China’s Salt Typhoon backdoors Latin American orgs with new snooping malware
China-linked cyber-espionage group Salt Typhoon has deployed a newly identified backdoor, SparroWocky, against government agencies and other high-profile organisations across Latin America since at least August 2025. Researchers at ESET said the group shifted its focus to the region amid heightened US-China tensions, potentially seeking intelligence on governments’ responses to expanding US pressure and China’s regional investments.
SparroWocky is a modular C++ backdoor that uses open-source components, encrypted communications and evasion techniques to avoid detection. ESET found it in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela, while reporting that about 90% of Salt Typhoon’s targets from mid-2025 into 2026 were in Latin America; the malware can gather system information, steal files, take screenshots and manage remote sessions.
- Salt Typhoon is targeting Latin American organisations with new espionage malware.
- ESET identified SparroWocky in government agencies across eight locations.
- The backdoor can steal files, capture screenshots and evade security tools.