Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Researchers Trick AI Browsers Into Leaking Credentials

June 24, 2026

Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting

June 24, 2026

macOS Backdoor Uses Prompt Injection to Evade AI Triage

June 24, 2026
Facebook X (Twitter) Instagram
Wednesday, June 24
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»LATAM Infrastructure Hit by Fortinet and Ivanti Exploits
Cyber Security

LATAM Infrastructure Hit by Fortinet and Ivanti Exploits

Team-CWDBy Team-CWDJune 18, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A coordinated campaign against government and financial targets across Latin America has been laid bare by the attackers’ own mistake, after they left a staging server exposed online.

New analysis from CloudSEK detailed the operation, which it named Operation Escaneo, after researchers found an open directory on the group’s server in early 2026 and mapped its toolkit from the artifacts left behind.

The campaign hit critical infrastructure across Mexico, with lesser activity in Ecuador and Portugal, spanning government, tax authorities, utilities, transport, telecoms and banks.

CloudSEK said it confirmed beacons from at least five victims and large-scale data theft.

Breaking In Through the Perimeter

Entry came mainly through internet-facing security appliances. The group kept tuned exploits for Fortinet FortiOS SSL-VPN flaws, including CVE-2022-42475 and CVE-2024-21762, and Ivanti Connect Secure flaws CVE-2023-46805, CVE-2024-21887 and CVE-2025-0282, adapting public proof-of-concept (PoC) code so it would not crash the target.

Its reach went well beyond perimeter gear, with exploits for Apache Tomcat’s GhostCat flaw, the Windows bugs EternalBlue and Zerologon and Log4Shell.

All of it was fed by a custom reconnaissance engine the group calls Kimera, which CloudSEK said scanned and triaged targets at high speed, then handed them straight to the exploitation stage.

Read more on attacks targeting Mexican infrastructure: OpenAI and Anthropic LLMs Used in Critical Infrastructure Cyber-Attack

Tunnels, Routers and Stolen Data

To stay connected, the group layered its access. Neo-reGeorg webshells gave encrypted footholds on web servers, Chisel reverse tunnels carried traffic over HTTP and a compromised Cisco router was fitted with a GRE tunnel pointing back to the attackers, a network-level channel invisible to host-based defenses.

Chisel logs alone recorded 3,708 sessions over a 13-day window.

Inside victim networks, the attackers reached SAP and Oracle systems to run commands and pulled out a large volume of sensitive data, including:

  • More than 1.3 million personal records from one transport provider

  • A 407MB map of a victim’s Active Directory

  • SSL private keys, streamed out live from a database server

  • SAP service-account hashes and browser-stored passwords

A Suspected Hacktivist Link

CloudSEK attributed the campaign, with medium confidence, to a group it calls Mexican Mafia, or Pancho Villa, which spent 2024 claiming breaches against Mexican government, judicial and energy targets, sometimes casting the hacks as protest.

The firm hedged the link, noting some of the group’s past claims have been disputed by the organizations named.

Regardless of the link, CloudSEK urged Latin American organizations to patch perimeter appliances first, singling out the Fortinet and Ivanti flaws and to watch for the operation’s quieter tells.

These include GRE tunnels reaching external addresses, Chisel’s TCP-over-HTTP traffic and unexpected commands running through SAP and Oracle.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleHostile States Behind 75% of Cyber-Attacks on UK CNI, NCSC Warns
Next Article China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance
Team-CWD
  • Website

Related Posts

Cyber Security

UK Museums Face Cybersecurity Risks, MPs Warn

June 24, 2026
Cyber Security

Trump Issues Executive Order to Fast-Track Post-Quantum Migration

June 23, 2026
Cyber Security

Microsoft Attributes Mastra AI Supply Chain Attack to North Korea

June 22, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

What’s at stake if your employees post too much online

December 1, 2025

How the always-on generation can level up their cybersecurity game

September 11, 2025

Here’s how to avoid a ‘second strike’

April 11, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.