Threats Affecting Argentina
View all threats affecting or targeting Argentina. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Argentina
Click on any threat for detailed analysis and mitigation recommendations
BraZetsu is a Python-based Windows malware framework used by the Brazilian threat actor Exilware. It acts as a toolkit for Initial Access Brokers, turning compromised systems into commercial assets. The malware targets corporate, financial, industrial, and law enforcement sectors in Iberia and Latin America. It harvests financial transaction files in Brazilian CNAB format, browsing histories, and digital certificates. BraZetsu supports the 'Infected Marketplace' where initial access is sold to criminal clients for further exploitation. It has evolved rapidly since early 2026, incorporating AI-enhanced reconnaissance and advanced evasion techniques. Join the discussion | AlienVault OTX General | 10/02/2026, 13:14:24 UTC Added: 10/05/2026, 09:03:32 UTC |
The FamousSparrow espionage group, linked to China, has deployed a new backdoor malware named SparroWocky targeting government organizations in Latin America since mid-2025. SparroWocky is a modular C++ backdoor with advanced anti-analysis and evasion techniques, including DLL side-loading, runtime code patching, and thread creation interception to disguise malicious activity. It enables extensive system reconnaissance, file operations, screenshot capture, process creation, and network proxying. Persistence is maintained via Windows services or registry keys. The malware communicates with multiple command-and-control servers over common ports and proxies. The attacks aim to gather intelligence on Latin American governments' responses to U.S. pressure on Chinese economic interests. Join the discussion | Bleeping Computer | 09/17/2026, 09:00:00 UTC Added: 09/17/2026, 09:01:44 UTC |
BambooToken is an emerging multiplatform malware family active since at least February 2023, utilizing the Message Queueing and Telemetry Transport (MQTT) protocol for covert command and control operations. The campaign targets Windows and Linux systems across Asia and South America, with infections observed on backend servers for mobile applications, legal and financial services, software companies, hotels, and GitLab instances. The malware leverages sideloading techniques through Tendyron's OnKey authentication software, commonly used in Chinese banking and government networks. Analysis reveals extensive host enumeration capabilities, plugins for antivirus detection, and potential keylogging and clipboard theft functions. Infrastructure analysis shows C2 domains ranking in Cloudflare's top 500,000, indicating widespread infections. The actor demonstrates sophisticated operational security, using MQTT's publish-subscribe architecture to hide infrastructure and employing Cloudflare proxies for additional o... Join the discussion | AlienVault OTX General | 09/16/2026, 09:45:38 UTC Added: 09/16/2026, 12:31:39 UTC |
A Chinese-speaking threat actor group known as Red Heron exploited a recently disclosed remote code execution vulnerability (CVE-2026-60004) in Gitea, a self-hosted Git service, in a multinational campaign. The campaign targeted internet-facing Gitea instances across multiple countries, including Canada, Argentina, Taiwan, the United States, and Sri Lanka, focusing on sectors such as defense, elections, energy, aerospace, telecommunications, government, and research. The attackers used automated tools to steal source code, credentials, and maintain persistent access, including root-level control on some infrastructure. They deployed a novel Linux implant named JITTERLY with extensive post-exploitation capabilities and embedded a previously undocumented rootkit called SIXZUT to maintain stealth and persistence. The campaign demonstrates rapid weaponization of n-day vulnerabilities in development platforms and highlights significant risks to source code confidentiality and infrastructure integrity. Join the discussion | Reddit NetSec | 09/15/2026, 18:05:21 UTC Added: 09/15/2026, 19:01:29 UTC |
0 A Chinese-speaking threat actor tracked as Red Heron rapidly weaponized CVE-2026-60004, a critical Gitea remote code execution vulnerability, within days of public disclosure in July 2026. The actor scanned 1,386 Gitea instances across seven countries, successfully compromising organizations in Canada, Argentina, Taiwan, the United States, and Sri Lanka. Activities included source code theft, credential collection, SSH persistence, and lateral movement, with one case escalating from a vulnerable Gitea server to root access across a three-node Proxmox cluster. An exposed staging server revealed targeting taxonomies using Simplified Chinese labels covering defense, elections, energy, aerospace, telecommunications, and government sectors. The campaign deployed JITTERLY, a C++ Linux implant with 30+ post-exploitation commands, embedding SIXZUT, a previously undocumented LD_PRELOAD rootkit capable of hiding files, processes, and network connections while protecting the implant from termination. Join the discussion | SecurityWeek | 09/15/2026, 13:05:50 UTC Added: 08/26/2026, 05:22:13 UTC |
