LIVE · cybersecurity feed
Live wire
Cisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
malware

China's Salt Typhoon backdoors Latin American orgs with new snooping malware

Beware the SparroWocky, my son! The backdoor that bites…

zeroday.news ·

A Chinese state-sponsored advanced persistent threat (APT) group, known as Salt Typhoon, has developed and deployed a new backdoor called SparroWocky against high-profile organizations in Latin America since at least August 2025. This shift in focus to Central and South American targets represents a new strategic direction for the group, which previously targeted telecommunications and government agencies globally.

According to researchers tracking the group, Salt Typhoon, also identified as FamousSparrow, has directed approximately 90 percent of its operations towards Latin America between mid-2025 and 2026. This increased activity in the region is believed to be a response to evolving geopolitical dynamics, specifically the reassertion of US interests in Latin America, which could impact China's long-standing investments in sectors such as energy, mining, and telecommunications. The espionage activities are suspected to provide China with intelligence to monitor and anticipate local governments' reactions to US pressures.

SparroWocky, a modular C++ backdoor, was first detected in August 2025. It has been deployed against government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The backdoor is designed to evade detection by security software and incorporates several open-source tools and sophisticated techniques.

The name "SparroWocky" is derived from Lewis Carroll's poem "Jabberwocky," with the first stanza found within several collected malware samples. The backdoor’s compilation date is noted as November 17. Its technical composition includes Mbed TLS, a C library for secure command-and-control (C2) communication, and MinHook, a Windows API hooking library used to conceal newly created thread start addresses from security products.

Additionally, SparroWocky utilizes a COFF Loader, or a similar project, to enable dynamic loading and execution of in-memory plugins as COFF objects. It also integrates a variant of the SilentMoonwalk technique to spoof call stacks originating from MinHook routines, further aiding in evasion. A custom API-hashing algorithm is employed for dynamic resolution of Windows API functions.

The deployment method for SparroWocky follows Salt Typhoon's established "trident loader scheme," which involves a legitimate executable, a malicious DLL, and an encrypted malware file. The malicious DLL contains the loader, which executes via DLL side-loading.

Upon establishing communication with its C2 server, SparroWocky receives commands handled by a custom class named WinHandler, derived from a ServerHandler class. The backdoor supports nearly 30 commands, enabling it to collect system details, initiate and terminate sessions, remove persistence mechanisms, steal and delete files, capture periodic screenshots, gather session IDs and usernames of enumerated remote sessions via WTSEnumerateSessionsW, and spawn new SparroWocky instances.

Communication with C2 servers is encrypted using TLS, typically connecting directly to IP addresses on port 443, though port 8080 has also been observed in some cases. Researchers have published a comprehensive list of indicators of compromise (IoCs) and malware samples in a public GitHub repository.

malware
ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

Chosen Brick, Iran’s Surveillance Malware

UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services use to track down dissidents, journalists, and activists, and the […]

security

[Virtual Event] Cybersecurity Outlook 2027

ai

Should you care about an “AI slowdown?”

In this week's Threat Source, David talks about why focusing on your security basics is still your best bet, even in a world with rapid AI advancements.

patch

Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE

Six months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of customer data in Bahrain and the UAE. In two updates posted September 15, AWS said it can no longer recover customer data and resources stored in its Middle East (Bahrain) region, known as me-south-1, or in one availability zone of its Middle East (UA

patch

Windows 11 24H2 Home and Pro reach end of support in October

Microsoft reminded customers this week that devices running Windows 11 24H2 Home and Pro editions will stop receiving updates next month. [...]

phishing

A fake ChatGPT billing email is after your OpenAI password

A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense’s Phishing Defense Center traced the email’s payment button through a Google redirect to the attacker’s page. The lure targets ChatGPT users on work and personal accounts alike, and it copies the kind of bill a subscriber already expects. Cre