Urgent.News

What's breaking now, across thousands of outlets.

Tech

China's Salt Typhoon backdoors Latin American orgs with new snooping malware

Beware the SparroWocky, my son! The backdoor that bites…

China's Salt Typhoon backdoors Latin American orgs with new snooping malware

China's Salt Typhoon group has developed a new backdoor, SparroWocky, and has been deploying it in Latin American organizations since at least August 2025. The PRC-backed espionage crew shifted its focus to the region a month prior, with 90 percent of Salt Typhoon's targets located in Latin America from mid-2025 to 2026. ESET researchers discovered the new backdoor, which is a modular C++ malware that integrates open-source tools and evades detection.

The backdoor communicates with its command-and-control servers using TLS encryption and connects to IP addresses on port 443, though it has also used port 8080 in some instances. SparroWocky's commands include gathering system details, starting and terminating sessions, stealing and deleting files, taking screenshots, collecting session IDs and usernames, and spawning new instances.

The malware researchers have published a list of indicators of compromise and malware samples on ESET's GitHub repository.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

More from Thursday 17 September →