousSparrow APT Spies on US Politics in Latin America
In a move that highlights the escalating tensions between China and the United States in Latin America, a sophisticated cyber-espionage group known as “FamousSparrow” has been using a custom backdoor to gather sensitive information from government agencies and major industries in Central and South America. The group’s activities have been observed since July 2025, with a notable shift towards targeting organizations that host Chinese investments, which are currently under scrutiny by the Trump administration.
FamousSparrow is associated with other well-known threat groups, Earth Estries and Salt Typhoon, but its exact relationship remains unclear. What is known, however, is that it has been using a revamped backdoor called “SparroWocky” to build a nest inside government agencies in Latin America. This malware is notable for its ability to execute in-memory, encrypt command-and-control traffic, and automate self-deletion, making it extremely difficult to detect.
The threat actors behind SparroWocky have shown an impressive level of sophistication by incorporating features from the offensive security community’s open-source red teaming tools. Specifically, they have adopted Beacon Object Files (BOFs), a file format first introduced by Cobalt Strike, which allows them to leverage pre-built modules for their malware framework. This approach not only gives them access to powerful tools but also enables them to keep those tools hidden from detection.
One of the most intriguing aspects of SparroWocky is its use of stack spoofing, a technique that manipulates a thread’s call stack to make potentially sensitive function calls appear legitimate. ESET senior malware researcher Romain Dumont notes that this feature demonstrates FamousSparrow’s willingness to avoid being detected. By incorporating such advanced techniques, the group has successfully flown under the radar, gathering sensitive information without being caught.
The implications of FamousSparrow’s activities are far-reaching and highlight the increasing importance of cybersecurity in the region. As the United States and China engage in a battle for influence in Latin America, cyber-espionage groups like FamousSparrow will likely continue to play a significant role in gathering intelligence on sensitive information. It is essential for governments, organizations, and individuals to be vigilant about their digital security, particularly when dealing with high-stakes targets.
In light of this development, it’s crucial for Latin American countries to prioritize cybersecurity measures, such as implementing robust threat detection systems and conducting regular security audits. Additionally, organizations hosting Chinese investments should take extra precautions to protect themselves from potential cyber threats. By staying informed about the latest developments in cybersecurity and taking proactive steps to safeguard their digital presence, individuals and organizations can reduce the risk of falling victim to sophisticated attacks like SparroWocky.
Source: Dark Reading — 2026-09-17