Chinese Cyber Espionage Group Targets Latin American Governments with New Malware

Chinese Cyber Espionage Group Targets Latin American Governments with New Malware

2026-09-23 global

Bratislava, Wednesday, 23 September 2026.
Cybersecurity researchers revealed that China-aligned group FamousSparrow directed 90% of its recent cyberespionage attacks at Latin American governments, using new malware amid rising geopolitical tensions over regional investments.

Technical Capabilities and Deployment Timeline

The newly identified backdoor, designated SparroWocky by ESET Research, is a modular tool written in C++ that demonstrates significant sophistication in its architecture [1][3]. Deployment of this malware began no later than August 2025, following the initiation of the broader cyberespionage campaign in July 2025 [1][2]. The tool incorporates anti-analysis techniques and integrates open-source project code to evade detection, allowing it to execute arbitrary files, proxy TCP traffic, and capture periodic screenshots of compromised systems [2][4]. Data exfiltration is handled securely for the operators, with information encrypted via RC4 and transmitted over TLS protocols to prevent interception [1][4]. Persistence on infected machines is achieved through the creation of dedicated services or modifications to Windows Registry Run keys, ensuring the malware remains active after system reboots [3][4].

Geopolitical Motivations and Target Selection

This surge in activity is widely interpreted as a strategic response to shifting geopolitical dynamics, specifically the reaffirmation of United States interests in Latin America under the second-term policies of President Donald Trump [2][5]. The campaign focuses heavily on sectors critical to Chinese economic interests, including energy, mining, and telecommunications infrastructure [1][5]. ESET telemetry reveals that 90 percent of FamousSparrow’s tracked targets were located in Latin America between mid-2025 and 2026, a concentration rare for China-aligned advanced persistent threat groups [1][2]. Specific victims include governmental entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela [1][5]. Notably, one targeted Panamanian entity was involved in a commercial dispute over port operations previously managed by a China-based company, highlighting the direct link between cyber operations and economic disputes [2][4].

Implications for Regional Security and Investment

For multinational corporations and international investors, this escalation presents heightened operational and supply chain vulnerabilities within emerging markets [1][2]. The remaining 10 percent of targets outside the region suggests that while the focus is regional, the threat actor retains global capabilities that could impact international supply chains linked to Latin American operations [1]. Security firms advise that the integration of Beacon Object Files and runtime code patching allows SparroWocky to bypass standard security software, necessitating enhanced defensive measures for organizations in the affected sectors [2][4]. As regional governments evaluate methods to reinforce digital defenses, the overlap between cyber espionage and traditional geopolitical competition underscores the need for robust cybersecurity frameworks to protect critical infrastructure [4][5].

Sources


Geopolitics Cybersecurity