Cyberwarfare / Nation-State Assaults
,
Fraud Administration & Cybercrime
ESET Says FamousSparrow Shifted Almost All Focusing on to Latin America

Chinese language government-linked hackers have spent the previous 12 months gaining footholds into authorities networks throughout Latin America – together with Puerto Rico – utilizing a beforehand unidentified backdoor.
See Additionally: Consultants Supply Insights from Theoretical to the Realities of AI-enabled Cybercrime
Researchers from Eset mentioned in a report revealed Thursday that the group often called FamousSparrow started fielding a “new flagship backdoor” named SparroWocky, in August 2025 – and has since shelved the backdoor that initially gave the group its identify. Researchers discovered that the group started focusing its targets throughout Latin American governments at a second when Washington and Beijing have been competing for affect throughout the hemisphere.
Alongside authorities company infections in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru and Venezuela, Eset counted authorities entities in Puerto Rico, a U.S. territory with authorities businesses that administer federal applications and obtain federal funding. The corporate didn’t identify any sufferer group impacted by the focused assaults.
Eset usually tracks Chinese language espionage crews conducting widespread operations throughout a number of continents over related timelines. However almost 9 out of 10 FamousSparrow targets logged in Eset telemetry since mid-2025 have been positioned in Latin America, based on the report.
Researchers mentioned the concentrate on the area needed to do with U.S.-China coverage, pointing to the Trump administration’s aggressive push into the hemisphere. Beijing has spent the previous decade shopping for into ports, energy era, mining and telecom networks. The report mentioned the intrusions are seemingly meant to offer China an advance learn on how governments within the area will reply to these rising pressures.
Panama presents the clearest illustration of the assaults. Eset noticed one entity focused whereas it was caught up in a dispute over two container ports flanking the Panama Canal. China-based operators ran that terminal till not too long ago, when the Panamanian authorities challenged the concession in court docket in early 2025.
Eset mentioned the hackers seemingly sought “early, privileged data of native authorities’ intentions.” Panama’s president has publicly described the ports as caught up in a dispute between Washington and Beijing, Reuters reported in April.
FamousSparrow has run cyberespionage campaigns since at the least 2019, and Eset first documented the group in September 2021, when it was chaining ProxyLogon exploits towards internet-facing Microsoft Trade servers. Early victims leaned closely towards inns earlier than the group moved into public sector, authorized and engineering targets.
Development Micro has related the group to the cluster it tracks as Earth Estries, and others have linked it to Salt Storm, the operation behind 2024 intrusions into U.S. telecommunications carriers. Eset mentioned it tracks Salt Storm as a separate entity as a result of no technical indicators join the 2 (see: Consultants See Little Progress After Main Chinese language Telecom Hack).
Cisco Talos reported in March {that a} cluster overlapping with FamousSparrow had spent two years inside South American telecom suppliers (see: China-Linked Hackers Use Malware Trio for Telecom Espionage).
Eset attributed the brand new marketing campaign with excessive confidence, citing a element from the earliest intrusions: SparroWocky arrived on some machines delivered by SparrowDoor, a backdoor that no different group is understood to function. Many organizations hit with the brand new device had additionally been focused with the outdated one.
The beforehand undisclosed backdoor can run executables, stock the host right down to its username and pull information off disk, amongst different superior capabilities. For persistence, operators select between a Home windows service and a registry Run key.
Early samples of the malware carried a stanza of Lewis Carroll’s “Jabberwocky,” which the researchers traced to cryptographic check vectors.









