CuraSec

Learn active

FamousSparrow Deploys New SparroWocky Backdoor in Latin America

2026-09-17 15:32 UTC · The Hacker News · read the source ↗ #apt#backdoor#latin-america
  • Engineer — Learn: No CVE or patchable software surface identified — this is a modular C++ backdoor deployed by a nation-state actor. Review ESET’s technical report for evasion techniques that may inform detection or hardening decisions.
  • SOC/IR — Learn: No IOCs or ATT&CK mappings surfaced in the current summary; read the full ESET technical report to extract TTPs and candidate detection rules, especially if your environment covers Latin American entities or sectors FamousSparrow has historically targeted.
  • Leader — Learn: A China-aligned APT expanding campaign scope into Latin America is worth tracking for sector and geographic risk awareness, but no vendor breach or regulation deadline makes immediate leadership action necessary.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.