A Chinese cyberespionage group, dubbed "FamousSparrow," has employed a modified backdoor to infiltrate Central and South American governments and major industries. Another advantageous feature of the modular SparroWocky is its capability to integrate Beacon Object Files (BOFs)—a file format initially introduced by Cobalt Strike and subsequently adopted by other penetration testing developers. FamousSparrow plays a significant role in geopolitics.
Since August 2025, SparrowWocky has been primarily targeting government organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela, as well as a telecommunications firm in Puerto Rico. "We suspect that FamousSparrow's activities are aimed at enhancing China's ability to monitor and predict local governments' responses to current US pressure," according to ESET's report, which includes information about indicators of compromise for at-risk organizations.
"For example, one of the Panamanian entities we've observed being targeted is directly involved in the ongoing commercial dispute over two major ports in the canal area, which were, until recently, operated by a China-based company. As the concession granted to this company was legally challenged by the Panamanian government in early 2025, it is highly probable that FamousSparrow's operation was intended to obtain early, privileged knowledge of local authorities' intentions regarding this issue." The intensified cyber activity is likely indicative of a new normal for organizations in the region, as noted by Côté Cyr.


.jpg?width=1280&auto=webp&quality=80&disable=upscale)








