Threats Tagged 'latin america'
View all threats tagged with 'latin america'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'latin america'
Click on any threat for detailed analysis and mitigation recommendations
In August 2026, a Casbaneiro campaign targeted Latin American users through phishing emails and PDFs themed as fake invoices and legal notices. The multi-stage infection chain includes HTA downloaders and AutoIt loaders, employing geofencing to filter victims by IP address location. The malware exhibits sophisticated evasion techniques, including distributed data-receiving servers, deliberate HTTP 403 responses, and activation only when victims access targeted banking websites. Casbaneiro steals email data, performs clipboard injection, and creates fake windows for fraudulent activities. The campaign specifically targets Argentina, Peru, Colombia, and Mexico while avoiding German, French, and English language systems. The malware splits stolen data across multiple servers and uses malformed HTTP packets to complicate detection and analysis efforts. Join the discussion | AlienVault OTX General | 09/10/2026, 17:27:46 UTC Added: 09/11/2026, 09:02:09 UTC |
Beginning in 2024, a financially motivated threat actor designated BREEZE COMET has conducted sophisticated operations targeting Brazilian financial services, retail, and eCommerce organizations. The group specializes in manipulating payment systems including Pix, STR, and Boleto to conduct fraudulent transfers worth tens of thousands of USD. Their evolved tactics leverage customized malware suites written in multiple languages including Rust, Nim, Golang, and Java, alongside compromised government websites for initial access and command and control. The threat actor demonstrates advanced capabilities by targeting banking software, payment APIs, and mTLS credentials while maintaining persistent access through multiple backdoors. Evidence indicates BREEZE COMET uses generative AI to accelerate malware development and script creation, suggesting potential expansion to other Latin American and African countries based on infrastructure replication observed in Nigeria, Paraguay, Ghana, and Venezuela. Join the discussion | AlienVault OTX General | 09/01/2026, 07:05:40 UTC Added: 09/01/2026, 08:37:15 UTC |
Grandoreiro, a notorious banking trojan active since 2016 across Latin America, continues operations despite major law enforcement disruption in 2024. Recent campaigns leverage DLL sideloading techniques, abusing the legitimate Duplicate Files Finder application to execute malicious code. The loader incorporates extensive anti-analysis mechanisms including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated analysis systems. These defensive checks occur before C2 contact, indicating high priority on avoiding detection. Telemetry from June 2026 shows activity concentrated in Latin America, primarily Mexico, with limited presence in Europe and North America. The malware uses custom string obfuscation combining proprietary decryption with Base64 encoding, and communicates with C2 infrastructure over TCP port 6432 using encrypted requests containing host-specific information. Join the discussion | AlienVault OTX General | 08/19/2026, 20:39:08 UTC Added: 08/20/2026, 23:07:12 UTC |
Between May and July 2026, researchers tracked the Latin America-focused threat actor Blind Eagle through multiple exposed staging servers, identifying significant toolkit evolution. Four key developments emerged: a third string-obfuscation scheme featuring JavaScript with custom AES S-box substitution, a RunPE loader using bare AutoIt3 interpreter staged via GitHub, a reusable 'Photo Studio' persistence mechanism shared across three distinct toolchains, and a materially upgraded AsyncRAT variant codenamed JC-46. This enhanced RAT incorporates Windows Notification Facility process injection, custom Base28 encoding, Hidden VNC banking-fraud capabilities with browser profile cloning, and a Chrome App-Bound Encryption v20 bypass. Despite operational security weaknesses including exposed directories and hardcoded credentials, the group demonstrates selective sophistication targeting banking operations across Spanish-speaking regions. Join the discussion | AlienVault OTX General | 07/18/2026, 11:29:32 UTC Added: 07/20/2026, 11:11:45 UTC |
