China-linked group FamousSparrow targets Latin American governments with new backdoor
AI-generated from multiple sources. Verify before acting on this reporting.
A China-linked espionage group known as FamousSparrow has deployed a new malware backdoor named SparroWocky in a coordinated campaign against government organizations across Latin America. The operation, detected on Sept. 17, 2026, marks an escalation in state-sponsored cyber activity aimed at gathering intelligence on regional responses to intensifying U.S. economic pressure on Chinese interests.
The attacks have targeted critical infrastructure and administrative networks in eight jurisdictions: Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. Security analysts identified SparroWocky as a sophisticated tool designed to maintain persistent access within compromised systems, allowing the group to monitor communications and data flows without immediate detection.
The timing of the intrusion coincides with heightened diplomatic friction between Washington and Beijing regarding trade policies and investment restrictions in the Western Hemisphere. Intelligence indicates that FamousSparrow is specifically focused on understanding how Latin American governments are adjusting their economic strategies in reaction to U.S. measures designed to limit Chinese market access. The group appears intent on mapping political decision-making processes and identifying potential vulnerabilities in regional alliances.
FamousSparrow has previously been linked to espionage operations targeting government entities, but the deployment of SparroWocky represents a distinct technical evolution. The backdoor utilizes novel methods to evade standard security protocols, suggesting significant investment in the group's cyber capabilities. While the specific objectives within each country remain under investigation, the breadth of the campaign suggests a broad strategic interest rather than isolated incidents.
Government officials in the affected nations have not yet issued public statements regarding the extent of the compromise or the specific data accessed. However, cybersecurity firms note that the group has been active since early 2026, with recent activity spiking as U.S.-China economic tensions reached new levels. The campaign underscores the growing role of cyber espionage in shaping geopolitical outcomes in Latin America.
Questions remain regarding the full scope of the data exfiltrated and whether other regions are currently under similar attack. As governments work to patch vulnerabilities and remove the backdoor, experts warn that FamousSparrow may continue to refine its tactics to maintain access or pivot to new targets. The incident highlights the increasing complexity of state-sponsored cyber operations in an era of intensifying global economic competition.