# ESET reports SparroWocky backdoor in Latin American government attacks

_Published Thursday, September 17, 2026 at 6:07 AM EDT · Security · Latest · Tier 1 — Major_

![ESET reports SparroWocky backdoor in Latin American government attacks — Primary](https://www.bleepstatic.com/content/hl-images/2026/04/23/China.jpg)

ESET researchers said China-linked FamousSparrow has used a new backdoor, SparroWocky, against government organizations in eight Latin American jurisdictions. The researchers said the operations have continued for more than a year and that the malware replaced SparrowDoor. SparroWocky can execute commands, collect system and user data, manipulate files, capture changing screen regions and proxy connections. ESET said it is deployed through DLL side-loading after a loader decrypts an RC4-encoded payload and maps it in memory.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/chinese-hackers-use-sparrowocky-malware-in-govt-espionage-attacks/)

---
Canonical: https://techandbusiness.org/newswire/QvTXMovhbWgpk8BNCuLCDA
Published: 2026-09-17T10:07:25.622Z
Story chronology: 2026-09-17T09:00:00.000Z
Retrieved: 2026-09-17T12:17:06.108Z
Publisher: Tech & Business (techandbusiness.org)
