Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America

The Hacker News by The Hacker News
September 17, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananSep 17, 2026Malware / Cyber Espionage

The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025.

“SparroWocky is a modular, C++ backdoor,” ESET security researchers Alexandre Côté Cyr and Romain Dumont said in a technical report shared with The Hacker News ahead of publication. “Its architecture and the techniques used by its authors indicate strong knowledge of anti-analysis tricks and Windows internals.”

SparroWocky is so named for the fact that early iterations of the malware have been found to contain the first stanza of Jabberwocky, a famous nonsense poem written by the English author, poet, and mathematician Lewis Carroll in around 1855.

The latest findings from ESET indicate that the cyber espionage group, which shares some level of overlap with Earth Estries and Salt Typhoon, has replaced SparrowDoor with SparroWocky as its primary implant. The threat actor is assessed to be active since at least 2019.

SparroWocky features the ability to execute arbitrary files, act as a TCP proxy, and run commands. It can also collect general information about the compromised machine and the IP addresses of its network interfaces, as well as exfiltrate files, take periodic screenshots, perform file operations, and delete itself from the host.

Furthermore, it makes use of various public projects for communications and defense evasion –

  • Mbed TLS, to establish a secure communication channel with its command-and-control (C2) server (“216.238.110[.]120”) over TLS
  • MinHook, to hide the start address of newly created threads from security products
  • COFF Loader, to enable dynamic loading and execution of in-memory plugins in the form of COFF objects
  • A variant of SilentMoonwalk (or StackMoonwalk), to spoof the call stacks originating from MinHook routines

“FamousSparrow still uses open-source offensive tooling for its own malicious ends,” ESET said. “Previously, these tools were mainly used side by side with the group’s backdoor. With SparroWocky, we can observe that it also has the development capabilities to integrate open-source code directly into its own custom backdoor.”

Despite switching to a distant malware family, the underlying techniques remain the same. As observed in the case of SparrowDoor, the malware is triggered by means of a DLL sideloading chain. The legitimate executable is used to launch a loader DLL that then decrypts and launches the main payload. The initial access vector used in these attacks is unknown.

What’s more, FamousSparrow appears to be more focused on targeting high-profile entities across Latin America starting July 2025, with the new backdoor deployed against governmental entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. ESET said 90% of the group’s targets recorded in its telemetry have been located in the region.

“It is not clear whether the group’s apparent focus on Latin America may reflect a formal, geographical mandate, or whether this focus is only temporary and dictated by the current geopolitical circumstances,” the Slovak cybersecurity company said.



Source link

The Hacker News

The Hacker News

Next Post

Het nieuwste rapport van Huawei stelt 10 belangrijke richtingen voor Intelligent World 2035 voor

Recommended.

ODI tells EU to balance AI safeguards with innovation promotion | Computer Weekly

ODI tells EU to balance AI safeguards with innovation promotion | Computer Weekly

August 13, 2025
Strong security balances consolidation and best-of-breed capabilities | Computer Weekly

Strong security balances consolidation and best-of-breed capabilities | Computer Weekly

March 12, 2026

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

January 8, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026
The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

June 9, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio