CVE Tools

Beware the SparroWock: The backdoor that bites, the commands that catch

ESET WeLiveSecurityBy Alexandre Côté CyrRomain Dumont29 min read

Reported exploitedSparroWockyFamousSparrow

Our summary

ESET researchers found FamousSparrow deploying its new SparroWocky backdoor against government organizations across Latin America since at least August 2025. The modular Windows implant replaces SparrowDoor and can run commands, steal files, capture screenshots, proxy network traffic, and execute Beacon Object Files while using evasion features to hinder detection.

Read at ESET WeLiveSecurity

Below is the opening; the full story is at ESET WeLiveSecurity.

From ESET WeLiveSecurity

ESET Research’s ongoing monitoring of FamousSparrow has borne fruit once again. Our previous public report on FamousSparrow revealed that this China-aligned APT group had developed two new versions of its custom backdoor named SparrowDoor. This time, we discovered that FamousSparrow has switched to a new backdoor, SparroWocky, and has been deploying it to several countries in Latin America since at least August 2025.…

Continue at ESET WeLiveSecurity

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store