VYPR
researchPublished Sep 17, 2026· 2 sources

China's Salt Typhoon Targets Latin America with New SparroWocky Backdoor

The China-linked APT group Salt Typhoon has been observed deploying a new C++ backdoor, dubbed SparroWocky, against government agencies in Latin America since August 2025, likely to monitor US initiatives.

China-linked advanced persistent threat (APT) group Salt Typhoon, also tracked as FamousSparrow, has shifted its focus to Latin America, deploying a new sophisticated backdoor named SparroWocky against government agencies in multiple countries since at least August 2025. Researchers at ESET, who have been tracking the group, noted that approximately 90 percent of Salt Typhoon's targets were located in the region during the latter half of 2025 and into 2026.

Salt Typhoon is known for its espionage operations, aiming to gain stealthy, long-term access to victim organizations. While the group has been active since at least 2019, its previous activities were only discovered in late 2023. The recent targeting of Latin American nations, including Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela, represents a notable shift in the group's operational geography. ESET speculates this focus is a response to renewed US interests and initiatives in the region under President Donald Trump's administration, which could potentially disrupt China's long-standing investments in sectors like energy, mining, and telecommunications.

The SparroWocky backdoor, discovered by ESET's malware hunters in August 2025, is a modular C++ implant designed with evasion techniques to bypass antivirus and other security software. Its name is derived from a stanza found within the malware samples, referencing Lewis Carroll's poem 'Jabberwocky'. The backdoor integrates several open-source tools to enhance its functionality and stealth. These include Mbed TLS for secure communication with its command-and-control (C2) server, MinHook for hiding thread start addresses from security products, and a COFF Loader for dynamic loading of in-memory plugins.

To further evade detection, SparroWocky employs a variant of the SilentMoonwalk technique to spoof call stacks originating from MinHook routines, making it harder for monitoring tools to identify malicious activity. It also utilizes a custom API-hashing algorithm to dynamically resolve Windows API functions, adding another layer of obfuscation. The malware's architecture allows for modularity, enabling the execution of various plugins to expand its capabilities.

The deployment mechanism for SparroWocky follows Salt Typhoon's typical pattern: a trident loader scheme involving a legitimate executable, a malicious DLL, and an encrypted malware payload. The malicious DLL is executed via DLL side-loading, initiating the backdoor's operation. Once communication is established with the C2 server, SparroWocky can receive and execute a wide array of commands.

These commands are handled by a custom class named WinHandler and include functionalities such as gathering system details, initiating or terminating sessions, establishing persistence, stealing and deleting files, capturing screenshots, and enumerating remote sessions on the compromised system. The backdoor uses TLS encryption for its C2 communications, typically connecting directly to IP addresses on port 443, though port 8080 has also been observed. ESET has made indicators of compromise and malware samples available on their GitHub repository for further analysis.

The Chinese APT group FamousSparrow is now identified as the primary actor behind the SparroWocky backdoor campaign targeting Latin America, with researchers noting its recent shift in focus to government entities. This new intelligence clarifies the attribution for the ongoing espionage efforts, which aim to monitor US political and economic interests in the region, highlighting a strategic pivot by the long-standing cyber-espionage outfit.

Synthesized by Vypr AI
China's Salt Typhoon Targets Latin America with New SparroWocky Backdoor · VYPR