China's Salt Typhoon backdoors Latin American orgs with new snooping malware
Beware the SparroWocky, my son! The backdoor that bites…
China's Salt Typhoon hacking group has rolled out a new backdoor, dubbed SparroWocky, targeting high-profile organizations in Central and South American nations since at least August 2025. The Russian-backed espionage crew redirected its efforts towards Latin America a month earlier, with around 90% of Salt Typhoon's targets located in this region during 2025 and 2026, according to ESET researchers.
Salt Typhoon, infamous for hacking telecommunications and government agencies since 2019, gained unauthorized access to these organizations for extended periods before being discovered in late 2023. In August 2025, ESET's malware team identified the group's new backdoor in government agencies from Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.
The focus on Latin America is believed to be a response to Donald Trump's aggressive reaffirmation of US interests in the region, which threatens China's long-term investments in energy, mining, and telecommunications. SparroWocky is a modular C++ backdoor that integrates open source tools and employs techniques to evade antivirus and security software.
The malware sample, sourced from November 17, included Mbed TLS, MinHook, COFF Loader, a SilentMoonwalk technique, and a custom API-hashing algorithm. The backdoor uses a trident loader scheme, establishing communication with its command-and-control server via TLS encryption on port 443, although some instances use port 8080.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.