CiberLATAMbywhalemate

Chile: ransomware.live flags Army

ransomware.live links Chile’s Army to Rhysida and ties seit.cl to Apt73, but offers no technical details or official confirmation.

Whalemate Labs · AI-assisted researchAug 2, 20261 min read

The ransomware.live map for Chile lists the Chilean Army as a victim attributed to the Rhysida ransomware group, while the domain seit.cl is linked to an actor labeled Apt73. The portal does not provide additional technical details or official confirmation in either case.

The ransomware.live map for Chile lists the Chilean Army as a ransomware victim attributed by the portal to Rhysida, but the site does not publish further technical detail about the intrusion or any official confirmation from the Chilean institution.

Records published on the map

In the same view, the domain seit.cl appears linked to an actor labeled Apt73. The portal does not include additional documentation on TTPs, the affected industry sector, or the state nature of that actor, so the association is limited to what the map itself shows.

The available information is therefore based on public ransomware.live records, not on official statements or on supplemental technical reports available from the material provided. With that scope, the two cases sit in different categories, even though both are geolocated in Chile on the map consulted.

What is not shown in the available evidence

No recent, verifiable public reports were found in the material provided on APT or state-backed campaigns targeting government, banking, or energy in Chile. The information angle that is available is centered on ransomware.live records, but without official validation in the case of the Chilean Army and without further technical context for seit.cl.

The second source available, a CronUp note on a large-scale smishing campaign in Chile, points to impersonation of public agencies and companies, but does not attribute that activity to APTs or states. For that reason, based on the documentation provided, there is no basis to connect that campaign to the ransomware.live map entries or to present any state attribution as verified.

Sources

View all