Executive Summary
Since at least August 2025, the China-aligned espionage group FamousSparrow (linked to Earth Estries) has pivoted its targeting almost exclusively to government organizations in Latin America. This campaign utilizes a new flagship C++ backdoor named SparroWocky, which has largely replaced the group's previous custom malware, SparrowDoor. The activity is suspected to be a strategic response to increasing U.S. economic and diplomatic pressure in the region, aimed at monitoring local government responses to these shifts.
SparroWocky is highly sophisticated, utilizing modular architecture and several advanced evasion techniques to bypass security products. It is typically deployed via a trident loader scheme involving DLL side-loading and reflective memory mapping. The malware is capable of extensive data exfiltration, screen monitoring every 500ms, and the execution of Beacon Object Files (BOFs), allowing the group to leverage a wide range of red-teaming tools. Victims have been identified across Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.
This threat represents a significant risk to government entities in the Latin American region. The group's ability to manipulate low-level Windows structures, spoof call stacks, and mask thread start addresses indicates a high level of technical proficiency. Organizations in the targeted region and sectors should prioritize monitoring for DLL side-loading artifacts and anomalous outbound TLS traffic to the identified C2 infrastructure.
Key Details
Threat Name
SparroWocky Malware
Affects
Microsoft Exchange Server
Adversary
FamousSparrow Other Adversaries and Aliases: Chinese Fire Ant
MITRE Techniques
Malware/Tools
SparroWocky, SparrowDoor
