The China-linked espionage group FamousSparrow has replaced its longtime SparrowDoor implant with a new, more evasive backdoor called SparroWocky, according to research from ESET. The malware has been used in government-targeted attacks across Latin America for more than a year.

ESET identified victims in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. Researchers assess the campaign’s likely goal was intelligence collection on how Latin American governments are responding to increasing US economic pressure on Chinese interests. Telemetry shows FamousSparrow has focused primarily on the region since mid-2025.

A modular C++ backdoor built for stealth

SparroWocky is a full-featured, modular backdoor written in C++ that incorporates code from open-source projects. Its capabilities include executing commands and files, loading Beacon Object Files directly into memory, harvesting system and network details, enumerating drives and active sessions, manipulating files, taking rapid screenshots that transmit only changed screen regions, spawning processes in another user’s session, and acting as a TCP proxy.

The malware is deployed via DLL side-loading, with a loader decrypting an RC4-encoded payload from a .dat file and mapping it directly into memory to avoid detection. ESET found the backdoor employs call stack and thread origin spoofing, dynamic API resolution, and disguises malicious code as legitimate Windows components.

Hiding malicious threads

One notable evasion technique involves hooking the CreateThread function using the MinHook library to conceal the true starting address of malicious threads. Every thread created by SparroWocky is made to appear as though it originates from the legitimate AnimateWindow function, a trick designed to slip past security products that flag suspicious thread origins.

Persistence is established either through a Windows service named ProcAuditManager or a registry key called SnapCart, placed under HKLM or HKCU depending on the privilege level obtained. ESET says the malware’s architecture and anti-analysis tricks reflect strong knowledge of Windows internals, consistent with attribution to a well-resourced, experienced threat actor.

Command and control infrastructure

Researchers identified at least 18 command-and-control addresses communicating with infected systems directly over ports 443 and 8080, or through HTTP and SOCKS5 proxies. ESET has published a full technical breakdown of SparroWocky along with indicators of compromise for defenders.

Government agencies and organizations in the affected countries should review network logs for the shared IoCs, monitor for unusual DLL side-loading activity, and inspect for the specific persistence artifacts named above.