China-linked spies that spent years inside telecommunications and government networks have moved their weight to Latin America, and they brought a fresh backdoor with them.
ESET, which tracks the cluster as FamousSparrow, says 90 percent of the group’s targets from mid-2025 into 2026 sat in Central and South America. The new implant, SparroWocky, appeared in August 2025 against government agencies in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela.
It is a modular C++ backdoor stitched together from open source parts: Mbed TLS for the encrypted channel to its command server, MinHook to disguise the start address of new threads, and a COFF loader for plugins executed in memory. It adds a variant of the SilentMoonwalk technique to spoof call stacks and a custom API-hashing algorithm to resolve Windows functions quietly. Researchers found the first stanza of Lewis Carroll’s Jabberwocky in several samples, which is where the name comes from.
Delivery follows the group’s usual trident loader: a legitimate executable, a malicious DLL and an encrypted payload file, with the loader running through DLL side-loading. Once connected, close to 30 commands cover reconnaissance, file theft and deletion, screenshots, session enumeration and spawning new copies of itself. Traffic is TLS to hard-coded IP addresses, usually on port 443.
ESET reads the pivot as China positioning to watch how regional governments answer renewed US pressure over energy, mining and telecoms. Hard-coded command servers and side-loaded DLL pairs are the artifacts to hunt.
