FamousSparrow Deploys SparroWocky Backdoor Against Latin American Governments
Chinese threat actor FamousSparrow has targeted government agencies across Latin America with a newly identified backdoor called SparroWocky, according to ESET Research. The malware is delivered via DLL side-loading, where a legitimate executable is tricked into loading a malicious DLL, with the main payload decrypted using RC4 and injected directly into memory to evade detection. Once active, SparroWocky can execute additional code, perform file operations, capture screens, and relay TCP traffic between the command-and-control server and other devices on the victim's internal network. The backdoor achieves persistence by registering as a Windows service or via the Run registry key, and uses TLS encryption for its C2 communications. ESET notes that roughly 90% of FamousSparrow's targets between mid-2025 and 2026 were concentrated in Latin America, with compromised Exchange servers suspected as an initial access vector.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in