China's FamousSparrow APT Spies on US Politics in Latin America
China's FamousSparrow APT group is intensifying its espionage efforts in Latin America, targeting government organizations and industries linked to Chinese investments, as part of a broader geopolitical struggle between the United States and China. The group is utilizing a new backdoor, SparroWocky, to gather intelligence on how Latin American governments are responding to US pressure and Chinese economic influence in the region. This escalation is driven by China's Belt and Road Initiative and the US's ‘Donroe Doctrine’ to counter Chinese influence.
China's FamousSparrow APT group is significantly increasing its cyber espionage activities within Latin America, focusing on government organizations and industries connected to Chinese investments. This campaign is a direct response to the growing geopolitical competition between the United States and China, particularly regarding influence in the region. The group is leveraging a revamped backdoor, dubbed ‘SparroWocky,’ to monitor how Latin American governments are reacting to US pressure and China’s Belt and Road Initiative.
Since August 2025, SparroWocky has been primarily targeting government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela, alongside a telecommunications organization in Puerto Rico. The group’s objective appears to be gathering information on local authorities’ intentions regarding Chinese investments and ongoing disputes, such as the legal challenge to a China-based company’s concession for two major ports in the Panama Canal area.
SparroWocky utilizes a modular C++ program deployed via DLL sideloading, incorporating advanced techniques like stack spoofing to evade detection. It also leverages Cobalt Strike BOFs, allowing FamousSparrow to incorporate readily available offensive security tools into its malware framework, minimizing the need for extensive custom development. This approach simplifies deployment and reduces the risk of detection.
Estonian cybersecurity firm ESET researchers believe that FamousSparrow’s activities are intended to assist China in monitoring and anticipating local governments’ responses to US pressure. The group’s targeting aligns with the broader strategic goals of the Belt and Road Initiative and the US’s ‘Donroe Doctrine,’ which aims to counter China’s growing influence in the region.
Previously, FamousSparrow had a broader targeting scope, but the shift to a laser-focused approach on Latin America suggests a heightened strategic priority. The increased cyber activity represents a new normal for organizations in the region, and ESET has provided indicators of compromise for at-risk organizations. The group’s actions underscore the growing importance of cybersecurity in the context of geopolitical competition.
.jpg?width=720&quality=80&disable=upscale)