CiberLATAMbywhalemate

Latin America: attacks hit Mexico

Unit 42 found active campaigns against transport, government, water and finance in Mexico, Ecuador

Whalemate Labs · AI-assisted researchPublished:3 min read

Unit 42 reported two active campaigns against organizations in Latin America: one against transport, federal government and water services in Mexico and Ecuador, and another against Brazil's financial sector. Separately, there were reports on Blind Eagle in Colombia and on Gambling Goblin, which turned Brazilian public websites into SEO fraud infrastructure.

Unit 42 reported two active campaigns targeting organizations in Latin America. One focused on transport, federal ministries and municipal water services in Mexico and Ecuador. The other targeted Brazil's financial sector. In parallel, other coverage examined Blind Eagle activity in Colombia and Gambling Goblin's use of Brazilian public websites as infrastructure for SEO fraud.

What did Unit 42 detect in Mexico, Ecuador and Brazil?

Unit 42 identified a transport-focused campaign in Mexico, with additional impact on Mexican federal ministries and a municipal water company in Ecuador, along with a financial campaign in Brazil. The firm internally attributed the first to cluster CL-CRI-1131 and the second to CL-CRI-1163.

In CL-CRI-1131's case, Unit 42 described living-off-the-land techniques, batch scripts used to manipulate and exfiltrate data, and NextChat hosted on the attackers' operational infrastructure. CSA expanded on that coverage and said the target set was not limited to a single industry vertical, but spanned critical infrastructure and public administration.

For CL-CRI-1163, Unit 42 pointed to custom RATs and tunneling tools, including a Go-based SOCKS5 proxy. The same coverage said the attackers gained initial access in February 2026 through a CV attachment in a phishing email. CSA added that the SOCKS5 proxy was versioned and redeployed in at least nine iterations, suggesting active tooling maintenance and a prolonged campaign against Brazil's financial sector.

How did CL-CRI-1131 and CL-CRI-1163 operate?

The two clusters show sustained use of common system tools, iterative scripts and custom components for persistence, exfiltration and communication tunnels. CSA also said both operators consistently used their own NextChat interfaces to query commercial LLMs such as Claude and GPT-4.1 for operational tasks, including exploit troubleshooting and iterative generation of exfiltration scripts.

SocDefenders.ai also described CL-CRI-1131 and CL-CRI-1163 as active campaigns dating back at least to February 2026, and highlighted the mix of LotL, batch scripting and custom malware, including the Go SOCKS5 proxy used for traffic tunneling. Risky Business, in its bulletin, summarized the Mexican campaign as active activity that affected a transport organization, federal ministries and municipal water services in Mexico and Ecuador.

What happened with Blind Eagle in Colombia?

LevelBlue SpiderLabs published analysis of a malicious loader infrastructure linked to Blind Eagle, also known as APT-C-36, in Colombia. The coverage described judicial notification lures and targeting of Colombian government entities.

Security Arsenal and OffSeq Threat Radar added that the actor was distributing loaders and RAT payloads through GitHub, using AsyncRAT, DcRat, Remcos and XWorm. OffSeq detailed phishing emails with judicial notice and traffic fine lures, plus password-protected archives. DeafNews added that the GitHub account "cabeto850128" and the repositories "comicsam" and "jacobo" were used as staging for AutoIt loaders, while a local folder called "Rats" contained builds of those same families.

How did Gambling Goblin use Brazilian websites?

Check Point Research reported that Gambling Goblin, a Chinese-speaking group linked to the Earth Berberoka cluster, turned compromised government and education websites in Brazil into infrastructure for a sustained SEO fraud campaign starting in mid-2025. The coverage said the group inserted malicious modules into Apache servers at government and educational bodies, and redirected legitimate traffic to gambling and phishing pages while keeping the appearance of browsing under the same domain.

Infosecurity Magazine said the compromised organizations included federal, state and municipal agencies, as well as a national public agency, a state legislative assembly, audit courts and a state-owned utilities company. Check Point's statement in Japan added that the phishing pages impersonated app stores such as Google Play, Microsoft Store and Amazon, with versions in Brazilian Portuguese, Vietnamese, Spanish and English. Nivel4 said the campaign has been active since mid-2025, seeks to hijack traffic and manipulate search rankings at scale, and uses redirect chains across compromised domains, many of them government-owned.

Sources

View all