China’s Salt Typhoon gang has developed a new backdoor and dropped it in networks belonging to high-profile organizations in several countries across Central and South America since at least August 2025, according to researchers.
The PRC-backed espionage crew shifted its focus to Latin America a month earlier, and from mid-2025 into 2026, the large majority - 90 percent - of Salt Typhoon’s targets were located in that region, ESET said in a Thursday report.
Salt Typhoon is the cyber-spy gang that hacked telecommunications and government agencies to gain stealthy, long-term access to victim organizations going back as far as 2019.
In August 2025, ESET’s malware hunters found the group’s new backdoor, called SparroWocky, deployed against government agencies in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. While targeting entities in these countries “represents a rare occurrence among the China-aligned APT groups,” ESET believes the focus likely reflects China’s reaction to recent US President Donald Trump’s initiatives in the region, malware researchers Alexandre Côté Cyr and Romain Dumont said.
SparroWocky is a modular C++ backdoor that appeared soon after the Beijing snoops started focusing on Latin America. The new backdoor integrates open source tools and uses techniques designed to evade antivirus and other security software.
The name comes from Lewis Carroll’s Jabberwocky poem - the researchers found the first stanza in several collected samples.
ESET based its analysis on a malware sample compiled on November 17, and said it contained the following open source projects:.
After establishing communication with its C2 server, the backdoor starts receiving commands handled by a custom class named WinHandler, according to the runtime type information in the malware.