Threats · 4 days ago
ESET says FamousSparrow has replaced its older SparrowDoor backdoor with a modular C++ implant called SparroWocky, and has been using it against government entities across Latin America since at least August 2025. The group’s latest wave is notable not just for the new malware name, but for the access path: publicly reachable Microsoft Exchange servers are the foothold.
SparroWocky can load extra capabilities as needed and uses anti-analysis tricks to hide what it is doing. In plain terms, that means the operator can add functions without swapping out the whole implant, and an exposed mail server can stay useful as a repeatable entry point for espionage even as the payload changes.
For teams that run internet-facing Exchange, the exposure is in the server layer, not only in the named malware sample. If the same mailbox system stays public, the actor can come back through that door with different tooling, so the lasting risk is the reachable Exchange service itself and the access it gives into the network behind it.
7 sources covering this story
China's FamousSparrow APT Spies on US Politics in Latin America
Amid the US and China's fight for eco-colonial influence in Latin America, a stealthy backdoor has taken flight.
China's Salt Typhoon backdoors Latin American orgs with new snooping malware
Beware the SparroWocky, my son! The backdoor that bites…
The Record from Recorded Future
China’s FamousSparrow hackers target Latin America with new backdoor
Alleged Chinese hackers are breaking into government agencies across Latin America using a new backdoor that researchers are calling “SparroWocky.”
FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor
ESET said FamousSparrow has replaced SparrowDoor with SparroWocky
China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
FamousSparrow deploys SparroWocky against government entities across Latin America, enabling command execution and file exfiltration.
Beware the SparroWock: The backdoor that bites, the commands that catch
ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group
Chinese hackers use SparroWocky malware in govt espionage attacks
The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America.
Part of the PlainSec briefing for 2026-09-18