Alleged Chinese hackers are targeting Latin American government agencies with a new backdoor called “SparroWocky,” according to ESET researcher Alexandre Côté Cyr. Since August 2025, the campaign has affected countries including Guatemala, Honduras, Puerto Rico, Panama, Venezuela, Peru, and Argentina. This long-running operation, linked to the Chinese group FamousSparrow, is unusual because Chinese cyber espionage usually targets multiple regions simultaneously. ESET suggests the campaign aims to monitor U.S. influence in Latin America, especially as the U.S. under Trump has increased pressure on Chinese investments in the region. One Panama target involved in a dispute over ports is notable, as Trump has sought to challenge Chinese control of port operations and the Panama Canal.
The malware, named SparroWocky after the “Jabberwocky” poem by Lewis Carroll, is sophisticated and designed to hinder analysis. It can exfiltrate files, take screenshots, and gather system info like IP addresses and usernames. The campaign has been active since at least 2019, initially targeting hotels before shifting focus to governments, trade groups, and international organizations. FamousSparrow, the group behind the campaign, has been linked to Salt Typhoon, a Chinese cyber espionage operation accused of breaching U.S. government and corporate targets.

