Chinese hackers use SparroWocky malware in govt espionage attacks
AI Summary
The China-linked threat actor FamousSparrow has been conducting espionage campaigns against government organizations in Latin America since mid-2025, using a new modular C++ backdoor named SparroWocky. This malware replaces the group's previously used SparrowDoor backdoor and is deployed via DLL side-loading, with payloads RC4-encoded in .dat files. SparroWocky features advanced evasion techniques, including thread creation hooking to spoof legitimate Windows functions, in-memory code manipulation, and anti-analysis tricks, enabling command execution, file manipulation, screenshot capture, and proxy capabilities. The malware establishes persistence via a Windows service or registry key and communicates with C2 servers over ports 443 or 8080, sometimes through HTTP and SOCKS5 proxies.
AI-extracted · verify before operational use