China-linked espionage group FamousSparrow has been targeting government organizations across Latin America with a new backdoor called SparroWocky, according to ESET researchers.
The attacks have been ongoing for more than a year and have affected organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela. ESET believes the campaign is aimed at gathering intelligence on how Latin American governments are responding to growing US pressure on Chinese economic interests.
SparroWocky is a C++ backdoor that can run commands, steal system information, manage files, take screenshots and act as a proxy for network connections. It also incorporates several techniques designed to avoid detection by security software. For example, the malware can disguise the starting point of malicious threads as a legitimate Windows function.
The malware is delivered through DLL side-loading after a loader decrypts an RC4-encoded payload and places it directly into memory. It can remain on infected systems through a Windows service or registry entries, depending on the privileges available to the attackers.
ESET identified at least 18 command-and-control (C&C) addresses linked to the malware. The researchers said that SparroWocky's design and functionality suggest deep knowledge of Windows, meaning that FamousSparrow is likely a well-resourced and experienced threat group.