MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-17 · via BleepingComputer

New Backdoor Linked to Chinese Espionage Group Targets Latin American Governments

Image via BleepingComputer
Image via BleepingComputer

A China-linked threat actor known as FamousSparrow has deployed a new modular backdoor called SparroWocky against government agencies across several Latin American countries. The malware, which replaces an older tool, includes anti-analysis tricks and can execute commands, capture screenshots, and proxy network traffic. Researchers believe the campaign aims to gather intelligence on regional responses to U.S. pressure on Chinese economic interests.

Expanded Detail

ESET's investigation identified at least 18 command-and-control servers communicating with the malware over ports 443 and 8080, sometimes routing through HTTP or SOCKS5 proxies. The backdoor establishes persistence through a Windows service named ProcAuditManager or a registry key called SnapCart, depending on privilege levels. The malware's design incorporates code from open-source projects and uses the MinHook library to intercept thread creation, disguising malicious threads as legitimate Windows functions.

The campaign has run for over a year, with telemetry showing a shift toward Latin American targets beginning mid-2025. ESET attributes the operation to FamousSparrow, a group with demonstrated expertise in Windows internals and anti-analysis techniques. The researchers published indicators of compromise alongside their technical breakdown to assist defenders in detecting the threat.

Context

This campaign may signal an escalation in cyber espionage targeting sovereign governments in Latin America, potentially affecting diplomatic relations and regional security postures. Officials in affected countries could face pressure to strengthen cybersecurity defenses while balancing economic ties with China against U.S. interests. The malware's sophistication suggests that smaller nations with limited security resources may be particularly vulnerable, and the intelligence gathered could influence regional policy decisions on trade, technology, and international alignment.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
State-linked Iranian group deploys new Windows spyware against dissidents · Cybersecurity
Compromised HBO Max Reddit account used to spread info-stealing malware via fake ads · Cybersecurity
ClickFix malware scheme spreads through compromised Reddit ads · Cybersecurity
China-linked espionage group exploits Sogou Input Method flaw to install GrayRabbit backdoor · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Chinese hackers use SparroWocky malware in govt espionage attacks.” Browse more stories.