MalwareTips News SparroWocky backdoor targets government networks across Latin America

Security News
0 Replies 172 Views

Do you regularly use a computer to access government or public-service websites?

  • Yes, often

    Votes: 0 0.0%
  • Sometimes

    Votes: 1 33.3%
  • Rarely

    Votes: 1 33.3%
  • I do not use them

    Votes: 1 33.3%
  • I am not sure

    Votes: 0 0.0%

  • Total voters
    3

News Now

Happening Now
Verified
Government organizations in Latin America are being targeted with SparroWocky, a new Windows backdoor linked to the China-aligned FamousSparrow group. The malware can steal files, take screenshots, run commands and use an infected computer to relay network traffic.

Government entities are the main targets​

ESET Research says SparroWocky has been deployed in Latin America since at least August 2025. From mid-2025 into 2026, 90% of FamousSparrow targets visible in its telemetry were in the region.

Observed targets included government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela. ESET attributes the campaign to FamousSparrow with high confidence, partly because the group's older SparrowDoor malware deployed SparroWocky in some early attacks.

What a successful infection allows​

SparroWocky is a separate malware family rather than a new SparrowDoor version. It is a modular backdoor, meaning attackers can remotely control an infected Windows system and extend what the malware can do.

  • Collect the computer name, username, domain, Windows version and network addresses.
  • Run commands and arbitrary files, steal files, and capture screenshots periodically.
  • Act as a TCP proxy, allowing attackers to relay network traffic through the compromised machine.
  • Load Beacon Object Files, small in-memory modules commonly supported by security-testing tools but also useful to intruders.

Checks for potentially affected networks​

This campaign is narrowly focused on high-profile organizations rather than ordinary home users. IT teams in government bodies and related organizations in the named countries should review endpoint and network alerts, especially where internet-facing systems or administrator accounts may have been compromised.

  • Look for a Windows service named ProcAuditManager, described as tracking process creation, termination and related audit events.
  • Check for an autorun value named SnapCart under SOFTWARE\Microsoft\Windows\CurrentVersion\Run.
  • Investigate unexpected connections to 216.238.110[.]120 on port 443 in historical logs.
  • If any indicator is found, isolate the computer and preserve logs before removing persistence or rebuilding the system.
 
Community
Security tip
Include the small essentials. Alongside documents and photos, keep recoverable copies of important settings and license information. Avoid putting unprotected passwords in a general backup folder.
Back
Top