Mercenary Spyware and Exploit Brokers: A Rising Threat in Latin America's Cybersecurity Landscape
Mercenary spyware and exploit brokers are increasingly targeting Latin America, posing significant risks to organizations in the region. This briefing examines the current threat landscape, focusing on ransomware groups leveraging commercial offensive tools and surveillance-as-a-service.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- High
- Actor Type:
- Ransomware Group
- Geography:
- Latin America
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Introduction
In early 2026, Latin America has witnessed a surge in cyber threats, particularly from ransomware groups utilizing mercenary spyware and exploit brokers. These actors employ sophisticated commercial offensive tools and surveillance-as-a-service models, posing significant risks to organizations across the region.
Mercenary Spyware and Exploit Brokers
Mercenary spyware refers to surveillance tools developed by private companies and sold to government agencies or other entities. These tools often exploit zero-day vulnerabilities to gain unauthorized access to target systems. Notable examples include:
-
Cytrox: Established in 2017, Cytrox specializes in malware used for cyberattacks and covert surveillance. Its "Predator" spyware has been linked to targeting politicians and journalists in various countries. (en.wikipedia.org)
-
Candiru: Founded in 2014, Candiru provides spyware and cyber-espionage services to government clients. Their products exploit zero-day vulnerabilities to deploy persistent spyware implants, enabling remote control of victim devices. (en.wikipedia.org)
These companies often operate under the guise of providing legitimate surveillance capabilities to law enforcement and intelligence agencies. However, their tools have been found to target a wide range of individuals, including dissidents, journalists, and political figures, raising significant ethical and legal concerns.
Commercial Offensive Tools and Red Team Frameworks
The proliferation of commercial offensive tools has democratized cyber capabilities, allowing even less technically skilled actors to conduct sophisticated attacks. For instance, the "Coruna" exploit kit has been observed targeting iOS devices, demonstrating the accessibility of advanced cyberattack tools. (en.wikipedia.org)
Red team frameworks, such as "RedTeamLLM," utilize large language models to automate penetration testing tasks, enhancing the efficiency and effectiveness of security assessments. (arxiv.org)
Surveillance-as-a-Service and Ransomware Groups
The rise of surveillance-as-a-service models has blurred the lines between state-sponsored and criminal cyber activities. Ransomware groups are increasingly leveraging commercial surveillance tools to enhance their operations. For example, the "Werewolves" group has been observed using tools like Anydesk, Netscan, CobaltStrike, Meterpreter, and Lockbit in their attacks. (ics-cert.kaspersky.com)
In August 2024, Google analysts found evidence that Russian state-backed hackers used exploits identical or similar to those sold by commercial spyware vendors NSO Group and Intellexa. (arstechnica.com)
Implications for Latin America
The convergence of mercenary spyware, exploit brokers, and ransomware groups poses a high-level threat to organizations in Latin America. The region's growing digital infrastructure and economic significance make it an attractive target for cybercriminals seeking financial gain and geopolitical leverage.
Recommendations
Organizations in Latin America should adopt a proactive cybersecurity posture by:
-
Regularly updating and patching systems to mitigate known vulnerabilities.
-
Conducting comprehensive security assessments to identify and address potential weaknesses.
-
Implementing robust monitoring and incident response plans to detect and respond to cyber threats promptly.
-
Engaging in information sharing and collaboration with regional and international cybersecurity communities to stay informed about emerging threats and best practices.
Conclusion
The landscape of cyber threats in Latin America is evolving, with ransomware groups increasingly leveraging mercenary spyware and exploit brokers. By understanding these dynamics and implementing proactive security measures, organizations can better defend against the growing cyber threat landscape.
Highlights:
- Commercial spyware vendor exploits used by Kremlin-backed hackers, Google says - Ars Technica, Published on Wednesday, August 28
- Google Catches Russian APT Reusing Exploits From Spyware Merchants NSO Group, Intellexa - SecurityWeek, Published on Wednesday, August 28
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Global Surge in Mercenary Spyware Attacks Triggers Massive Apple Security Alert Wave

New Pegasus Zero-Click Exploits Target Activists as Global Mercenary Spyware Campaigns Intensify

