Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Exposing the Salt Typhoon: A Looming Threat to Latin American Organizations


China's Salt Typhoon gang has backdoored numerous organizations across Latin America with its latest malware, SparroWocky, a modular C++ program that integrates open source tools and employs techniques to evade security software. The gang's focus on Latin America is believed to reflect China's reaction to US President Donald Trump's initiatives in the region.

  • The Salt Typhoon gang's malware, SparroWocky, is a sophisticated backdoor with modular C++ code that employs techniques to evade antivirus and security software.
  • SparroWocky has been deployed against government agencies in Latin America, with 90% of its targets located in the region since mid-2025.
  • The malware uses open source tools, including Mbed TLS, MinHook, and COFF Loader, to establish a secure communication channel and hide its presence from security products.
  • SparroWocky can spoof call stacks and use a custom API-hashing algorithm to dynamically resolve Windows API functions, making it difficult to detect.
  • The malware has nearly 30 commands, including stealing files, taking screenshots, and spawning new instances, and uses TLS encryption to communicate with its C2 servers.



  • The cyber-security landscape has witnessed an influx of sophisticated threats in recent years, with various groups employing innovative tactics to infiltrate networks and compromise sensitive information. Among these threats, the Salt Typhoon gang stands out for its cunning and stealthy approach, having successfully backdoored numerous organizations across Latin America. This article delves into the intricacies of the Salt Typhoon gang's latest malware, SparroWocky, and its implications for organizations in the region.

    In August 2025, researchers from ESET discovered the SparroWocky backdoor, which had been deployed against government agencies in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. This marked a significant shift in the Salt Typhoon gang's focus, with 90 percent of its targets located in Latin America since mid-2025. According to ESET, this focus likely reflects China's reaction to recent US President Donald Trump's initiatives in the region, which threatens various long-term investments that China has cultivated throughout the continent.

    The SparroWocky backdoor is a modular C++ program that integrates open source tools and employs techniques designed to evade antivirus and security software. The name "SparroWocky" is derived from Lewis Carroll's Jabberwocky poem, which was found in several collected malware samples. The backdoor contains the following open source projects: Mbed TLS, a C library used to establish a secure communication channel with its command-and-control server; MinHook, a Windows API hooking library that hides the start address of newly created threads from security products; and COFF Loader, which enables dynamic loading and execution of in-memory plugins.

    SparroWocky's capabilities include the ability to spoof call stacks originating from MinHook routines, allowing it to escape the watchful eyes of monitoring tools. The backdoor also incorporates a custom API-hashing algorithm to dynamically resolve Windows API functions. Furthermore, it uses a trident loader scheme consisting of a legitimate executable, a malicious DLL, and a file containing the encrypted malware.

    After establishing communication with its command-and-control server, SparroWocky starts receiving commands handled by a custom class named WinHandler (derived from a ServerHandler custom class). The nearly 30 commands include scooping up system details, sending them to the C2, starting and/or terminating a new session, removing persistence, stealing and deleting files, taking periodic screenshots, collecting session IDs and usernames of enumerated remote sessions on the system via WTSEnumerateSessionsW, and spawning new SparrowWocky instances.

    SparroWocky utilizes TLS encryption to communicate with its C2 servers, connecting directly to their IP addresses, generally on port 443, although ESET also spotted the malware using port 8080 in some cases. The researchers have published a full indicators-of-compromise list and samples in ESET's GitHub repository, providing a valuable resource for organizations and security professionals.

    The discovery of SparroWocky and the Salt Typhoon gang's increasing focus on Latin America serves as a stark reminder of the evolving threat landscape. As organizations in the region continue to navigate the complexities of cyber-security, it is essential to remain vigilant and take proactive measures to protect against such sophisticated threats. By understanding the intricacies of SparroWocky and the Salt Typhoon gang's tactics, organizations can better prepare themselves to counter this looming threat.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Exposing-the-Salt-Typhoon-A-Looming-Threat-to-Latin-American-Organizations-ehn.shtml

  • https://www.theregister.com/security/2026/09/17/chinas-salt-typhoon-backdoors-latin-american-orgs-with-new-snooping-malware/5297286


  • Published: Thu Sep 17 15:40:24 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us