FamousSparrow SparroWocky backdoor activity against Latin American governments
Malware Activity
Summary
Hide ▲
Show ▼
The FamousSparrow espionage group is using the new SparroWocky backdoor to target government organizations in Latin America, extending a long-running intrusion operation. ESET observed the malware across Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela and said it has been active for more than a year. The implant is built for stealth, persistence, remote execution, file manipulation, and in-memory loading, making the operation harder to detect and disrupt.
Related Happenings
FamousSparrow SparroWocky Latin America government espionage campaign
Campaign
H score32
First: 17.09.2026 12:00
Last: 17.09.2026 12:00
Sources 1
How related:
The operations have been ongoing for more than a year, with the new malware replacing the previously used SparrowDoor custom backdoor.
About this happening:
The FamousSparrow espionage campaign has shifted to SparroWocky, a new backdoor used against government organizations in Latin America. The operation has been active f...
FamousSparrow SparroWocky Latin America government espionage campaign
CampaignHow related: The operations have been ongoing for more than a year, with the new malware replacing the previously used SparrowDoor custom backdoor.
About this happening: The FamousSparrow espionage campaign has shifted to SparroWocky, a new backdoor used against government organizations in Latin America. The operation has been active f...
Earth Lusca Operation FishMedley espionage campaign
Campaign
H score38
First: 16.06.2026 12:44
Last: 16.06.2026 12:44
Sources 1
About this happening:
A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
Earth Lusca Operation FishMedley espionage campaign
CampaignAbout this happening: A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
Webworm multi-country targeting campaign against government and enterprise victims
Campaign
H score38
First: 20.05.2026 15:51
Last: 20.05.2026 15:51
Sources 1
About this happening:
Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...
Webworm multi-country targeting campaign against government and enterprise victims
CampaignAbout this happening: Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...
GopherWhisper China-aligned APT campaign targeting Mongolian government institutions
Campaign
H score30
First: 23.04.2026 12:04
Last: 23.04.2026 12:04
Sources 1
About this happening:
The GopherWhisper campaign is a China-aligned APT operation targeting Mongolian governmental institutions, and it now appears to extend beyond a single compromise to *...
GopherWhisper China-aligned APT campaign targeting Mongolian government institutions
CampaignAbout this happening: The GopherWhisper campaign is a China-aligned APT operation targeting Mongolian governmental institutions, and it now appears to extend beyond a single compromise to *...
APT28 BEARDSHELL and COVENANT surveillance activity against Ukrainian military personnel
Malware Activity
H score23
First: 10.03.2026 12:55
Last: 10.03.2026 12:55
Sources 1
About this happening:
The APT28 operation has expanded into BEARDSHELL and COVENANT implants used for long-term surveillance of Ukrainian military personnel, indicating an active es...
APT28 BEARDSHELL and COVENANT surveillance activity against Ukrainian military personnel
Malware ActivityAbout this happening: The APT28 operation has expanded into BEARDSHELL and COVENANT implants used for long-term surveillance of Ukrainian military personnel, indicating an active es...
Timeline
-
17.09.2026 12:00 2 articles · 1h ago
FamousSparrow deploys SparroWocky against Latin American government organizations
Initial DisclosureFamousSparrow is using the new SparroWocky backdoor in espionage attacks against government organizations in Latin America, replacing the previously used SparrowDoor custom backdoor. ESET observed the malware in organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela, and said the operation has been ongoing for more than a year with Latin America as the primary focus from mid-2025. The implant is a modular C++ backdoor that uses DLL side-loading, RC4-encoded .dat payloads, persistence through a Windows service or registry key, and thread-start spoofing via the MinHook library.
Show sources
- Chinese hackers use SparroWocky malware in govt espionage attacks — www.bleepingcomputer.com — 17.09.2026 12:00
- Chinese hackers use SparroWocky malware in govt espionage attacks — www.bleepingcomputer.com — 17.09.2026 12:00