hacker-news · Crawled Sep 17, 2026

China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America

1 IoCs 2 Actors 1 Malware
Read original article ↗

AI Summary

The China-aligned state-sponsored threat actor FamousSparrow has been deploying a new modular C++ backdoor named SparroWocky in targeted cyber espionage attacks across Latin America since at least August 2025. The malware, which replaces the group's previous SparrowDoor implant, supports command execution, file exfiltration, periodic screenshots, and acts as a TCP proxy. It uses anti-analysis techniques and integrates open-source tools like Mbed TLS, MinHook, and COFF Loader for secure communications, evasion, and in-memory plugin execution. Targets include governmental entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela, with 90% of observed activity focused on the region.

AI-extracted · verify before operational use

Extracted Entities 3 found

Indicators of Compromise 1 extracted

Type Value Detail
IP 216[.]238[.]110[.]120 Details →

MITRE ATT&CK TTPs 38 techniques

T1003 OS Credential Dumping · Credential Access T1003.001 LSASS Memory · Credential Access T1013 T1013 T1021.001 Remote Desktop Protocol · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1048 Exfiltration Over Alternative Protocol · Exfiltration T1055 Process Injection · Defense Evasion T1055.001 Dynamic-link Library Injection · Defense Evasion T1059.001 PowerShell · Execution T1071.001 Web Protocols · Command And Control T1074 Data Staged · Collection T1078 Valid Accounts · Defense Evasion T1078.002 Domain Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1087.002 Domain Account · Discovery T1090 Proxy · Command And Control T1095 Non-Application Layer Protocol · Command And Control T1098.002 Additional Email Delegate Permissions · Persistence T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1110.001 Password Guessing · Credential Access T1120 Peripheral Device Discovery · Discovery T1133 External Remote Services · Persistence T1136.001 Local Account · Persistence T1190 Exploit Public-Facing Application · Initial Access T1210 Exploitation of Remote Services · Lateral Movement T1482 Domain Trust Discovery · Discovery T1499 Endpoint Denial of Service · Impact T1543.001 Launch Agent · Persistence T1548 Abuse Elevation Control Mechanism · Privilege Escalation T1556.004 Network Device Authentication · Credential Access T1558 Steal or Forge Kerberos Tickets · Credential Access T1566 Phishing · Initial Access T1571 Non-Standard Port · Command And Control T1574.001 DLL Search Order Hijacking · Persistence T1574.002 DLL Side-Loading · Persistence T1665 Hide Infrastructure · Command And Control