Hacktivist Cyber Espionage Campaigns Target Latin American Governments and Corporations
Hacktivist groups have intensified cyber espionage activities in Latin America, targeting government agencies and corporations to steal sensitive information and disrupt operations.
Encrygma is selling the entire Full Cyber Weapon Research of Hacktivist Cyber Espionage Campaigns Target Latin American Governments and Corporations for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- Critical
- Actor Type:
- Hacktivist
- Geography:
- Latin America
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Executive Summary
In early 2026, hacktivist groups have escalated cyber espionage campaigns across Latin America, focusing on government agencies and corporations. These operations aim to steal sensitive information, disrupt operations, and advance ideological or political agendas. Notable groups involved include APT-C-36, Guacamaya, and Handala Hack Team.
APT-C-36: Persistent Cyber Espionage in South America
APT-C-36, also known as Blind Eagle or Blind Spider, has been active since 2018, primarily targeting government and financial entities in South America. The group employs a combination of open-source and commodity remote access tools (RATs) such as AsyncRAT, QuasarRAT, njRAT, and BitRAT, along with custom droppers designed to evade local antivirus solutions. These tools facilitate remote access, credential theft, and document exfiltration. Their operations are characterized by persistence through scheduled tasks, registry changes, and abuse of legitimate remote administration tools. (brandefense.io)
Guacamaya: Environmental Hacktivism and Data Leaks
Guacamaya, an international hacktivist group, has been active in Latin America, targeting major corporations and government entities in countries such as Chile, Colombia, El Salvador, Guatemala, Mexico, and Peru. The group is motivated by anti-imperialism and environmentalism, focusing on transnational corporations and external interventions in Latin America, particularly in sectors like mining and oil. Guacamaya has been known to publish anonymous reports and leak sensitive files through platforms like Distributed Denial of Secrets and Enlace Hacktivista. (en.wikipedia.org)
Handala Hack Team: Pro-Iranian Cyber Operations
The Handala Hack Team, linked to Iran's Ministry of Intelligence, has conducted cyber operations targeting Israeli energy firms, Jordanian fuel systems, and healthcare targets. Their activities include data breaches, website defacements, and DDoS attacks, aligning with pro-Iranian narratives. The group has also issued bounties for the beheadings of individuals and leaked personal information to affiliated groups. (en.wikipedia.org)
Impact on Latin American Governments and Corporations
The surge in hacktivist cyber espionage has placed significant pressure on Latin American governments and corporations. In December 2025, organizations in the region experienced an average of 3,065 cyber attacks per week, a 26% increase year-over-year, surpassing the global average. These attacks often involve data-leak extortion, credential-stealing campaigns, and exploitation of edge devices. (blog.checkpoint.com)
Recommendations
Organizations in Latin America should enhance their cybersecurity measures by implementing robust intrusion detection systems, conducting regular security audits, and training personnel to recognize phishing attempts. Collaboration with international cybersecurity agencies and sharing threat intelligence can also bolster defenses against these evolving cyber threats.
Conclusion
Hacktivist cyber espionage campaigns in Latin America are increasingly sophisticated and pose significant risks to governmental and corporate entities. Proactive measures and international cooperation are essential to mitigate these threats and safeguard sensitive information.
Highlights:
- Cyberattacks Intensify Pressure on Latin American Governments, Published on Tuesday, March 31
- Surging Cyberattacks Boost Latin America to Riskiest Region, Published on Tuesday, January 27
- Cyber Attacks Surge in Latin America | Dec 2025, Published on Monday, January 12
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Russian State-Nexus Cluster GTG-20006 Weaponizes AI for Automated Espionage Operations

China-Nexus 'Antino' Backdoor Targets Asian Government Networks via Cloud Infrastructure

