ESET exposed a China-linked espionage campaign of more than a year against Latin American governments: Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The reported objective is collecting intelligence on those governments’ responses to American pressure against Chinese economic interests.
Brazil does not appear on the list. I will come back to that at the end, because it is the least comfortable part of the case.
The instrument: state patience in modular code
The SparroWocky backdoor is a complete arsenal in modular C++:
- Discreet visual surveillance: screenshots every 500 milliseconds, sending only the regions of the screen that changed. Exfiltration designed not to show up: small bands of pixels instead of whole files.
- Silent movement: injects processes into other users’ sessions, escaping the visibility of the profile that carries it.
- Robust infrastructure: operates as a network proxy and talks to more than 18 command-and-control servers.
This is state espionage with state patience: a campaign of over a year, against targets whose value is not a ransom payment but what public employees’ screens show.
The geographic cut tells a story
Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, Venezuela: Spanish-speaking targets, inside Washington’s pressure arc against Chinese economic interests. The selection is not random, it is analytical: whoever responds to US pressure is exactly who the other side wants to hear.
The technique rhymes with patterns we have covered before: discreet instruments, long persistence, and targets chosen for what they reveal, not what they pay. The C2 backdoor that turned Teams channels into a relay showed the same logic on the criminal side: when legitimate communication is the channel, detection must be behavioral, not signature-based.
Brazil off the list: three readings, no comfort
Brazil’s absence from the list allows three readings:
- Language: the campaign was designed for the Spanish-speaking segment (social engineering, documentation, operations), and the Portuguese effort has not yet paid for itself.
- Doctrine: different instruments for Brazil, not yet exposed.
- Waiting: the queue exists, and prioritization is not a defense merit badge.
None of the three readings is comfort, and the third is the most probable of all the ones that cannot be ruled out. An APT is not a weekend campaign: it is long-term presence, and today’s list is not tomorrow’s. Brazil is the region’s largest digital market, with elections and Pix as its financial backbone: assuming we are uninteresting is the cheapest vulnerability an attacker can find.
The answer the region can run
For anyone defending infrastructure on the continent, the answer is singular: continuous hunting instead of the annual pentest, with updated indicators and a permanent-compromise hypothesis.
In practice: EDR/XDR instrumented across endpoints (with telemetry for process injection and unusual traffic), subscribed and applied threat intelligence (ESET published SparroWocky’s IoCs; applying them is this week’s minimum), and rehearsed response playbooks. The annual pentest answers "how would we get in today"; continuous hunting answers "who is already inside, and for how long". Different questions, and the second one is the one that defines survival.
Conclusion
SparroWocky is not news about eight neighboring governments: it is confirmation that Latin America has become a systematic espionage board, with state patience and a state budget.
For Brazil, the message is double: not being on the list is not merit, and being out of the photo does not mean being out of the film. Continuous hunting starts by assuming the adversary is already looking for you. Whoever starts from that premise builds defense; whoever starts from the other builds surprise.