Chinese Salt Typhoon group deploys new SparroWocky backdoor across Latin American agencies
The China-backed espionage crew Salt Typhoon has been using a new C++ backdoor called SparroWocky to infiltrate government networks in several Latin American nations since at least August 2025.
ESET’s latest analysis identifies Salt Typhoon, a Chinese-state-aligned cyber-espionage group, as the operator of a new modular C++ backdoor named SparroWocky. Beginning in mid-2025, the group redirected its operations toward Latin America, and from then through 2026 roughly 90 % of its intrusions targeted entities in the region, including government agencies in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela.
Researchers suggest the shift reflects Beijing’s intent to monitor local responses to renewed US pressure under Donald Trump’s second term, which endangers Chinese investments in energy, mining and telecommunications. SparroWocky incorporates open-source libraries like Mbed TLS, MinHook and a COFF loader, and employs techniques to hide its activity from antivirus tools. It is delivered via a trident loader scheme involving a legitimate executable, a malicious DLL and an encrypted payload, then contacts command-and-control servers over port 443 (or 8080) using TLS. ESET has released indicators of compromise and sample code for further study.
Why it matters
It reveals a new Chinese cyber-espionage tool targeting Latin American governments amid heightened US-China rivalry.
In this story
