Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Healey to ask EU finance ministers to let UK into industry scheme

    September 17, 2026

    The FAA’s plan to fix air traffic? $875 million worth of AI

    September 17, 2026

    Microsoft Open-Sources TauGrid: A Kubernetes-Native Stack for GPU AI Workloads

    September 17, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Healey to ask EU finance ministers to let UK into industry scheme
    • The FAA’s plan to fix air traffic? $875 million worth of AI
    • Microsoft Open-Sources TauGrid: A Kubernetes-Native Stack for GPU AI Workloads
    • China’s FamousSparrow APT Spies on US Politics in Latin America
    • Is There Any Chance Left to Save the CLARITY Act?
    • Big space mirrors could bring Earth on-demand light — and upend our night sky
    • Mekong’s Irrawaddy dolphins find cautious hope amid a river in crisis
    • Technip Energies picks up assignment on Mexican LNG project
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 17
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    China’s FamousSparrow APT Spies on US Politics in Latin America

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 17, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A Chinese cyber-espionage group known as “FamousSparrow” is using a revamped backdoor to build a nest inside Central and South American governments and major industries.

    The advanced persistent threat (APT) is associated with, but not definitively confirmed to be related to, Earth Estries and Salt Typhoon; it’s a seven-year-old outfit that made its reputation by attacking international hotels, and governments and corporations here and there. It appears to have changed its modus operandi of late, though, to become China’s eyes and ears in the global southwest. Since the summer of 2025, it has been using a custom backdoor called “SparroWocky” to keep an eye on government agencies in the Latin American region, particularly those that host Chinese investments that are currently being scrutinized by the Trump administration.

    Chinese Cyberattacks in Latin America

    In July 2025, ESET researchers observed FamousSparrow pivot to exclusively targeting government organizations in Latin America. To meet its new challenge, the following month, it ditched its namesake “SparrowDoor” backdoor for the aforementioned SparroWocky malware.

    Related:Cyber Op Targets South Korean Media & Automotive Sectors

    APTs commonly iterate on their flagship spying tools, developing newer and more powerful versions as their ambitions grow, or their targets wise up. FamousSparrow took the harder route with SparroWocky, utilizing some of the same logic as its past malware, but largely building something new from the ground up. Alexandre Côté Cyr, malware researcher at ESET, speculates that SparrowDoor was aging, widely cloned, and possibly triggering cybersecurity alerts too readily.

    “For a time, we thought it was exclusive to them, but over the last couple of years we’ve seen versions of the same thing — [malware that] seems to have a common ancestor, used by other threat groups. So one possibility is that because this malware is now widespread, it’s better detected,” he says.

    The threat actors’ new toy is a modular C++ program, deployed via dynamic link library (DLL) sideloading. To fly under the radar, FamousSparrow executes its malware in-memory, encrypts its command-and-control (C2) traffic, and automates self-deletion. It also stacks on a couple of neat tricks.

    “Stack spoofing is pretty awesome,” says ESET senior malware researcher Romain Dumont. “The fact that they used it proved that they were really willing to avoid being detected.” Stack spoofing is the process of messing with a thread’s call stack, such that potentially sensitive function calls made by a malicious program could be made to seem like they came from a legitimate program.

    Related:Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency

    Another helpful feature of the modular SparroWocky is its ability to incorporate Beacon Object Files (BOFs) — a file format first introduced by Cobalt Strike, which has since been adopted by other penetration testing developers. Côté Cyr notes, “This allows them to leverage a lot of what the offensive security community is building — to directly take these modules that were built for red teaming, and repurpose them in their own malware.”

    Not only does BOF compatibility afford FamousSparrow more open source (OSS) red teaming tools to play with, but by folding those tools into their malware framework, they can keep them more hidden than they otherwise could by deploying OSS tools in addition to their malware. “Having it all in one thing means there’s just one thing you need to hide. There’s not too much interprocess communication. You’re not dropping a bunch of files. The scope is limited,” Côté Cyr explains.

    FamousSparrow’s Role in Geopolitics

    Whether it’s about land, sugar, Communism, tourism, or produce, the United States has always taken an interest in its neighbors to the south. That interest hadn’t been quite as heavy-handed in recent decades, arguably, until the current US president took power for a second time, according to ESET. With the so-called “Donroe Doctrine,” America’s designs on the region have grown as a firewall against a chief rival: China.

    Related:Russian Hackers Phish EU Officials Over Messaging Apps

    Replacing the Soviet Union and then Russia as the State’s main geopolitical adversary, the Chinese Communist Party (CCP) extended its Belt and Road Initiative to Latin America in 2018, helping to build infrastructure across the region — and with it, its sphere of influence.

    As just one example, nine days after Donald Trump’s second election victory, the Port of Chancay shipping terminal opened in Lima, Peru, thanks to heavy support from Chinese organizations. Trump has since flagged the activity as an economic risk, and just last week enlisted his Secretary of State to discuss Chinese influence with Peru’s president.

    This type of fomenting imperial-ish standoff, ESET believes, is what inspired FamousSparrow’s latest campaign. Since August 2025, SparroWocky has been spotted almost exclusively attacking government organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela, plus a telecommunications organization in Puerto Rico; likely to keep tabs on how countries are interacting with the US.

    “We suspect that FamousSparrow’s activities are intended to help China better monitor and anticipate the reaction of local governments to current US pressures,” according to ESET’s report, which contains information about indicators of compromise for the activity for at-risk organizations. “For instance, one of the Panamanian entities we’ve seen being targeted is directly involved in the ongoing commercial dispute regarding two major ports located in the canal area, which were, until recently, operated by a China-based company. As the concession granted to this company was legally challenged by the Panamanian government in early 2025, it seems highly likely that FamousSparrow’s operation was intended to gain early, privileged knowledge of local authorities’ intentions on this issue.” The ramped-up cyber activity likely represents a new normal for organizations in the region, Côté Cyr notes.

    “China-aligned APT groups were already somewhat present in Latin America. And, more broadly, the Chinese state and economy has had interests in businesses in Latin America. But it wasn’t so much a focus as other [regions],” Côté Cyr says. But nowadays, he says, China has real skin in the regional game, and the cyberespionage duly follows.

    “In the past, FamousSparrow targeted victims very broadly,” Côté Cyr recalls. But for the past year, “It looks like they changed their mandate to very specifically Latin America.”

    America APT Chinas FamousSparrow Latin politics Spies
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

    OpenAI details more cases of AI agents taking unauthorized actions

    OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training

    Brevo supply-chain attack injected ClickFix scripts on customer sites

    Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels

    OpenAI admits six new misalignment incidents under new reporting framework

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Healey to ask EU finance ministers to let UK into industry scheme

    September 17, 2026

    The FAA’s plan to fix air traffic? $875 million worth of AI

    September 17, 2026

    Microsoft Open-Sources TauGrid: A Kubernetes-Native Stack for GPU AI Workloads

    September 17, 2026

    China’s FamousSparrow APT Spies on US Politics in Latin America

    September 17, 2026
    Latest Posts

    ADNOC, SLB roll out AI-powered tool across over 120 rigs to enhance drilling ops

    August 4, 2026

    Mining threat persists in Raja Ampat, Indonesia’s ‘Amazon of the Seas’

    August 4, 2026

    Smoke Streams Across Eastern Washington

    August 4, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Healey to ask EU finance ministers to let UK into industry scheme

    September 17, 2026

    The FAA’s plan to fix air traffic? $875 million worth of AI

    September 17, 2026

    Microsoft Open-Sources TauGrid: A Kubernetes-Native Stack for GPU AI Workloads

    September 17, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.