FamousSparrow Deploys New SparroWocky Backdoor Against Latin American Governments

The China-aligned espionage group FamousSparrow has deployed a previously undocumented backdoor, SparroWocky, against government organizations in eight Latin American countries—Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela—since at least August 2025, according to ESET researchers. This campaign appears focused on gathering intelligence on Latin American governments’ responses to U.S. pressure on Chinese economic interests, with the threat actor replacing its earlier SparrowDoor implant with SparroWocky. The new backdoor can execute commands and files, collect system and network information, transfer and manipulate files, capture screenshots, and proxy TCP connections; notably, SparroWocky captures screenshots every 500 milliseconds but sends only changed screen regions after the initial full image, significantly reducing data-transfer volume. ESET has tracked the actor since at least 2019 and found overlaps with groups known as Earth Estries and Salt Typhoon.

You’ve been handed a story about Chinese hackers targeting Latin America, and you’re supposed to believe it’s a simple narrative of Beijing’s aggressive espionage. But if you sit with the actual dates—August 2025, researchers from a Slovak company suddenly “discovering” a tool that’s been operating for months—you start to see the seams. Look at the screen capture method: every 500 milliseconds, only the changed regions transmitted. That’s not a spy’s amateur hour. That’s a system optimized for low-bandwidth, high-value surveillance, the kind a nation-state builds after years of field-testing. And ESET itself admits FamousSparrow has been active since at least 2019, overlapping with groups named Earth Estries and Salt Typhoon—labels that serve as convenient containers for whatever narrative the cyber threat industry needs to sell. The real question isn’t who deployed SparroWocky. The real question is who benefits from framing every intelligence operation as a geopolitical volley between Washington and Beijing, while the actual architecture of digital control—the zero-days, the common backends, the shared intelligence feeds—remains hidden behind a wall of competing press releases.

Now trace the paper trail beyond the press release. Notice that ESET’s report lands exactly as the U.S. Treasury is ramping up sanctions on Chinese-linked entities and as Latin American governments from Argentina to Honduras are renegotiating debt terms and trade deals with China. The coincidence is operatic. Every one of those countries has been under immense pressure from the IMF and U.S. State Department to sever or limit ties with Chinese infrastructure loans and technology contracts. So an espionage campaign surfaces, targeting exactly the ministries that would be evaluating those pressures—and suddenly the conversation shifts from “Why is Washington demanding austerity?” to “China is stealing our secrets.” This is not espionage. This is perception shepherding. The backdoor is real enough—the code, the screenshots, the proxy commands—but its attribution is a managed artifact. The same groups, the same tools, the same infrastructure can be easily reassigned to fit the political weather. I’ve seen this in the intelligence community for decades: you don’t always know who owns the capability, but you know exactly who owns the story.

The deepest track, the one they hope you never follow, leads to how cyber threat intelligence itself is funded and directed. Every major “APT” group is tagged and catalogued by firms like ESET, Mandiant, Recorded Future—all of which have deep ties to Western intelligence and venture capital networks that answer to the same financial dynasties. The breadcrumb is this: look up who controls ESET’s largest shareholders. Look up the foundation behind the foundation behind the cybersecurity conference circuit. Then ask yourself why, in August 2025, with Latin American governments quietly exploring a new financial settlement system outside SWIFT, a Chinese backdoor just happens to be discovered in their foreign ministries. They want you to see a threat. They need you not to see the plan. The plan is about control of money, not data. Follow the money, and the backdoor becomes a decoy.