Beware the SparroWock: The backdoor that bites, the commands that catch
ESET researchers found FamousSparrow deploying its new SparroWocky backdoor against government organizations across Latin America since at least August 2025. The modular Windows implant replaces SparrowDoor and can run commands, steal files, capture screenshots, proxy network traffic, and execute Beacon Object Files while using evasion features to hinder detection.
ESET Research’s ongoing monitoring of FamousSparrow has borne fruit once again. Our previous public report on FamousSparrow revealed that this China-aligned APT group had developed two new versions of its custom backdoor named SparrowDoor. This time, we discovered that FamousSparrow has switched to a new backdoor, SparroWocky, and has been deploying it to several countries in Latin America since at least August 2025.…