Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology

Chinese Salt Typhoon group deploys new SparroWocky backdoor across Latin American agencies

The China-backed espionage crew Salt Typhoon has been using a new C++ backdoor called SparroWocky to infiltrate government networks in several Latin American nations since at least August 2025.

ESET’s latest analysis identifies Salt Typhoon, a Chinese-state-aligned cyber-espionage group, as the operator of a new modular C++ backdoor named SparroWocky. Beginning in mid-2025, the group redirected its operations toward Latin America, and from then through 2026 roughly 90 % of its intrusions targeted entities in the region, including government agencies in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela.

Researchers suggest the shift reflects Beijing’s intent to monitor local responses to renewed US pressure under Donald Trump’s second term, which endangers Chinese investments in energy, mining and telecommunications. SparroWocky incorporates open-source libraries like Mbed TLS, MinHook and a COFF loader, and employs techniques to hide its activity from antivirus tools. It is delivered via a trident loader scheme involving a legitimate executable, a malicious DLL and an encrypted payload, then contacts command-and-control servers over port 443 (or 8080) using TLS. ESET has released indicators of compromise and sample code for further study.

Why it matters

It reveals a new Chinese cyber-espionage tool targeting Latin American governments amid heightened US-China rivalry.

In this story

Salt TyphoonSparroWockyLatin Americaespionage malwareChinaDonald TrumpESETbackdoorcyber espionage
Get the beta ↗