ESET traces the new C++ implant, SparroWocky, to government targets in at least eight Latin American countries. Roughly 90% of the group's 2025–26 activity now sits in the region.
FamousSparrow, a China-aligned hacking group publicly linked by The Wall Street Journal to Salt Typhoon, has retired the implant it once rode into government networks. Its replacement, called SparroWocky, is a modular C++ backdoor that ESET researchers first detailed on September 17. It is showing up across at least eight Latin American countries, and the engineering choices inside it tell a different story from the wire-service headlines: the operator knows it is being watched, and has rebuilt the tool accordingly.
ESET researchers Alexandre Côté Cyr and Romain Dumont, who track the group as a distinct threat actor, report deployments against governmental entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The group, ESET said in its press release, has focused almost exclusively on Latin America since July 2025. From mid-2025 into 2026, roughly 90% of FamousSparrow's observed targets now sit in the region.
The malware is built to look like nothing. The kill chain starts with a legitimate executable that loads a malicious DLL through sideloading. That DLL decrypts the main payload and hands off to a COFF loader, which streams additional plugins directly into memory rather than writing them to disk. The plugins include Beacon Object Files, the same building blocks that Cobalt Strike operators chain together for post-exploitation work. Once running, SparroWocky uses MinHook, a publicly available library, to intercept thread-creation calls and rewrite the call stacks its own routines produce. A security tool that hooks into the malware's execution then sees a stack that looks like the operating system did the work, not the implant.
That stack-spoofing step signals an operator that knows defenders are watching, and that has budgeted the engineering time to look unwatched anyway. ESET credits the technique to a variant of the SilentMoonwalk and StackMoonwalk approaches, both of which were published openly before FamousSparrow adopted them. The codename is a Lewis Carroll tell: ESET named the family for the first stanza of "Jabberwocky" found in early samples.
ESET's earlier research on the group ran on the name SparrowDoor. The 2021 first writeup named hotels, governments, and INGOs as targets. By 2026, the same group's telemetry shows a different operational shape. FamousSparrow still hits governments, but the geographic center of gravity has shifted south, and the implant has been rebuilt around modular, in-memory execution.
The attribution argument is the part ESET will not paper over. The Wall Street Journal previously linked FamousSparrow to Salt Typhoon, the Chinese state-aligned cluster blamed for the 2024 and 2025 US telecom wiretap intrusions. Trend Micro has separately linked the group to a cluster it calls Earth Estries. ESET does neither. Côté Cyr and Dumont, in their writeup, say ESET tracks FamousSparrow as a separate group because the technical indicators do not overlap with Salt Typhoon's known toolset. The dispute is not about geography. It is about whether the two clusters share operators and infrastructure, or just playbooks.
The geopolitical read sits on top of that uncertainty, and it is ESET's interpretation, not a confirmed motive. The researchers argue that the Latin American pivot is most likely a reaction to renewed US interest in the region under President Trump's second term, and to commercial pressure on Chinese investments in Latin American energy, mining, and telecoms. The Panama target observed in ESET's data lines up with a live dispute over canal-area port concessions once operated by a China-based company whose contract was challenged in early 2025. Initial access for SparroWocky remains unconfirmed; ESET does not name a vector.
The convergence is what makes the timing worth a second look. A group publicly named in one of the most-watched US telecom compromises of the decade has, in the same year, refactored its flagship implant, retargeted an entire hemisphere, and shipped anti-forensic upgrades tuned to evade the very vendors that published the original indictments. The malware family is new. The operational continuity is not.