Home Β· Wiki Β· Incidents & Campaigns
type: incident Β· created: 2026-09-18 Β· updated: 2026-09-18 Β· tags: [incident, defence] Β· confidence: high Β· severity: critical Β· affected_sectors: [defence] Β· au_impact: true

The China-aligned state-sponsored group FamousSparrow has been observed deploying a previously unreported Windows backdoor, SparroWocky, against government agencies across Latin America since at least August 2025, according to ESET. The modular C++ backdoor β€” named for the "Jabberwocky" stanza found in early samples β€” can execute arbitrary files, act as a TCP proxy, run commands, capture screenshots, exfiltrate files and delete itself, and it integrates open-source offensive tooling (Mbed TLS, MinHook, COFF Loader, SilentMoonwalk) directly into the implant to evade analysis. Initial access is via a DLL-sideloading chain; the underlying access vector is unknown. ESET recorded targets in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela, with roughly 90 per cent of the group's telemetry targets in the region since July 2025 β€” a rare, almost region-exclusive focus that ESET theorises is aimed at helping China monitor local government reactions to Trump-era US pressure, including the Panama canal-port dispute. FamousSparrow, active since at least 2019 and publicly linked to Salt Typhoon, has replaced SparrowDoor with SparroWocky as its primary implant.

Attribute Detail
Sector Defence
Date 2026-09-18
Source ESET
Reliability Tier 1