China’s Salt Typhoon backdoors Latin American orgs with new snooping malware

← Back to the feed

China’s Salt Typhoon backdoors Latin American orgs with new snooping malware

The Register · 2 weeks ago

China-linked cyber-espionage group Salt Typhoon has deployed a newly identified backdoor, SparroWocky, against government agencies and other high-profile organisations across Latin America since at least August 2025. Researchers at ESET said the group shifted its focus to the region amid heightened US-China tensions, potentially seeking intelligence on governments’ responses to expanding US pressure and China’s regional investments.

SparroWocky is a modular C++ backdoor that uses open-source components, encrypted communications and evasion techniques to avoid detection. ESET found it in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela, while reporting that about 90% of Salt Typhoon’s targets from mid-2025 into 2026 were in Latin America; the malware can gather system information, steal files, take screenshots and manage remote sessions.

  • Salt Typhoon is targeting Latin American organisations with new espionage malware.
  • ESET identified SparroWocky in government agencies across eight locations.
  • The backdoor can steal files, capture screenshots and evade security tools.

Americas Asia Cybersecurity Technology World

Read the full article at the source →