Hacktivist Cyber Espionage Campaigns Intensify in Latin America Amid Rising Threats
Hacktivist groups in Latin America are increasingly targeting government and corporate entities, employing sophisticated cyber espionage tactics to extract sensitive information and disrupt operations.
Encrygma is selling the entire Full Cyber Weapon Research of Hacktivist Cyber Espionage Campaigns Intensify in Latin America Amid Rising Threats for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- High
- Actor Type:
- Hacktivist
- Geography:
- Latin America
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
In early 2026, Latin America has witnessed a significant surge in cyber espionage activities attributed to hacktivist groups. These actors are leveraging advanced techniques to infiltrate government and corporate networks, aiming to extract sensitive information and disrupt operations.
Emergence of APT-C-36
A notable threat actor in this landscape is APT-C-36, also known as Blind Eagle or Blind Spider. Active since 2018, APT-C-36 has primarily targeted government ministries, financial institutions, telecommunications providers, and educational sectors across South America. Their operations blend intelligence collection with financial motives, often using phishing campaigns that impersonate tax authorities or law enforcement to deliver malicious payloads. Once inside, they deploy remote access tools like AsyncRAT, QuasarRAT, and BitRAT to maintain persistence and exfiltrate data. (brandefense.io)
Guacamaya Group's Activism
Another significant actor is the Guacamaya group, an international collective operating mainly in Central and Latin America. Motivated by anti-imperialism and environmentalism, Guacamaya has targeted major corporations and governments in countries such as Chile, Colombia, El Salvador, Guatemala, Mexico, and Peru. Their operations often involve publishing sensitive files and reports to the public, aiming to expose perceived injustices and corporate malpractices. (en.wikipedia.org)
Rising Cyberattack Trends
The overall cyber threat landscape in Latin America has become increasingly hostile. In December 2025, organizations in the region experienced an average of 3,065 cyberattacks per week, marking a 26% year-over-year increase. This surge is driven by ransomware operations and the expanding exposure linked to enterprise adoption of generative AI technologies. (blog.checkpoint.com)
Defensive Measures and Recommendations
To counteract these evolving threats, organizations in Latin America should implement the following defensive strategies:
-
Localized Awareness Training: Develop training programs focused on local phishing techniques and social engineering tactics to enhance employee vigilance.
-
Behavioral Detection Systems: Deploy security solutions that monitor for unusual behaviors, such as abnormal PowerShell executions or unauthorized command and control communications, to detect and mitigate attacks.
-
Network Segmentation and Zero Trust Models: Implement network segmentation to limit lateral movement and adopt zero trust architectures to monitor user activities and prevent privilege escalation.
-
Regional Intelligence Sharing: Collaborate with local cybersecurity entities and private sector organizations to share threat intelligence, disrupt adversary infrastructure, and respond swiftly to emerging threats.
By adopting these measures, organizations can bolster their defenses against the growing cyber espionage activities in the region.
Highlights:
- APT-C-36: Latin America’s Persistent Cyber-Espionage Force - Brandefense, Published on Wednesday, February 18
- Latin America sees sharp rise in ransomware, hacktivist attacks in 2025 amid expanding fraud and phishing threats, Published on Tuesday, February 17
- Cyber Attacks Surge in Latin America | Dec 2025, Published on Monday, January 12
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