In August 2026, a Casbaneiro campaign targeted Latin American users through phishing emails and PDFs themed as fake invoices and legal notices. The multi-stage infection chain includes HTA downloaders and AutoIt loaders, employing geofencing to filter victims by IP address location. The malware exhibits sophisticated evasion techniques, including distributed data-receiving servers, deliberate HTTP 403 responses, and activation only when victims access targeted banking websites. Casbaneiro steals email data, performs clipboard injection, and creates fake windows for fraudulent activities. The campaign specifically targets Argentina, Peru, Colombia, and Mexico while avoiding German, French, and English language systems. The malware splits stolen data across multiple servers and uses malformed HTTP packets to complicate detection and analysis efforts. Join the discussion | AlienVault OTX General | 09/10/2026, 17:27:46 UTC Added: 09/11/2026, 09:02:09 UTC |
BraZetsu is a sophisticated Python-based Windows malware framework attributed to the Brazilian threat actor Exilware, functioning as a comprehensive toolkit for Initial Access Brokers. Unlike standard infostealers, BraZetsu transforms compromised systems into commercial assets through deep reconnaissance capabilities targeting Iberian and Latin American corporate, financial, industrial, and law enforcement environments. The framework scans for standardized financial remittance files in Brazilian CNAB format, extracts detailed browser histories, and employs AI-enhanced data triage for target prioritization. Operating through a modular architecture with stealth techniques, BraZetsu powers the Infected Marketplace where Exilware commercializes initial access to compromised hosts. The platform allows criminal customers to remotely execute secondary malicious payloads on purchased access, creating a persistent threat-multiplier effect. Tracked since February 2026, BraZetsu demonstrates rapid technical progressi... Join the discussion | AlienVault OTX General | 08/31/2026, 15:42:36 UTC Added: 09/01/2026, 08:52:34 UTC |
AnonyMousKIT is an AI-powered Phishing-as-a-Service platform engineered to disable Apple's Activation Lock on stolen devices. Operating as a credit-metered system, it automates credential harvesting through email, SMS, WhatsApp, and AI-driven voice phishing calls. The investigation exposed a reseller supply chain spanning 506 domains and 168 storefront brands active since early 2024. The platform targets owners of stolen Apple devices using device-specific lures with internal model identifiers and real-time Find My statuses. Conversational AI agents impersonating Apple Support conduct vishing operations, with over 200 calls placed primarily to Brazil at minimal cost. Coding vulnerabilities exposed 120,242 lines of operational logs, revealing 689 distinct WhatsApp operator accounts and detailed attack infrastructure. The ecosystem operates through a decentralized enterprise structure with developers, resellers, and hundreds of subscriber-operators monetizing stolen iPhone hardware through industrialized soc... MediumCampaign Join the discussion | AlienVault OTX General | 08/27/2026, 08:04:55 UTC Added: 08/28/2026, 00:37:15 UTC |
Beginning in August 2025, a sophisticated intrusion was discovered where attackers used log poisoning techniques to deploy a web shell on vulnerable phpMyAdmin panels. The threat actors exploited misconfigured web applications to plant China Chopper web shells, controlled via AntSword, before deploying Nezha, an open-source monitoring tool, to facilitate remote command execution. This led to the deployment of Ghost RAT on compromised systems. Analysis revealed over 100 compromised machines, predominantly located in Taiwan, Japan, South Korea, and Hong Kong. The attackers demonstrated technical proficiency through multi-stage operations, utilizing AWS and VPS infrastructure, with indicators pointing to China-nexus threat actors. The campaign highlights increasing abuse of legitimate publicly available tools to achieve malicious objectives while maintaining plausible deniability. Join the discussion | AlienVault OTX General | 07/03/2026, 21:26:02 UTC Added: 07/06/2026, 09:21:27 UTC |
A Chinese web-development framework called DCloud Uni-App has become the technical foundation for over 236,000 scam domains since 2022, powering fake cryptocurrency exchanges, pig-butchering operations, wallet drainers, gambling platforms, and brand-impersonation sites. The framework gained prominence after the 2024 RainbowEx cryptocurrency scam in Argentina, which defrauded residents of San Pedro. Similar operations include the Lightning Shared Scooter Co. (LSSC) scam in the United States, which caused millions in losses across multiple states, and the currently-active Yuechi Sharing Technology Ltd. bicycle-sharing investment scam. These operations use legitimate hosting providers, with approximately 6% utilizing bulletproof hosting, particularly CTG Server. The scams target victims globally through WhatsApp, Telegram, and social media, converting victims into recruiters for pyramid-style operations. Enterprise exposure reaches over 985 distinct organizations across 25 industry verticals, with over five m... Join the discussion | AlienVault OTX General | 06/25/2026, 18:43:49 UTC Added: 06/26/2026, 08:31:07 UTC |
Showing 1 to 10 of 81 results