As cited
Copy frozen at (site build).
threat intel
China's Salt Typhoon backdoors Latin American orgs with new snooping malware
China's Salt Typhoon, a state-sponsored espionage group, developed a new modular backdoor called SparroWocky and deployed it across government agencies and high-profile organizations in eight Latin American countries and territories starting in August 2025. The malware uses open source tools, call stack spoofing, and direct IP connections to command-and-control servers to maintain persistent access while evading detection. Researchers believe the shift in targeting reflects China's effort to monitor local government responses to recent US policy initiatives in the region.
Why it matters: Government agencies and critical infrastructure operators in Central and South America face a sophisticated, persistent threat from a nation-state actor; practitioners should review network logs for indicators of compromise published by ESET and assess whether SparroWocky or similar trident loader schemes have penetrated their environments.
- Source published
- First seen by Cybersecurity Tracker