Bottom line: A new backdoor, dubbed SparroWocky, is being used by Chinese hackers to breach government agencies in Latin America, potentially compromising sensitive data.
What's happening: Chinese hackers allegedly linked to Fancy Bear and Lazarus Group have been targeting government agencies in Argentina, Brazil, and Mexico since October 2022. Researchers have identified a new backdoor, dubbed SparroWocky, which is being used in these breaches. The malware is believed to have been introduced via a vulnerability in the Apache Kafka messaging system.
What to do: Security leaders should ensure their organizations have patched the Apache Kafka vulnerability (CVE-2022-11835) and monitor for suspicious activity related to SparroWocky. Additionally, they should implement a zero-trust architecture to prevent lateral movement in case of a breach.