Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Affecting Mexico

View all threats affecting or targeting Mexico. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (2):Country:MexicoMexico

Threats Affecting Mexico

Click on any threat for detailed analysis and mitigation recommendations

New OkoBot framework deploys 20 payloads to steal data, crypto
0

OkoBot is a malicious framework delivering over 20 payloads aimed at stealing cryptocurrency wallet seed phrases, credentials, and sensitive data. It spreads via ClickFix attacks and trojanized GitHub repositories. The infection chain involves multiple stages, starting with a PowerShell script that installs an SSH bot to collect system info and disable Windows Defender notifications. Key modules include browser injectors, fake seed phrase prompts targeting hardware wallets, keyloggers, and spyware that records video and keystrokes. The campaign has been active since early 2025 with a global reach, primarily impacting Brazil, Vietnam, Canada, Mexico, and Turkey. Indicators of compromise and detailed telemetry are available from Kaspersky. No official patch or remediation is noted.

Join the discussion
OkoBot framework infection chain
0

In January 2026, researchers identified a sophisticated malware framework dubbed OkoBot that targets cryptocurrency users through a multi-stage infection chain. The campaign begins with TookPS PowerShell scripts delivered via ClickFix attacks or fake software on GitHub. An automated SSH bot deploys over 20 malicious modules including HDUtil launcher, browser extension injectors installing Rilide stealer, and specialized tools like SeedHunter for wallet seed phrase theft and OkoSpyware for window capture. The framework uses VMProtect obfuscation, UAC bypass techniques, and maintains persistence through RDP access and scheduled tasks. Victims span more than 25 countries with concentrations in Brazil, Vietnam, Canada, Mexico, and Turkey. Attribution suggests Russian-speaking threat actors based on geoblocking patterns and Russian language artifacts.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Country: Mexico
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses