Minacce · 4 giorni fa
ESET dice che FamousSparrow ha sostituito SparrowDoor con SparroWocky e lo ha usato almeno da agosto 2025 contro enti pubblici in America Latina. Il salto non è solo di nome: il gruppo ha spostato la sua cassetta degli attrezzi su un implant C++ modulare, pensato per cambiare capacità senza riscrivere tutto ogni volta.
SparroWocky può caricare moduli aggiuntivi, eseguire comandi, esfiltrare file e nascondere parte della propria attività con tecniche anti-analysis. Il punto d’ingresso resta però il più importante: ESET riferisce che FamousSparrow ha ottenuto accesso passando da server Microsoft Exchange esposti su Internet, quindi il rischio non è limitato ai bersagli già nominati ma a qualunque mail server raggiungibile pubblicamente nel perimetro dei target del gruppo.
Per chi gestisce Exchange esposto, il segnale è che il gruppo sta ottimizzando per persistenza operativa e cambi rapidi di funzionalità, non per una singola famiglia di malware statica. Il file name cambia; il varco resta riusabile.
7 fonti che coprono questa storia
China's FamousSparrow APT Spies on US Politics in Latin America
Amid the US and China's fight for eco-colonial influence in Latin America, a stealthy backdoor has taken flight.
China's Salt Typhoon backdoors Latin American orgs with new snooping malware
Beware the SparroWocky, my son! The backdoor that bites…
The Record from Recorded Future
China’s FamousSparrow hackers target Latin America with new backdoor
Alleged Chinese hackers are breaking into government agencies across Latin America using a new backdoor that researchers are calling “SparroWocky.”
FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor
ESET said FamousSparrow has replaced SparrowDoor with SparroWocky
China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
FamousSparrow deploys SparroWocky against government entities across Latin America, enabling command execution and file exfiltration.
Beware the SparroWock: The backdoor that bites, the commands that catch
ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group
Chinese hackers use SparroWocky malware in govt espionage attacks
The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America.
Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-09-18