CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

China's Salt Typhoon backdoors Latin American orgs with new snooping malware

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7690

As cited

Copy frozen at (site build).

threat intel

China's Salt Typhoon backdoors Latin American orgs with new snooping malware

China's Salt Typhoon, a state-sponsored espionage group, developed a new modular backdoor called SparroWocky and deployed it across government agencies and high-profile organizations in eight Latin American countries and territories starting in August 2025. The malware uses open source tools, call stack spoofing, and direct IP connections to command-and-control servers to maintain persistent access while evading detection. Researchers believe the shift in targeting reflects China's effort to monitor local government responses to recent US policy initiatives in the region.

Why it matters: Government agencies and critical infrastructure operators in Central and South America face a sophisticated, persistent threat from a nation-state actor; practitioners should review network logs for indicators of compromise published by ESET and assess whether SparroWocky or similar trident loader schemes have penetrated their environments.

VendorsMicrosoftGitHub
Actorssalt typhoon
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary