Cybersecurity 5 min read

China-Aligned Spies Targeted a Port Authority in Panama

SparroWocky replaced SparrowDoor from August 2025. ESET puts about nine in ten of the group's recent victims in one region, which is unusual for an operation of this kind.

Kenji Tanaka
Developer Tools & Cloud Analyst
Published 23 Sep 2026, 9:08 AM (SGT)
Share:
Stacked shipping containers and gantry cranes at a container port Stacked shipping containers and gantry cranes at a container port Photo by 652234 on Pixabay
Advertisement

23 SEP 2026 — A new China-aligned backdoor has compromised government organisations across Latin America, including a Panamanian port authority. The concessions that authority oversees are already the subject of a dispute involving Chinese operators.

The port authority says more about the campaign than the backdoor does, and the backdoor is unusually good.

What replaced SparrowDoor

SparroWocky is a modular backdoor written in C++, and since August 2025 it has been the main implant of FamousSparrow, replacing the SparrowDoor family the group had used for years. ESET researchers Alexandre Cote Cyr and Romain Dumont documented it on 17 September.

It runs files, opens a shell, proxies TCP, takes screenshots, exfiltrates with RC4 inside TLS, and persists through a Windows service or a registry run key. It borrows from open-source projects for the parts nobody needs to write twice, including a loader for Beacon Object Files, which lets the operators run post-exploitation modules built for commercial red-team frameworks without ever writing an executable to disk.

Forging a call stack

The anti-analysis work shows significant effort to evade products that watch for suspicious behaviour rather than merely suspicious files.

When a security tool asks not just which function was called but who called it, SparroWocky lies. It builds fake call stacks out of fragments of a system library, so that a monitored call appears to originate from the ordinary Windows thread-start routines rather than from the backdoor.

It also patches a window-animation function at runtime and uses it as a trampoline, so its own threads report a harmless starting address. When it loads code into memory it forges the structures Windows uses to describe loaded modules, and redirects the functions that would reveal the real command line.

Each of these is a lie told to a specific sensor, describing an author who knows precisely which ones to expect.

8Countries with confirmed government targets
~90%Of the group's targeting, in one region
Aug 2025When it replaced SparrowDoor
RFC 7539Where the nonsense poem actually came from

Eight governments, one region

ESET has confirmed SparroWocky inside government organisations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela.

From the middle of 2025 into 2026, roughly nine in ten of the FamousSparrow targets ESET could see were in Latin America. For a China-aligned group, that concentration is the anomaly. These operations are normally spread across continents. A near-exclusive regional focus is a choice, not drift.

Why Latin America, and why now

ESET reads the shift as tracking Washington rather than the region itself. The United States has been paying more attention to Latin America, including pressure on Chinese investments in energy, mining and telecommunications, and a corresponding interest in how local governments intend to respond.

Advertisement

That brings us back to the port authority. A body administering concessions that are themselves contested is not a general intelligence target. It is a specific target, and the specificity is what gives the campaign away.

ESET attributes the campaign to FamousSparrow with high confidence on three grounds. The first samples arrived through infrastructure only that group used, the victims match its earlier pattern, and several of the same organisations had been hit with the older backdoor.

Where the name comes from

The early samples all contained the opening stanza of Lewis Carroll's Jabberwocky, which is how the backdoor got its name. The actual reason is less literary.

Those lines are test vectors from the specification for a widely used encryption construction, and they were almost certainly inherited from the open-source TLS library the malware borrows. The authors did not choose Carroll. They copied a library that happened to ship him.

Advertisement
Kenji Tanaka
Developer Tools & Cloud Analyst

Kenji Tanaka covers developer tools, cloud platforms, DevOps, CI/CD, and software supply-chain topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Kenji Tanaka is a RECATOOLS editorial persona for developer tools, cloud, DevOps, and software supply-chain coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement