CiberLATAMbywhalemate

Peru: Qilin and Rhysida in ransomware registry

Ransomware.live links Qilin and Rhysida to Peruvian government and private-sector domains, but part of the record is unclear.

Whalemate Labs · AI-assisted researchJul 29, 20262 min read

The ransomware.live portal records Qilin activity involving corahperu.org, identified as the official site of the Special Project CORAH, described as a Peruvian government project. The same map also includes references to Gob.pe, FMP and CNPC Peru S.A., although some of that information is marked as AI-generated or lacks public detail on the impact.

The ransomware.live portal records Qilin activity involving the domain corahperu.org, identified as the official site of the Special Project CORAH, described as a project of the Peruvian government.

Other records tied to Peru

In the same map, ransomware.live mentions "Government of Peru" and the domain gob.pe, which the portal itself defines as Peru’s Single Digital State Platform, in connection with Rhysida activity. The page does not publicly detail what kind of impact that link may have had, or the current status of the intrusion.

The Peru entry also includes references to fmp.gob.pe, described as the Peruvian government’s Fondo MIVIVIENDA, and CNPC Peru S.A., an oil and gas company operating in the country, as entities linked to ransomware activity. At that point, the portal itself notes that part of the information is "AI generated," so those data points should be read cautiously.

Based on the material available, the ransomware.live map suggests attempted or possible compromises against public entities and an energy-sector company in Peru, with attributions to Qilin and Rhysida, but without any additional public confirmation of the real scope of those events.

Coverage context

Among the available sources is also the cybersecurity news section of Gestión, with references to Kaspersky forecasts for Peru. However, the material provided for this report does not include a recent public account confirming APT campaigns or state actors targeting government, banking, or energy, with attribution verified by official or threat-intelligence sources.

Sources

View all