China’s FamousSparrow hackers target Latin America with new backdoor
Chinese hackers, operating under the FamousSparrow group, are targeting government agencies in Latin America with a new backdoor named ‘SparroWocky.’ This campaign is linked to China’s strategic interest in countering U.S. pressure in the region, particularly concerning trade and infrastructure investments. The malware is designed to evade detection and gather extensive information from compromised systems.
Chinese hackers, operating under the FamousSparrow group, are targeting government agencies across Latin America with a new backdoor named ‘SparroWocky.’ ESET researcher Alexandre Côté Cyr has been tracking this campaign since at least August 2025, observing attacks on government departments in Guatemala, Honduras, Puerto Rico, Panama, Venezuela, Peru, and Argentina. This campaign is a rare occurrence, as Chinese government-backed hacking campaigns typically target single regions.
ESET theorizes that China’s renewed focus on Latin America is directly linked to U.S. President Donald Trump’s increased attention to the region and his efforts to challenge China’s influence on U.S. trade and infrastructure investments. The group is likely aiming to monitor and anticipate local government reactions to these pressures.
The malware, ‘SparroWocky,’ is named after the opening stanza of Lewis Carroll’s poem, ‘Jabberwocky,’ a deliberate tactic to hinder analysis and demonstrate the group’s deep understanding of internal Windows systems. The backdoor allows users to exfiltrate files and take screenshots while also collecting information about the compromised system, including the IP address, usernames, and other sensitive data.
ESET indicates that FamousSparrow has been operating since at least 2019, conducting Chinese cyberespionage campaigns in multiple regions through a variety of vulnerabilities. Initially targeting hotels, the group has evolved to breach government agencies, trade groups, international organizations, and law firms. The group has been publicly linked to Salt Typhoon, a Chinese group that U.S. law enforcement agencies accused of breaching the Treasury Department, several large U.S. telecoms, and an email platform used by Congressional staffers.
