Subscribe Sign in

China

China's Salt Typhoon backdoors Latin American orgs with new snooping malware

1 min read Rewritten in plain language

Security

Show what we removed Rules applied: A1 A9 D3×5 E3×2 F2×5 all 30 rules
  • China’s Salt Typhoon gang has developed a new backdoor and dropped it in networks belonging to high-profile organizations in several countries across Central and South America since at least August 2025, according to researchers.
  • In August 2025, ESET’s malware hunters found the group’s new backdoor, called SparroWocky, deployed against government agencies in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.
  • SparroWocky is a modular C++ backdoor that appeared soon after the Beijing snoops started focusing on Latin America.
  • ESET based its analysis on a malware sample compiled on November 17, and said it contained the following open source projects:.

4 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

After establishing communication with its C2 server, the backdoor starts receiving commands handled by a custom class named WinHandler, according to the runtime type information in the malware. It uses TLS encryption to communicate with its C2 servers, connecting directly to their IP addresses, generally on port 443.

Headline check

The one thing this headline claims is in the report.

Figures, names and quoted words in the headline, looked for in the report itself — not in the summary above. One claim in this headline could be checked, so this is a narrow pass and not a thorough one. One name in this headline is spelled almost the same as a word in the report — the difference between a country and its adjective, for instance. We cannot tell whether they are the same thing, so that one was not checked either way rather than reported as missing. How this is checked

China’s Salt Typhoon gang has developed a new backdoor and dropped it in networks belonging to high-profile organizations in several countries across Central and South America since at least August 2025, according to researchers.

The PRC-backed espionage crew shifted its focus to Latin America a month earlier, and from mid-2025 into 2026, the large majority - 90 percent - of Salt Typhoon’s targets were located in that region, ESET said in a Thursday report.

Salt Typhoon is the cyber-spy gang that hacked telecommunications and government agencies to gain stealthy, long-term access to victim organizations going back as far as 2019.

In August 2025, ESET’s malware hunters found the group’s new backdoor, called SparroWocky, deployed against government agencies in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. While targeting entities in these countries “represents a rare occurrence among the China-aligned APT groups,” ESET believes the focus likely reflects China’s reaction to recent US President Donald Trump’s initiatives in the region, malware researchers Alexandre Côté Cyr and Romain Dumont said.

SparroWocky is a modular C++ backdoor that appeared soon after the Beijing snoops started focusing on Latin America. The new backdoor integrates open source tools and uses techniques designed to evade antivirus and other security software.

The name comes from Lewis Carroll’s Jabberwocky poem - the researchers found the first stanza in several collected samples.

ESET based its analysis on a malware sample compiled on November 17, and said it contained the following open source projects:.

After establishing communication with its C2 server, the backdoor starts receiving commands handled by a custom class named WinHandler, according to the runtime type information in the malware.

Shortened to 1 minute of reading, this version reads 7.4 on the Niral Score.

You are reading our version, not theirs. This is The Register's report shortened to its most important sentences, in plainer words, with verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingHappiness
The Registeras they published this story 8.9 17 54 51.5
Mundane Readneutralized from The Register 7.7 16 54 51.5

Sign in to react.

Comments

Nothing here yet.

Sign in to comment.

Questions

Readers can ask a question about this story here. Questions and answers are for subscribers. Sign in to read them.

Comments are read before they appear where anything in them needs a person to look. Nothing posted here is ever deleted; a comment taken down keeps its text and the reason, so the decision can be looked at again. How this works