CiberLATAMbywhalemate

Criba and Flecha Bus Join Ransomware Victims

DragonForce added Criba and Frato, KRYBIT added cases in Brazil and Guatemala, and CoinbaseCartel also posted Flecha Bus.

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

DragonForce added Criba in Argentina and Frato in Brazil among its victims, while CoinbaseCartel posted Flecha Bus in Argentina and KRYBIT added cases in Brazil and Guatemala.

Update August 31, 2026: DragonForce expanded the campaign with new details on Criba and Frato, while KRYBIT added independent confirmations in Brazil and Guatemala. The update also adds operational context on DragonForce and more precise timing for the cases.

DragonForce listed Criba in Argentina as one of its newest victims in a 24-hour campaign that also included another case in Brazil. During the same period, CoinbaseCartel added Flecha Bus in Argentina, and Qilin added victims in Mexico and Peru, putting South America and Mexico among the latest targets of these groups.

What did Security Arsenal say about DragonForce?

Security Arsenal attributes DragonForce's attack chain to initial access through VPN or RMM tools, or through exposed applications, followed by the use of valid accounts and lateral movement through PsExec or WMI. The chain ends with staging, data exfiltration, recovery prevention, and encryption. In its coverage, the firm also said the campaign concentrated victims in South America, with postings in Argentina and Brazil during the analysis window.

Criba, identified by the group at criba.com.ar, also appears on tracking platforms as a leak that, according to the actor's public description, includes financial and customer records with data spanning Argentina, Uruguay, and other countries. BreachSense logged the case as a 188.25 GB breach tied to the domain criba.com.ar and described the company as an Argentine construction firm offering preconstruction, project management, and public and private works services. Those portals make clear they only index the existence of the posting and do not validate the stolen content.

DragonForce also posted Frato on its leak site. BreachSense documented the incident as a 124.52 GB leak linked to the domain frato.com and described the victim as a luxury interior design and artisanal furniture brand based in Portugal, although the leak site presents it as a target in Brazil. Kalir.io Pulse also reported exposure of financial records, shareholder data, and employee and customer PII, with possible regulatory impact in Brazil. HookPhish said the Criba and Frato listings date to around August 24 and 25, 2026, and placed Frato's breach date on August 24, 2026, in the BR region.

What happened with CoinbaseCartel and Flecha Bus?

CoinbaseCartel posted 13 victims in 24 hours, and Flecha Bus in Argentina appears among them in the transportation sector. Security Arsenal placed the group in a campaign dominated by financial services, followed by professional services and healthcare, although the Argentine case fell outside that main focus.

Threat intelligence sources that monitor leak sites confirmed that CoinbaseCartel listed Flecha Bus, flechabus.com.ar, on August 22, 2026, with country, transportation sector, and incident discovery date. At the same time, they note that the company has not publicly confirmed the attack or the volume of data involved.

Consumer-facing records repeat that caution and describe the posting as an unverified claim by the group. They say the leak site listing reflects only the actor's version, with no independent verification and no detail on data categories or number of affected people, and that the company has not issued public statements on the incident.

How was Qilin's campaign distributed?

Qilin posted victims in Mexico and Peru, including Constructora Jimenez, Movitecnica, Cinépolis, and Quaker State Mexico. Security Arsenal placed the campaign across manufacturing, hospitality, energy and utilities, technology, professional services, retail and e-commerce, plus other unclassified sectors.

The same firm said Qilin's observed initial access vectors include exploitation of perimeter appliances, phishing with malicious attachments or links, RDP credentials bought from access brokers, and increasingly, supply chain compromise or development tools.

Independent threat intelligence sources also confirmed that Qilin posted Cinépolis on its leak site on August 21, 2026, with the domain www.cinepolis.com, country Mexico, and discovery date. That information is presented as an allegation by the actor, with no official confirmation from the cinema chain or figures on affected people.

In the same time window, Quaker State Mexico was listed as a Qilin victim, with an estimated attack date of August 21, 2026. Campaign tracking records use the case to reinforce the group's concentration in Mexico and in automotive or related services sectors.

What do KRYBIT's new cases in Latin America show?

Security Arsenal reported a burst of 13 KRYBIT victims in 48 hours and placed cases in Brazil and Guatemala within that set, with sector concentration in healthcare, agriculture and food production, retail and e-commerce, and financial services. That view now includes independent confirmations for ferretornillos.gt, mimafoods.net, vascara.com, and NEO Núcleo de Excelência em Oftalmologia.

The tracker Ransomware.live logged ferretornillos.gt as a KRYBIT victim with discovery on August 26, 2026, and Agriculture and Food Production as its sector. Hendry Adrian documented the case as an incident against Ferretornillos S.A., a Guatemalan wholesale distributor in the Agriculture and Food Production sector, while Breach House also included it in its campaign records.

Breach House also documented mimafoods.net in Brazil, classified under Agriculture/Food, and vascara.com in Brazil within the Retail/E-commerce vertical. MedRisk.io, for its part, reported that KRYBIT claimed three healthcare targets in a single day, including NEO Núcleo de Excelência em Oftalmologia in Brazil, as part of a broader wave that also included finance, retail, and industrial sectors. In all cases, the postings are presented as actor claims without official company confirmation.

How is DragonForce's operation being interpreted?

Tanium frames DragonForce as a ransomware cartel since 2025, with an affiliate model supported by shared resources. That reading helps explain why parallel campaigns can appear with common TTPs, such as edge, VPN, or RMM exploitation, but carried out by different operators.

That frame matches the sequence observed by Security Arsenal, which described initial access through VPN, RMM, or exposed applications, the use of valid credentials, lateral movement with PsExec and WMI, exfiltration, recovery inhibition, and encryption. The combination of those pieces once again put South America among the group's most active focus areas during the analysis window.

Sources

View all