CiberLATAMbywhalemate

Chile investigates telecom cyberespionage

The U.S. alerted Chile to alleged malware in Entel, Movistar and Telmex. Chile’s PDI is probing the so-called Chinese cable case.

Whalemate Labs · AI-assisted researchPublished:3 min read

The PDI is carrying out procedures at the Metropolitan North Central Prosecutor’s Office to verify a complaint based on information provided by the United States about possible cyberattacks on devices located in Chile, in the context of the case known as the "Chinese cable."

The PDI is carrying out procedures at the Metropolitan North Central Prosecutor’s Office to verify a complaint based on information provided by the United States about possible cyberattacks on devices located in Chile, in the context of the case known as the "Chinese cable."

Chile and the telecoms alert

According to Revista Seguridad, U.S. intelligence agencies allegedly warned the Chilean government about cyberespionage operations involving malware on the networks of Entel, Movistar and Telmex. In the same vein, 24 Horas reported that the attacks would have started appearing in Chilean territory in September 2024, and that Microsoft attributes the malicious code to an actor whose origins point to China.

Emol said the investigation seeks to determine whether there was targeted espionage against multiple private telecommunications companies, in a case tied to the so-called "Chinese cable." In that coverage, U.S. Ambassador to Chile Brandon Judd said the activity put at risk the privacy and personal data of nearly all Chileans who use mobile phones.

Cooperativa, meanwhile, reported that the PDI is investigating "possible cyberattacks" attributed to an Asian cyberespionage group, after receiving a complaint with information provided by the United States. The same report linked the filing to the "Chinese cable" case and said the investigation aims to establish a possible cyberespionage campaign by "Lilac Typhoon" against companies such as Entel, Movistar and Telmex.

Guatemala and Costa Rica under similar pressure

The available coverage on Central America indicates that a cybersecurity review detected the presence of APT-15, also known as Vixen Panda, Nickel and Nylon Typhoon, in several Guatemalan government systems. The same review included Costa Rica, where the Costa Rican Electricity Institute announced a March 2026 incident identified as cyberespionage, and a technical analysis by Mandiant found similarities with a group originating in China.

Ransomware and banking trojans across the region

At the same time, a Scitum assessment cited by Convergencia placed 78 ransomware variants targeting Latin America during 2025, with Qilin as the most active. It also recorded banking trojan campaigns and said Argentina accounted for 13% of those campaigns, in a regional map that also includes obsolete equipment and other exposure surfaces mentioned in the coverage.

The mix of alerts involving telecoms in Chile, findings in Guatemalan government systems and the incident reported by ICE in Costa Rica leaves the region facing active fronts in both cyberespionage and malware campaigns aimed at stealing credentials and encrypting data.

Sources

View all