CiberLATAMbywhalemate

Colombia and Mexico Hit by New Campaigns

Ransomware hit Colombia’s Justice Ministry, while Grandoreiro resurfaced in Mexico, with detections also reported in Peru

Whalemate Labs · AI-assisted researchPublished:2 min read

Check Point Research reported a ransomware attack on Colombia’s Ministry of Justice that affected part of its technology infrastructure and disrupted public services tied to illicit drug monitoring and legal processes. At the same time, Infosecurity Magazine reported Grandoreiro’s return in a campaign against Latin American users, with Mexico as the main focus and detections in Peru and Argentina.

Check Point Research reported that Colombia’s Ministry of Justice suffered a ransomware attack that affected part of its technology infrastructure and disrupted public services tied to illicit drug monitoring and legal processes. Colombian media added that the intrusion appears to have expanded progressively since January 2026, and forensic analysis was still underway to measure the full impact.

What is known about the attack on Colombia’s Ministry of Justice?

The incident reached systems at the Ministry of Justice and took components linked to sensitive state functions offline, according to Check Point Research. The firm did not specify in the material provided which ransomware family was used or publicly attribute the attack to any specific group.

Coverage from Las2orillas said the attack appears to have started spreading in January 2026 through malware that blocked access to networks and files. That report also said forensic analysis was still ongoing at the time of publication to determine the exact scope of the impact on the technology infrastructure.

What happened with Grandoreiro in Latin America?

Infosecurity Magazine reported that Grandoreiro resurfaced in a campaign aimed at Latin American users, with Mexico accounting for 40% of the detections observed. Activity was also detected in Peru and Argentina, and the operation used DLL sideloading to run the banking trojan through legitimate software.

The clearest figure in the report is the concentration in Mexico, which absorbed nearly half of the detections monitored. Even so, the regional pattern was not limited to that country, since the outlet also identified activity in other parts of Latin America.

What other threat intelligence activity was observed?

Microsoft Threat Intelligence observed Storm-2945, a subgroup of Midnight Blizzard, carrying out large-scale traffic manipulation attacks since early May 2026 against hotel sector networks served through captive portals in several countries. In parallel, Check Point Research described a campaign suspected of being linked to China that used autonomous AI agents against Taiwanese government systems and later expanded to a nuclear security organization and seven energy sector companies.

That second case was presented by the source itself as a hypothesis, not a closed attribution. Based on the available material, it can be described as a campaign allegedly linked to China, but not as a definitive confirmation.

Sources

View all