Threats Tagged 'south america'
View all threats tagged with 'south america'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'south america'
Click on any threat for detailed analysis and mitigation recommendations
UAT-9244, a China-nexus advanced persistent threat actor, has been targeting critical telecommunications infrastructure in South America since 2024. The group employs three new malware implants: TernDoor, a Windows-based backdoor variant of CrowDoor; PeerTime, an ELF-based backdoor using BitTorrent protocol; and BruteEntry, a brute force scanner for SSH, Postgres, and Tomcat servers. UAT-9244 uses dynamic-link library side-loading, scheduled tasks, and registry modifications for persistence. The group is closely associated with FamousSparrow and Tropic Trooper, sharing similar tooling and tactics. Their infrastructure includes multiple command and control servers and operational relay boxes for scanning and brute-forcing activities. Join the discussion | AlienVault OTX General | 03/05/2026, 20:13:36 UTC Added: 03/06/2026, 11:30:23 UTC |
The Brazilian Caminho loader is a sophisticated malware delivery mechanism active since March 2025, leveraging LSB steganography to hide . NET payloads within images hosted on legitimate platforms. It initiates infection via phishing emails containing malicious scripts that download these steganographic images. The loader executes payloads filelessly in memory and establishes persistence using scheduled tasks. Caminho operates as a Loader-as-a-Service, delivering multiple malware families such as Remcos RAT, Xworm, and Katz stealer across South America, Africa, and Eastern Europe. Its use of bulletproof hosting and Portuguese language artifacts indicates a Brazilian origin and professional operation. The campaign targets multiple industries opportunistically without a specific sector focus. The infection chain employs multiple advanced techniques including fileless execution, steganography, and obfuscation, complicating detection and mitigation efforts. European organizations, especially in Eastern Europe, face risks of data theft, espionage, and system compromise. Mitigation requires targeted email security, memory scanning, and monitoring of scheduled tasks for persistence. Join the discussion | AlienVault OTX General | 10/22/2025, 04:00:17 UTC Added: 10/22/2025, 12:09:03 UTC |
A new Astaroth banking trojan campaign has been discovered abusing GitHub to host malware configurations. The infection begins with a phishing email containing a link to download a zipped Windows shortcut file, which installs the Astaroth malware. The trojan detects when users access banking or cryptocurrency websites and steals credentials through keylogging. It sends stolen information to attackers using Ngrok reverse proxy and uses GitHub to update its configuration when command and control servers become inaccessible. The malware primarily targets South American countries, with a focus on Brazil. Astaroth employs various anti-analysis techniques and targets specific banking and cryptocurrency-related sites. The GitHub repositories hosting the malicious configurations have been reported and taken down. Join the discussion | AlienVault OTX General | 10/14/2025, 09:10:41 UTC Added: 10/14/2025, 09:21:37 UTC |
Insikt Group has identified five distinct activity clusters linked to TAG-144 (Blind Eagle), targeting primarily Colombian government entities across local, municipal, and federal levels throughout 2024 and 2025. The clusters share similar tactics, techniques, and procedures (TTPs) such as using open-source and cracked remote access trojans (RATs), dynamic domain providers, and legitimate internet services (LIS) for staging. However, they differ in infrastructure, malware deployment, and operational methods. The group maintains an extensive operational infrastructure, employs various RATs, and uses multi-stage infection chains. TAG-144's primary focus appears to be credential theft and espionage, with evidence linking it to Red Akodon and compromised Colombian government email accounts used in spearphishing campaigns. Join the discussion | AlienVault OTX General | 08/26/2025, 15:21:26 UTC Added: 08/26/2025, 19:17:49 UTC |
Showing 1 to 4 of 4 results