China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
AI Summary
The China-aligned state-sponsored threat actor FamousSparrow has been deploying a new modular C++ backdoor named SparroWocky in targeted cyber espionage attacks across Latin America since at least August 2025. The malware, which replaces the group's previous SparrowDoor implant, supports command execution, file exfiltration, periodic screenshots, and acts as a TCP proxy. It uses anti-analysis techniques and integrates open-source tools like Mbed TLS, MinHook, and COFF Loader for secure communications, evasion, and in-memory plugin execution. Targets include governmental entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela, with 90% of observed activity focused on the region.
AI-extracted · verify before operational use
Extracted Entities 3 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 216[.]238[.]110[.]120 | Details → |