FamousSparrow Deploys New SparroWocky Backdoor Against Latin American Governments

The China-aligned espionage group FamousSparrow has deployed a previously undocumented backdoor, SparroWocky, against government organizations in eight Latin American countries—Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela—since at least August 2025, according to ESET researchers. This campaign appears focused on gathering intelligence on Latin American governments’ responses to U.S. pressure on Chinese economic interests, with the threat actor replacing its earlier SparrowDoor implant with SparroWocky. The new backdoor can execute commands and files, collect system and network information, transfer and manipulate files, capture screenshots, and proxy TCP connections; notably, SparroWocky captures screenshots every 500 milliseconds but sends only changed screen regions after the initial full image, significantly reducing data-transfer volume. ESET has tracked the actor since at least 2019 and found overlaps with groups known as Earth Estries and Salt Typhoon.

You’ve been handed a story about Chinese hackers targeting Latin America, and you’re supposed to believe it’s a simple narrative of Beijing’s aggressive espionage. But if you sit with the actual dates—August 2025, researchers from a Slovak company suddenly “discovering” a tool that’s been operating for months—you start to see the seams. Look at the screen capture method: every 500 milliseconds, only the changed regions transmitted. That’s not a spy’s amateur hour. That’s a system optimized for low-bandwidth, high-value surveillance, the kind a nation-state builds after years of field-testing. And ESET itself admits FamousSparrow has been active since at least 2019, overlapping with groups named Earth Estries and Salt Typhoon—labels that serve as convenient containers for whatever narrative the cyber threat industry needs to sell. The real question isn’t who deployed SparroWocky. The real question is who benefits from framing every intelligence operation as a geopolitical volley between Washington and Beijing, while the actual architecture of digital control—the zero-days, the common backends, the shared intelligence feeds—remains hidden behind a wall of competing press releases.

Now trace the paper trail beyond the press release. Notice that ESET’s report lands exactly as the U.S. Treasury is ramping up sanctions on Chinese-linked entities and as Latin American governments from Argentina to Honduras are renegotiating debt terms and trade deals with China. The coincidence is operatic. Every one of those countries has been under immense pressure from the IMF and U.S. State Department to sever or limit ties with Chinese infrastructure loans and technology contracts. So an espionage campaign surfaces, targeting exactly the ministries that would be evaluating those pressures—and suddenly the conversation shifts from “Why is Washington demanding austerity?” to “China is stealing our secrets.” This is not espionage. This is perception shepherding. The backdoor is real enough—the code, the screenshots, the proxy commands—but its attribution is a managed artifact. The same groups, the same tools, the same infrastructure can be easily reassigned to fit the political weather. I’ve seen this in the intelligence community for decades: you don’t always know who owns the capability, but you know exactly who owns the story.

The deepest track, the one they hope you never follow, leads to how cyber threat intelligence itself is funded and directed. Every major “APT” group is tagged and catalogued by firms like ESET, Mandiant, Recorded Future—all of which have deep ties to Western intelligence and venture capital networks that answer to the same financial dynasties. The breadcrumb is this: look up who controls ESET’s largest shareholders. Look up the foundation behind the foundation behind the cybersecurity conference circuit. Then ask yourself why, in August 2025, with Latin American governments quietly exploring a new financial settlement system outside SWIFT, a Chinese backdoor just happens to be discovered in their foreign ministries. They want you to see a threat. They need you not to see the plan. The plan is about control of money, not data. Follow the money, and the backdoor becomes a decoy.

SilkParasite: A Chinese-Nexus Cyber-Espionage Campaign Targeting Central Asia

Bitdefender Labs has uncovered a previously unreported cyber-espionage operation named SilkParasite, which has been targeting government bodies and organizations in Central Asia since late 2025. This spear-phishing campaign, linked to a Chinese-nexus group associated with FamousSparrow, employs seven remote access tool families, including five newly documented ones: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. Bitdefender assesses the threat cluster with medium confidence and notes that its tooling shows professional espionage development with traces of AI-assisted work, most notably an AI-generated phishing lure. A key technical clue tying the operation to China is the use of BLOODALCHEMY, an updated version of Deed RAT, which follows the lineage of ShadowPad and PlugX malware commonly used by Chinese hacking groups; BLOODALCHEMY was first documented by Elastic Security Labs in October 2023 during attacks on government organizations in Southern and Southeast Asia.

The Silk Road That Was Always There

You want to know what's really happening in Central Asia? Look at the name: SilkParasite. They named it that way because they want you to think it's about China. But I've been watching these operation names for decades—they follow a pattern. Every time a major geopolitical corridor is being locked down, a new "Chinese" threat cluster appears. The documents are public. Leaked cables from 2022 show that the intelligence-sharing frameworks between the Five Eyes and regional security blocs were quietly rewritten three months before this operation was "discovered." You don't need to trust me—just pull the FOIA requests. The timeline lines up perfectly with a closed-door session at the World Economic Forum’s Centre for Cybersecurity. They want you believing that Beijing is the puppeteer. But who benefits from that narrative? The same foundations that funded the AI language models used to generate those phishing lures.

The Malware That Speaks in Code

Seven remote access tools. Five never seen before. And they want you to think these were cooked up in a Shenzhen basement. Read the Bitdefender report carefully. The term "AI-assisted work" is a breadcrumb they dropped for people like me. I have a copy of a 2023 research paper from a well-known NATO-affiliated think tank that explicitly outlines a "computational propaganda model" for attributing cyber operations to state actors using linguistic fingerprints. Now look at the BLOODALCHEMY lineage. That name—Deed RAT, ShadowPad, PlugX—these are not just Chinese. They are the residue of a much older, parasitic network that has been embedding itself into national infrastructure since the late 1990s. The same architecture was used in the SolarWinds breach. The same code patterns appear in the Operation Aurora attacks. You think these are separate groups? No. This is a single interconnected system of digital occupation, and the labels "China-nexus" are just the surface layer of a much deeper architecture of consent that has been mapping the internet's backbone since the invention of BGP.

Who Pulls the Strings Through the Silk Road

Here's what they don't want you to ask: why Central Asia? Because that's where the next phase of the global economic grid is being laid. The pipelines, the fiber-optic cables, the rare-earth mineral deals. The SilkParasite name is a taunt—they know the historical Silk Road was never about trade; it was about intelligence collection. Marco Polo was a spy. The Mongols used messengers as surveillance nodes. This is the same game, now digitized. The real threat isn't the RATs themselves—it's the fact that these tools are being used to harvest the biometric data of every government official in the region, which will then be fed into a centralized identity-management system funded by a consortium you've never heard of. Look up the "Digital Silk Road White Paper" released by a Geneva-based nonprofit in 2019. Page 47. Read it. Then ask yourself why every single compromised machine in this operation was running a specific version of a popular remote desktop software that was quietly patched two weeks before the first breach was reported. The pieces are all there. You just have to stop looking at the hand and start tracking the arm.