Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Cybercriminals Are Worried About AI Taking Their Jobs Too

June 18, 2026

China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance

June 18, 2026

LATAM Infrastructure Hit by Fortinet and Ivanti Exploits

June 18, 2026
Facebook X (Twitter) Instagram
Thursday, June 18
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»LATAM Infrastructure Hit by Fortinet and Ivanti Exploits
Cyber Security

LATAM Infrastructure Hit by Fortinet and Ivanti Exploits

Team-CWDBy Team-CWDJune 18, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A coordinated campaign against government and financial targets across Latin America has been laid bare by the attackers’ own mistake, after they left a staging server exposed online.

New analysis from CloudSEK detailed the operation, which it named Operation Escaneo, after researchers found an open directory on the group’s server in early 2026 and mapped its toolkit from the artifacts left behind.

The campaign hit critical infrastructure across Mexico, with lesser activity in Ecuador and Portugal, spanning government, tax authorities, utilities, transport, telecoms and banks.

CloudSEK said it confirmed beacons from at least five victims and large-scale data theft.

Breaking In Through the Perimeter

Entry came mainly through internet-facing security appliances. The group kept tuned exploits for Fortinet FortiOS SSL-VPN flaws, including CVE-2022-42475 and CVE-2024-21762, and Ivanti Connect Secure flaws CVE-2023-46805, CVE-2024-21887 and CVE-2025-0282, adapting public proof-of-concept (PoC) code so it would not crash the target.

Its reach went well beyond perimeter gear, with exploits for Apache Tomcat’s GhostCat flaw, the Windows bugs EternalBlue and Zerologon and Log4Shell.

All of it was fed by a custom reconnaissance engine the group calls Kimera, which CloudSEK said scanned and triaged targets at high speed, then handed them straight to the exploitation stage.

Read more on attacks targeting Mexican infrastructure: OpenAI and Anthropic LLMs Used in Critical Infrastructure Cyber-Attack

Tunnels, Routers and Stolen Data

To stay connected, the group layered its access. Neo-reGeorg webshells gave encrypted footholds on web servers, Chisel reverse tunnels carried traffic over HTTP and a compromised Cisco router was fitted with a GRE tunnel pointing back to the attackers, a network-level channel invisible to host-based defenses.

Chisel logs alone recorded 3,708 sessions over a 13-day window.

Inside victim networks, the attackers reached SAP and Oracle systems to run commands and pulled out a large volume of sensitive data, including:

  • More than 1.3 million personal records from one transport provider

  • A 407MB map of a victim’s Active Directory

  • SSL private keys, streamed out live from a database server

  • SAP service-account hashes and browser-stored passwords

A Suspected Hacktivist Link

CloudSEK attributed the campaign, with medium confidence, to a group it calls Mexican Mafia, or Pancho Villa, which spent 2024 claiming breaches against Mexican government, judicial and energy targets, sometimes casting the hacks as protest.

The firm hedged the link, noting some of the group’s past claims have been disputed by the organizations named.

Regardless of the link, CloudSEK urged Latin American organizations to patch perimeter appliances first, singling out the Fortinet and Ivanti flaws and to watch for the operation’s quieter tells.

These include GRE tunnels reaching external addresses, Chisel’s TCP-over-HTTP traffic and unexpected commands running through SAP and Oracle.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleHostile States Behind 75% of Cyber-Attacks on UK CNI, NCSC Warns
Next Article China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance
Team-CWD
  • Website

Related Posts

Cyber Security

Staffing Is Top SOC Challenge Even as AI Proliferates, Says SANS

June 18, 2026
Cyber Security

Sensitive Enterprise Data Uploads to AI Models Double in a Year

June 17, 2026
Cyber Security

Rokarolla Trojan Combines Banking Fraud With Device Surveillance

June 16, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

What it is and how to protect yourself

January 8, 2026

Why geopolitical turmoil is a gift for scammers, and how to stay safe

May 15, 2026

Is it time for internet services to adopt identity verification?

January 14, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.