A Chinese cyber-espionage group known as “FamousSparrow” is using a revamped backdoor to build a nest inside Central and South American governments and major industries.
The advanced persistent threat (APT) is associated with, but not definitively confirmed to be related to, Earth Estries and Salt Typhoon; it’s a seven-year-old outfit that made its reputation by attacking international hotels, and governments and corporations here and there. It appears to have changed its modus operandi of late, though, to become China’s eyes and ears in the global southwest. Since the summer of 2025, it has been using a custom backdoor called “SparroWocky” to keep an eye on government agencies in the Latin American region, particularly those that host Chinese investments that are currently being scrutinized by the Trump administration.
Chinese Cyberattacks in Latin America
In July 2025, ESET researchers observed FamousSparrow pivot to exclusively targeting government organizations in Latin America. To meet its new challenge, the following month, it ditched its namesake “SparrowDoor” backdoor for the aforementioned SparroWocky malware.
APTs commonly iterate on their flagship spying tools, developing newer and more powerful versions as their ambitions grow, or their targets wise up. FamousSparrow took the harder route with SparroWocky, utilizing some of the same logic as its past malware, but largely building something new from the ground up. Alexandre Côté Cyr, malware researcher at ESET, speculates that SparrowDoor was aging, widely cloned, and possibly triggering cybersecurity alerts too readily.
“For a time, we thought it was exclusive to them, but over the last couple of years we’ve seen versions of the same thing — [malware that] seems to have a common ancestor, used by other threat groups. So one possibility is that because this malware is now widespread, it’s better detected,” he says.
The threat actors’ new toy is a modular C++ program, deployed via dynamic link library (DLL) sideloading. To fly under the radar, FamousSparrow executes its malware in-memory, encrypts its command-and-control (C2) traffic, and automates self-deletion. It also stacks on a couple of neat tricks.
“Stack spoofing is pretty awesome,” says ESET senior malware researcher Romain Dumont. “The fact that they used it proved that they were really willing to avoid being detected.” Stack spoofing is the process of messing with a thread’s call stack, such that potentially sensitive function calls made by a malicious program could be made to seem like they came from a legitimate program.
Another helpful feature of the modular SparroWocky is its ability to incorporate Beacon Object Files (BOFs) — a file format first introduced by Cobalt Strike, which has since been adopted by other penetration testing developers. Côté Cyr notes, “This allows them to leverage a lot of what the offensive security community is building — to directly take these modules that were built for red teaming, and repurpose them in their own malware.”
Not only does BOF compatibility afford FamousSparrow more open source (OSS) red teaming tools to play with, but by folding those tools into their malware framework, they can keep them more hidden than they otherwise could by deploying OSS tools in addition to their malware. “Having it all in one thing means there’s just one thing you need to hide. There’s not too much interprocess communication. You’re not dropping a bunch of files. The scope is limited,” Côté Cyr explains.
FamousSparrow’s Role in Geopolitics
Whether it’s about land, sugar, Communism, tourism, or produce, the United States has always taken an interest in its neighbors to the south. That interest hadn’t been quite as heavy-handed in recent decades, arguably, until the current US president took power for a second time, according to ESET. With the so-called “Donroe Doctrine,” America’s designs on the region have grown as a firewall against a chief rival: China.
Replacing the Soviet Union and then Russia as the State’s main geopolitical adversary, the Chinese Communist Party (CCP) extended its Belt and Road Initiative to Latin America in 2018, helping to build infrastructure across the region — and with it, its sphere of influence.
As just one example, nine days after Donald Trump’s second election victory, the Port of Chancay shipping terminal opened in Lima, Peru, thanks to heavy support from Chinese organizations. Trump has since flagged the activity as an economic risk, and just last week enlisted his Secretary of State to discuss Chinese influence with Peru’s president.
This type of fomenting imperial-ish standoff, ESET believes, is what inspired FamousSparrow’s latest campaign. Since August 2025, SparroWocky has been spotted almost exclusively attacking government organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela, plus a telecommunications organization in Puerto Rico; likely to keep tabs on how countries are interacting with the US.
“We suspect that FamousSparrow’s activities are intended to help China better monitor and anticipate the reaction of local governments to current US pressures,” according to ESET’s report, which contains information about indicators of compromise for the activity for at-risk organizations. “For instance, one of the Panamanian entities we’ve seen being targeted is directly involved in the ongoing commercial dispute regarding two major ports located in the canal area, which were, until recently, operated by a China-based company. As the concession granted to this company was legally challenged by the Panamanian government in early 2025, it seems highly likely that FamousSparrow’s operation was intended to gain early, privileged knowledge of local authorities’ intentions on this issue.” The ramped-up cyber activity likely represents a new normal for organizations in the region, Côté Cyr notes.
“China-aligned APT groups were already somewhat present in Latin America. And, more broadly, the Chinese state and economy has had interests in businesses in Latin America. But it wasn’t so much a focus as other [regions],” Côté Cyr says. But nowadays, he says, China has real skin in the regional game, and the cyberespionage duly follows.
“In the past, FamousSparrow targeted victims very broadly,” Côté Cyr recalls. But for the past year, “It looks like they changed their mandate to very specifically Latin America.”


