The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America.
The operations have been ongoing for more than a year, with the new malware replacing the previously used SparrowDoor custom backdoor.
ESET researchers observed SparroWocky in attacks targeting organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.
The researchers believe the threat actor's objective was to collect intelligence on Latin American governments’ responses to increasing U.S. pressure on Chinese economic interests.
ESET's analysis revealed that SparroWocky is a modular, full-blown C++ backdoor that includes code from open-source projects.
The malware features anti-analysis mechanisms, like manipulating low-level structures in memory and patching code at runtime. SparroWocky's capabilities include:
- run commands and executable files
- load and execute Beacon Object Files in memory
- collect system, network, user, domain, and Windows-version details
- enumerate drives, directories, files, displays, and active user sessions
- upload, download, copy, move, rename, and delete files
- capture screenshots every 500 milliseconds, transmitting only changed screen regions after the first full-screen image
- create processes in another logged-in user’s session
- operate as a TCP proxy and forward connections
- remove its persistence and delete its own files
According to the researchers, the malware is deployed via DLL side-loading after a loader decrypts the RC4-encoded payload contained in a .dat file and maps it directly in memory for evasion.
The malware features several evasion mechanisms, including call stack and threat origin spoofing, dynamic API resolving, and disguising malicious in-memory code and DLLs as legitimate Windows components.
To hide from security solutions, SparroWocky is intercepting the Windows thread creation process to alter the start address.
“SparroWocky uses the MinHook library to hook the CreateThread function in order to conceal the original lpStartAddress parameter from security products.
“Essentially, any thread created by SparroWocky would have AnimateWindow as the starting address, which would likely be considered legitimate by a security product,” ESET explains.
SparroWocky establishes persistence either through a Windows service (ProcAuditManager) or by adding a Windows registry key (SnapCart) under HKLM or HKCU, depending on the available privileges.
The researchers note that the malware's architecture and evasion techniques “indicate strong knowledge of anti-analysis tricks and Windows internals,” which aligns with their attribution to a well-resourced and experienced threat group.
While analyzing the attacks, ESET found at least 18 command-and-control (C2) addresses communicating with the malware directly over port 443 or 8080, or through HTTP and SOCKS5 proxies.
ESET's telemetry indicates that from mid-2025, FamousSparrow's focus has been primarily on targets in the Latin America region.
The company's report includes a technical analysis of the SparroWocky backdoor and shares a list of indicators of compromise (IoCs) associated with this activity.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat