Chinese-linked hackers associated with the FamousSparrow espionage group are using a previously unreported backdoor called SparroWocky in attacks targeting government organizations across Latin America. Multiple reports describe the activity as part of government-focused intrusion campaigns, with deployments occurring across more than one country.

Security researchers say SparroWocky is modular and is implemented as a C++ backdoor. ESET researchers, cited across coverage, characterize the malware as designed to support backdoor functionality within targeted environments. One outlet reports that the malware is being used in government espionage operations, while another emphasizes the broader pattern of deployment across Latin America.

The coverage aligns on the attribution to a China-aligned threat actor, the identification of SparroWocky as a new backdoor used in espionage, and the timeline indicating observed activity since at least August 2025. Differences between outlets center mainly on framing—one highlights the government espionage angle, while the other focuses on the campaign’s cross-country deployment—but both rely on the same technical reporting from researchers.