New Backdoor Linked to Chinese Espionage Group Targets Latin American Governments

A China-linked threat actor known as FamousSparrow has deployed a new modular backdoor called SparroWocky against government agencies across several Latin American countries. The malware, which replaces an older tool, includes anti-analysis tricks and can execute commands, capture screenshots, and proxy network traffic. Researchers believe the campaign aims to gather intelligence on regional responses to U.S. pressure on Chinese economic interests.
ESET's investigation identified at least 18 command-and-control servers communicating with the malware over ports 443 and 8080, sometimes routing through HTTP or SOCKS5 proxies. The backdoor establishes persistence through a Windows service named ProcAuditManager or a registry key called SnapCart, depending on privilege levels. The malware's design incorporates code from open-source projects and uses the MinHook library to intercept thread creation, disguising malicious threads as legitimate Windows functions.
The campaign has run for over a year, with telemetry showing a shift toward Latin American targets beginning mid-2025. ESET attributes the operation to FamousSparrow, a group with demonstrated expertise in Windows internals and anti-analysis techniques. The researchers published indicators of compromise alongside their technical breakdown to assist defenders in detecting the threat.
This campaign may signal an escalation in cyber espionage targeting sovereign governments in Latin America, potentially affecting diplomatic relations and regional security postures. Officials in affected countries could face pressure to strengthen cybersecurity defenses while balancing economic ties with China against U.S. interests. The malware's sophistication suggests that smaller nations with limited security resources may be particularly vulnerable, and the intelligence gathered could influence regional policy decisions on trade, technology, and international alignment.