China's state-backed Salt Typhoon hacking group has quietly redirected almost all of its energy toward Latin America, armed with a new backdoor called SparroWocky.
ESET researchers say that from mid-2025 through 2026, the group - which the firm also tracks as FamousSparrow - hit government targets in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. About 90% of its recent activity went to this one region, a sharp break from years spent hacking telecom companies and government agencies across the western world. The new tool, SparroWocky, packs more than 30 commands for profiling systems, grabbing screenshots, and exfiltrating files. It arrives through a side-loading trick: a legitimate executable loads a malicious DLL alongside an encrypted payload, letting the malware slip past defenses tuned to spot obviously bad files.
ESET ties the shift directly to the Trump administration's renewed push into Latin America, which it says threatens Chinese investments in energy, mining, and telecoms built up over the past decade. That reframes this less as opportunistic spying and more as economic self-defense - Beijing watching how local governments respond to US pressure so it can react before they do.
Salt Typhoon spent years quietly burrowing into western telecom networks; turning that same machine toward a fight over Latin American mining and telecom contracts shows Chinese state hacking adapting in near real time to whatever geopolitical fire needs watching next.