:

CHINESE HACKERS DEPLOY SPARROWOCKY IN GOVT ATTACKS

SECURITY DESK2 MIN READ
THU, SEP 17, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Chinese espionage group FamousSparrow is using a new backdoor malware called SparroWocky to target government organizations across Latin America.

The China-linked threat actor FamousSparrow has deployed SparroWocky, a previously undocumented backdoor, in targeted attacks against government entities in the Latin American region. SparroWocky represents an expansion of FamousSparrow's arsenal, enabling the group to establish persistent access to compromised systems. The malware functions as a backdoor, allowing attackers to execute commands, exfiltrate data, and maintain long-term presence on infected networks. Government organizations in Latin America are the primary targets, suggesting the campaign is focused on geopolitical intelligence gathering and espionage operations. The timing and targeting pattern align with broader Chinese state-sponsored cyber espionage activity documented in recent years. FamousSparrow, also tracked by security researchers under alternative designations, has been attributed to Chinese intelligence services. The group maintains a history of targeting diplomatic, government, and critical infrastructure sectors across multiple regions. The deployment of SparroWocky indicates FamousSparrow continues to develop new tools to evade detection and maintain operational effectiveness. Security researchers have identified specific technical characteristics of the malware that distinguish it from previously known variants used by the group. Organizations in targeted regions are advised to implement enhanced monitoring for suspicious command execution, unusual network connections, and indicators of backdoor activity. Network segmentation, endpoint detection and response (EDR) solutions, and regular security audits are recommended as defensive measures. The discovery follows an uptick in Chinese state-sponsored cyber operations against Latin American governments, reflecting strategic interest in the region. Cybersecurity agencies in affected countries have been notified and are coordinating response efforts. Additional technical analysis of SparroWocky continues, with researchers working to identify overlaps with other malware families and refine attribution confidence.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

License plate camera company Flock Safety once promoted its devices as American-made, but the company now provides little clarity on where cameras are actually assembled. The shift raises questions about supply chain transparency and potential cybersecurity risks.

JUST NOWIndustry Desk

A reverse-engineering enthusiast has successfully broken Sony's original PlayStation 2 security chip after four years of effort. The CXP102064 MechaCon chip, which protected the console from unauthorized software, has been fully unlocked.

1H AGOSecurity Desk

Cisco has released security updates for a critical Identity Services Engine vulnerability being actively exploited by attackers. The zero-day flaw carries a CVSS score of 10.0, indicating maximum severity.

2H AGOSecurity Desk

A security researcher has successfully recovered the cryptographic signing keys used to secure barcodes on US driver's licenses. The discovery exposes a potential vulnerability in state ID verification systems nationwide.

3H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.