Chinese hackers use SparroWocky malware in govt espionage attacks

Chinese Hackers Use Sophisticated Malware in Government Espionage Attacks

A China-linked espionage group has been using a new, highly advanced malware to target government organizations in Latin America. The malware, known as SparroWocky, was identified by ESET researchers who tracked its use in attacks on at least nine countries in the region.

The targets of these attacks include government agencies in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. According to ESET’s analysis, the primary objective of these operations is to gather intelligence on the governments’ responses to increasing U.S. pressure on Chinese economic interests.

SparroWocky is a modular backdoor written in C++, which includes code from open-source projects. Its capabilities are extensive and include running commands and executable files, collecting system and network information, and even capturing screenshots every 500 milliseconds. The malware also features advanced evasion mechanisms to avoid detection by security solutions.

One of the most interesting aspects of SparroWocky is its ability to conceal its activities from security products. It does this by intercepting the Windows thread creation process and altering the start address, making it difficult for antivirus software to detect its presence. This is achieved through the use of a library called MinHook, which hooks the CreateThread function.

To establish persistence on infected systems, SparroWocky uses either a Windows service or a registry key, depending on the available privileges. The malware’s architecture and evasion techniques suggest that it is the work of a well-resourced and experienced threat group.

ESET’s analysis also revealed that at least 18 command-and-control (C2) addresses are communicating with SparroWocky directly over port 443 or 8080, or through HTTP and SOCKS5 proxies. This suggests a sophisticated communication infrastructure, which is likely to be used for future attacks.

The use of SparroWocky in these attacks highlights the ongoing threat posed by state-sponsored hacking groups. These groups have access to significant resources and expertise, making them increasingly difficult to detect and defend against. The fact that they are targeting government organizations in Latin America also suggests a broader strategy to gather intelligence on regional responses to global economic pressures.

In light of this attack, it’s essential for organizations, particularly those in the government sector, to review their cybersecurity posture and implement robust measures to prevent similar attacks. This includes regular software updates, secure configuration practices, and continuous monitoring for suspicious activity. By staying vigilant and proactive, we can reduce the risk of falling victim to these sophisticated cyber threats.

As a practical takeaway, it’s crucial for organizations to focus on developing a layered defense approach that incorporates multiple security measures, including endpoint detection and response (EDR), intrusion detection systems (IDS), and network segmentation. This will help to detect and contain advanced threats like SparroWocky before they can cause significant harm.


Source: Bleeping Computer — 2026-09-17