CiberLATAMbywhalemate

Qilin posts victims in Mexico, Chile

ZeroHour added new Qilin victims in Mexico, Chile, Argentina and Trinidad and Tobago. Panzer also listed Brazil’s K3G Solutions.

Whalemate Labs · AI-assisted researchPublished:2 min read

ZeroHour added Talleres Metropolitanos and Grupo Juste in Mexico, Futuro Forestal in Chile, Ceres Tolvas in Argentina and Inland and Offshore Contractors in Trinidad and Tobago to Qilin’s public victim page. In Brazil, Kalir Pulse and other trackers reported K3G Solutions in a case attributed to Panzer.

ZeroHour added Talleres Metropolitanos and Grupo Juste, both in Mexico and in the manufacturing sector, to Qilin’s public victim list. It also listed Futuro Forestal in Chile, Ceres Tolvas in Argentina and Inland and Offshore Contractors in Trinidad and Tobago, with sectors ranging from agriculture to business services and civil engineering construction.

What did this new batch of postings show?

ZeroHour placed the five cases on Qilin’s victim page with a Sept. 18, 2026 date. The available information confirms the public posting of those names, countries and business sectors, but it does not add details about the incident, the scope of access or whether the companies issued any official statement.

What is happening in Brazil?

In Brazil, Kalir Pulse identified K3G Solutions, a telecom and IT consultancy in Manaus, as a victim listed by the Panzer ransomware operation. Recent Breaches and Ransomware.live said a tracking source attributed a possible 300 GB exfiltration to the case, while another said the company has not confirmed the incident, the real number of affected parties is unknown and the posting did not specify what types of data may have been exposed.

What is known about Panzer and Qilin?

Cyware described Panzer as a ransomware-as-a-service operation that emerged in August 2026, with variants for Windows, Linux, FreeBSD and VMware ESXi. In its analysis, the ESXi variant could affect entire virtualized infrastructures, and the group would have used exposed VPN and RDP services, along with large-scale data transfers, with a focus on manufacturing and telecommunications.

The Hacker News also reported that Panzer appeared in early August 2026, that its affiliates operated on an 80/20 split and that it had cross-platform support for Windows, Linux, ESXi and FreeBSD. That report added activity in technology, manufacturing, government and education.

On the Qilin side, Security Arsenal reported 19 publicly posted victims in 72 hours in a recent window. In a sample of 15 cases with an identified sector, six were manufacturing and one was agriculture and food production, while the United States accounted for six of the 15. Scrutex, meanwhile, linked Qilin affiliates to exploitation of CVE-2026-50751 in Check Point Mobile Access, Remote Access VPN and Spark firewalls, and CVE-2026-0257 in Palo Alto Networks PAN-OS GlobalProtect, although that attribution is presented as third-party reporting and not as confirmation of the Latin American cases listed.

Sources

View all