Skip to content
Tech News
← Back to articles

Chinese hackers use SparroWocky malware in govt espionage attacks

read original more articles
Why This Matters

This report highlights how a China-linked espionage group, FamousSparrow, is using a sophisticated new backdoor called SparroWocky to spy on Latin American government agencies amid rising U.S.-China economic tensions. The attack showcases increasingly advanced evasion and anti-detection techniques, underscoring the growing sophistication of state-sponsored cyber espionage and the risks facing governments worldwide.

Key Takeaways

The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America.

The operations have been ongoing for more than a year, with the new malware replacing the previously used SparrowDoor custom backdoor.

ESET researchers observed SparroWocky in attacks targeting organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.

The researchers believe the threat actor's objective was to collect intelligence on Latin American governments’ responses to increasing U.S. pressure on Chinese economic interests.

FamousSparrow victims

Source: ESET

ESET's analysis revealed that SparroWocky is a modular, full-blown C++ backdoor that includes code from open-source projects.

The malware features anti-analysis mechanisms, like manipulating low-level structures in memory and patching code at runtime. SparroWocky's capabilities include:

run commands and executable files

load and execute Beacon Object Files in memory

... continue reading