Chile investigates telecom cyberespionage
The U.S. alerted Chile to alleged malware in Entel, Movistar and Telmex. Chile’s PDI is probing the so-called Chinese cable case.
The PDI is carrying out procedures at the Metropolitan North Central Prosecutor’s Office to verify a complaint based on information provided by the United States about possible cyberattacks on devices located in Chile, in the context of the case known as the "Chinese cable."
The PDI is carrying out procedures at the Metropolitan North Central Prosecutor’s Office to verify a complaint based on information provided by the United States about possible cyberattacks on devices located in Chile, in the context of the case known as the "Chinese cable."
Chile and the telecoms alert
According to Revista Seguridad, U.S. intelligence agencies allegedly warned the Chilean government about cyberespionage operations involving malware on the networks of Entel, Movistar and Telmex. In the same vein, 24 Horas reported that the attacks would have started appearing in Chilean territory in September 2024, and that Microsoft attributes the malicious code to an actor whose origins point to China.
Emol said the investigation seeks to determine whether there was targeted espionage against multiple private telecommunications companies, in a case tied to the so-called "Chinese cable." In that coverage, U.S. Ambassador to Chile Brandon Judd said the activity put at risk the privacy and personal data of nearly all Chileans who use mobile phones.
Cooperativa, meanwhile, reported that the PDI is investigating "possible cyberattacks" attributed to an Asian cyberespionage group, after receiving a complaint with information provided by the United States. The same report linked the filing to the "Chinese cable" case and said the investigation aims to establish a possible cyberespionage campaign by "Lilac Typhoon" against companies such as Entel, Movistar and Telmex.
Guatemala and Costa Rica under similar pressure
The available coverage on Central America indicates that a cybersecurity review detected the presence of APT-15, also known as Vixen Panda, Nickel and Nylon Typhoon, in several Guatemalan government systems. The same review included Costa Rica, where the Costa Rican Electricity Institute announced a March 2026 incident identified as cyberespionage, and a technical analysis by Mandiant found similarities with a group originating in China.
Ransomware and banking trojans across the region
At the same time, a Scitum assessment cited by Convergencia placed 78 ransomware variants targeting Latin America during 2025, with Qilin as the most active. It also recorded banking trojan campaigns and said Argentina accounted for 13% of those campaigns, in a regional map that also includes obsolete equipment and other exposure surfaces mentioned in the coverage.
The mix of alerts involving telecoms in Chile, findings in Guatemalan government systems and the incident reported by ICE in Costa Rica leaves the region facing active fronts in both cyberespionage and malware campaigns aimed at stealing credentials and encrypting data.
Sources
- Reportes de inteligencia de Estados Unidos alertan sobre actividad maliciosa y uso de malware en los sistemas de las empresas de telecomunicaciones en Chilerevistaseguridad.cl· Revista Seguridad
- PDI investiga posible espionaje a Entel, Movistar y Telmex tras advertencia de Estados Unidos24horas.cl· 24 Horas
- Centroamérica se enfrenta a un mayor riesgo de ciberataquesvietnam.vn· vietnam.vn
- Ciberseguridad: Ransomware, troyanos bancarios y equipos obsoletos en el diagnóstico de Scitum sobre Argentinaconvergencia.com· Convergencia
- "Lilac Typhoon": PDI indaga "posibles ataques informáticos" de un grupo de ciberespionaje asiáticocooperativa.cl· Cooperativa
- "Cable chino": Indagan a grupo de ciberespionaje asiático y eventuales accesos a empresas chilenasemol.com· Emol