BTMOB is an Android remote access trojan that evolved from SpySolr malware and poses significant threats beyond traditional banking trojans. The malware combines phishing-led delivery with an APK builder interface that enables rapid payload generation without coding skills. Distributed through fake app stores impersonating streaming services, cryptocurrency platforms, and government agencies, BTMOB abuses Android Accessibility Services to gain elevated permissions. Marketed as malware-as-a-service with a reported $5,000 lifetime license, it provides adversaries with capabilities to exfiltrate sensitive data, capture screenshots, record device activity, and establish remote control. The tool's customizable phishing lures have been adapted for specific regions, including campaigns impersonating Argentine tax authorities, making it a rapidly evolving threat with global reach. Join the discussion | AlienVault OTX General | 05/31/2026, 23:32:45 UTC Added: 06/01/2026, 08:48:35 UTC |
Two distinct threat campaigns, SHADOW-AETHER-040 and SHADOW-AETHER-064, have been identified targeting government entities and financial organizations across Latin America using agentic artificial intelligence to conduct cyber intrusions. SHADOW-AETHER-040, a Spanish-speaking group, compromised six government entities in Mexico between December 2025 and January 2026, while SHADOW-AETHER-064, operating in Portuguese, targeted Brazilian financial institutions starting in April 2026. Both campaigns established SOCKS5 tunnels via ProxyChains and SSH, enabling AI agents to execute commands directly within victim networks. The AI agents dynamically generated hacking tools and scripts on-demand, reducing detection by signature-based security solutions. Despite tactical similarities including shared toolsets like Chisel, Neo-reGeorg, CrackMapExec, and Impacket, the campaigns appear to be separate entities distinguished primarily by language. These operations represent emerging cases of AI agents executing complete... Join the discussion | AlienVault OTX General | 05/12/2026, 08:51:35 UTC Added: 05/12/2026, 09:21:23 UTC |
WEBJACK is a malware campaign targeting Microsoft IIS servers by deploying BadIIS malware modules to conduct SEO poisoning and fraud. The attackers hijack high-profile websites, including government and educational institutions, redirecting users to gambling sites. The campaign selectively serves malicious content to search engine crawlers while redirecting or blocking normal visitors, leveraging legitimate IIS modules for stealth. Originating from a Chinese-speaking threat actor, it primarily affects Southeast Asia and Latin America, with a focus on Vietnamese-language targets. Although no known exploits are publicly reported, the campaign uses advanced tools such as Cobalt Strike and XLANY Loader. The threat demonstrates evolving IIS hijacking techniques and abuse of legitimate security tools for monetization. European organizations could be at risk if targeted due to the use of IIS servers and the potential for reputational damage and fraud. Mitigation requires specific IIS module monitoring, integrity checks, and enhanced web server security. Countries with significant IIS usage and strategic government or educational targets, such as Germany, France, and the UK, are more likely to be affected. The threat severity is assessed as medium given the targeted nature, impact on availability and integrity, and moderate ease of exploitation without user interaction. Join the discussion | AlienVault OTX General | 11/19/2025, 09:01:54 UTC Added: 11/19/2025, 09:17:04 UTC |
A malware campaign in Latin America uses oversized SVG files containing the full malicious payload to deliver AsyncRAT, a remote access trojan. The attack employs social engineering via emails impersonating trusted institutions with urgent legal warnings, primarily targeting Colombia. Clicking the SVG file opens a fake judicial portal to deceive victims. The campaign uses DLL sideloading to evade detection and AI-generated templates for customization. This method avoids external connections by embedding the payload directly in the SVG file. Attacks peaked mid-week in August, focusing on judicial system impersonation. No CVSS score is available, but the threat is medium severity due to its stealth and control capabilities. European organizations should be aware of this evolving tactic as it could be adapted to target other regions. Vigilance against suspicious SVG attachments and advanced detection techniques are critical for defense. Join the discussion | AlienVault OTX General | 11/09/2025, 04:31:57 UTC Added: 11/10/2025, 11:35:31 UTC |
Showing 1 to 8 of 8 results