News Room
16
Share
mediumCyber Espionage

Recent Cyber Espionage Activities Targeting Latin American Entities

Recent cyber espionage campaigns have intensified in Latin America, with APT groups employing sophisticated tactics to infiltrate government and corporate networks.

₿

Encrygma is selling the entire Full Cyber Weapon Research of Recent Cyber Espionage Activities Targeting Latin American Entities for ₿ 0.10 BTC. Contact us.

27 March 2026Last updated 27 March 20265 min readRaptor Cyber Intelligence
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Cyber Espionage
Severity:
Medium
Actor Type:
APT
Geography:
Latin America
Confidence:
Confirmed
Source:
Raptor Cyber Intelligence
Read Time:
5 min

Introduction

In early 2026, Latin America has witnessed a surge in cyber espionage activities, with Advanced Persistent Threat (APT) groups deploying advanced techniques to infiltrate government and corporate networks. These operations aim to steal sensitive information, disrupt operations, and gain strategic advantages.

Resurgence of Careto APT

The Careto APT group, previously inactive since 2013, resurfaced in May 2024 with two sophisticated cyber espionage campaigns targeting organizations in Latin America and Central Africa. Utilizing a multimodal framework, Careto's malware enabled microphone recording, file theft, and full system control. The initial infection vector involved compromising email servers running MDaemon software, followed by deploying a distinct backdoor to gain network control. The malware targeted confidential documents, browser data, and login credentials, highlighting Careto's advanced operational capabilities. (usa.kaspersky.com)

BlindEagle's Evolving Tactics

Active since at least 2018, BlindEagle (also known as APT-C-36) has been observed refining its tactics and expanding its reach across Latin America. In May and June 2024, the group focused on individuals and organizations within Colombia, with the region accounting for about 87% of victims. BlindEagle's primary targets include government institutions, energy and oil & gas companies, and financial organizations in Colombia, Ecuador, Chile, Panama, and other Latin American countries. The group's objectives remain consistent: espionage and theft of financial information. (cybersecurefox.com)

Chinese-Speaking APT Activities

Chinese-speaking APT groups have also intensified their operations in Latin America. In the fourth quarter of 2025, Kaspersky researchers identified a new wave of Windows Server infections linked to the PassiveNeuron campaign, previously described in 2024. These infections were observed in government, financial, and industrial organizations across Asia, Africa, and Latin America. The initial infection vector was identified as an SQL Server compromise, suspected to have been carried out using the SQLMap tool. Following the compromise, the attackers deployed web shells and used custom backdoors like Neursite and NeuralExecutor, as well as Cobalt Strike implants, to conduct further malicious activity on the infected machines. (ics-cert.kaspersky.com)

Implications and Recommendations

The resurgence of Careto and the evolving tactics of BlindEagle underscore the persistent and sophisticated nature of cyber espionage in Latin America. Chinese-speaking APT groups' activities further complicate the threat landscape. Organizations in the region must enhance their cybersecurity posture by implementing robust security measures, conducting regular security audits, and fostering a culture of awareness to mitigate the risks associated with these advanced threats.

The dynamic nature of cyber threats necessitates continuous monitoring and adaptation of defense strategies to safeguard sensitive information and maintain operational integrity.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo