China’s FamousSparrow APT Spies on US Politics in Latin America

China’s FamousSparrow APT Spies on US Politics in Latin America with Sophisticated Backdoor

A highly sophisticated cyber-espionage group known as “FamousSparrow” has been secretly gathering intelligence on government agencies and major industries in Central and South America, using a custom-made backdoor called SparroWocky. This stealthy malware has allowed the Chinese threat actors to build a network of espionage capabilities that span multiple countries, all while flying under the radar of cybersecurity defenses.

FamousSparrow’s activities have been detected by ESET researchers, who have observed the group pivoting exclusively to targeting government organizations in Latin America since July 2025. To meet this new challenge, the group replaced its previous backdoor, SparrowDoor, with SparroWocky – a modular C++ program that uses dynamic link library (DLL) sideloading and executes its malware in-memory to evade detection.

One of the key features of SparroWocky is its ability to incorporate Beacon Object Files (BOFs), which allows the threat actors to leverage tools built by the offensive security community, including those used for red teaming. This compatibility enables FamousSparrow to repurpose these modules within their malware framework, making it even harder to detect.

But what’s most striking about SparroWocky is its use of “stack spoofing,” a technique that allows the threat actors to manipulate a thread’s call stack and make potentially sensitive function calls seem like they came from a legitimate program. This level of sophistication is unusual in cyber-espionage, where such techniques are typically used by nation-state actors.

FamousSparrow’s activities have significant implications for the geopolitics of the region. With China’s growing economic influence in Latin America, the US has been scrutinizing investments made by Chinese companies, including those that have ties to government agencies. By gathering intelligence on these organizations, FamousSparrow is effectively providing China with a strategic advantage in its bid for eco-colonial influence.

The use of SparroWocky also highlights the evolution of cyber-espionage tactics, where threat actors continually update and improve their tools to stay ahead of detection. In this case, FamousSparrow appears to have abandoned its aging SparrowDoor backdoor in favor of a more sophisticated tool that can evade detection more effectively.

For organizations operating in Latin America, particularly those with ties to US politics or Chinese investments, this development should serve as a wake-up call. Cybersecurity defenses must be strengthened to detect and prevent such advanced threats from infiltrating networks. Furthermore, companies should be aware of the potential risks associated with doing business with entities linked to government agencies or nation-state actors.

Ultimately, the use of SparroWocky by FamousSparrow underscores the need for a more vigilant approach to cybersecurity in the region, where nation-state actors are increasingly using advanced tools to gather intelligence and exert influence.


Source: Dark Reading — 2026-09-17