Chinese APT FamousSparrow deploys new SparroWocky backdoor against Latin American governments
ESET researchers report that the Chinese-linked espionage group FamousSparrow shifted in mid-2025 to focus exclusively on government targets in Central and South America, replacing its older SparrowDoor malware with a newly built implant called SparroWocky. The group, loosely tied to Earth Estries and Salt Typhoon, appears to be zeroing in on agencies overseeing Chinese investments now under scrutiny from the Trump administration.