A China-linked hacking group called FamousSparrow is using a new backdoor named SparroWocky to target multiple countries in Latin America since August 2025. ESET researchers say it's modular and built in C++. Here's what you need to know.
Imagine waking up to find a silent intruder has been living in your network for months. That's basically what's happening across Latin America right now. A hacking group called FamousSparrow, which security experts link to China, has been quietly breaking into systems using a brand-new backdoor. They call it SparroWocky. And it's been active since at least August 2025.
Security researchers Alexandre Côté Cyr and Romain Dumont from ESET shared the details in a technical report. According to them, "SparroWocky is a modular, C++ backdoor." In plain English, that means it's built to be flexible and hard to detect. Think of it like a Swiss Army knife for cyber spies. They can add or remove tools depending on what they need to do.
### What Exactly Is SparroWocky?
It's a backdoor, which is a type of malware that gives attackers secret remote access to a computer. Once it's inside, they can steal files, watch what you're doing, or jump to other machines on the same network. The "modular" part means it's not a single fixed program. Instead, it's made of different pieces that can be swapped in and out.
The C++ part is just the programming language used to build it. That matters because C++ code tends to run fast and can be compiled for different systems, making it easier for attackers to target both Windows and Linux machines. So far, the attacks have hit multiple countries in Latin America, but ESET hasn't named specific victims.
### Why Latin America?
That's the million-dollar question. State-sponsored groups often go after regions where they see strategic value. Latin America has growing economies, lots of infrastructure projects, and sometimes weaker cybersecurity defenses compared to North America or Europe. It's a soft target with plenty of valuable data.
Plus, many companies in the region work with international partners, so a breach there can be a stepping stone to bigger targets. FamousSparrow has been active since at least 2019, mainly hitting hotels and government offices. Now they're expanding their playground.
### How Does This Affect You?
If you're in the U.S., you might think this is someone else's problem. But supply chains are global. A compromised vendor in Brazil or Mexico could easily have connections to U.S. companies. And the same tactics could be used closer to home.
The good news? You don't have to be a sitting duck. Here are a few practical steps:
- Keep all software and operating systems updated. Those patches aren't just suggestions.
- Use multi-factor authentication everywhere. It's not bulletproof, but it stops a lot of lazy attacks.
- Train your team to spot phishing emails. That's still the number one way these groups get in.
- Consider network monitoring tools that can flag unusual outbound traffic. Backdoors love to phone home.
### What's Next for FamousSparrow?
ESET's report suggests this is an ongoing campaign. The group is likely refining SparroWocky and may expand to other regions. The fact that they're using a modular backdoor shows they're investing in long-term access, not just smash-and-grab attacks.
Security researchers are sharing indicators of compromise with the community, so defenders can check if they've been hit. If you run a security team, keep an eye on ESET's updates and any new signatures they release.
> "The quiet ones are always the most dangerous. They don't want you to notice until it's too late."
That quote sums up the threat. FamousSparrow isn't looking for headlines. They want persistence. And SparroWocky is their latest tool for staying hidden.
So, what can you do today? Start by assuming you could be a target. Review your logs, tighten your access controls, and talk to your team about the risks. It's not about paranoia. It's about being prepared. Because in this game, the attackers only need to be right once. You need to be right every time.