Recent Cyber Espionage Activities Targeting Latin American Entities
Recent cyber espionage campaigns have intensified in Latin America, with APT groups employing sophisticated tactics to infiltrate government and corporate networks.
Encrygma is selling the entire Full Cyber Weapon Research of Recent Cyber Espionage Activities Targeting Latin American Entities for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- Medium
- Actor Type:
- APT
- Geography:
- Latin America
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Introduction
In early 2026, Latin America has witnessed a surge in cyber espionage activities, with Advanced Persistent Threat (APT) groups deploying advanced techniques to infiltrate government and corporate networks. These operations aim to steal sensitive information, disrupt operations, and gain strategic advantages.
Resurgence of Careto APT
The Careto APT group, previously inactive since 2013, resurfaced in May 2024 with two sophisticated cyber espionage campaigns targeting organizations in Latin America and Central Africa. Utilizing a multimodal framework, Careto's malware enabled microphone recording, file theft, and full system control. The initial infection vector involved compromising email servers running MDaemon software, followed by deploying a distinct backdoor to gain network control. The malware targeted confidential documents, browser data, and login credentials, highlighting Careto's advanced operational capabilities. (usa.kaspersky.com)
BlindEagle's Evolving Tactics
Active since at least 2018, BlindEagle (also known as APT-C-36) has been observed refining its tactics and expanding its reach across Latin America. In May and June 2024, the group focused on individuals and organizations within Colombia, with the region accounting for about 87% of victims. BlindEagle's primary targets include government institutions, energy and oil & gas companies, and financial organizations in Colombia, Ecuador, Chile, Panama, and other Latin American countries. The group's objectives remain consistent: espionage and theft of financial information. (cybersecurefox.com)
Chinese-Speaking APT Activities
Chinese-speaking APT groups have also intensified their operations in Latin America. In the fourth quarter of 2025, Kaspersky researchers identified a new wave of Windows Server infections linked to the PassiveNeuron campaign, previously described in 2024. These infections were observed in government, financial, and industrial organizations across Asia, Africa, and Latin America. The initial infection vector was identified as an SQL Server compromise, suspected to have been carried out using the SQLMap tool. Following the compromise, the attackers deployed web shells and used custom backdoors like Neursite and NeuralExecutor, as well as Cobalt Strike implants, to conduct further malicious activity on the infected machines. (ics-cert.kaspersky.com)
Implications and Recommendations
The resurgence of Careto and the evolving tactics of BlindEagle underscore the persistent and sophisticated nature of cyber espionage in Latin America. Chinese-speaking APT groups' activities further complicate the threat landscape. Organizations in the region must enhance their cybersecurity posture by implementing robust security measures, conducting regular security audits, and fostering a culture of awareness to mitigate the risks associated with these advanced threats.
The dynamic nature of cyber threats necessitates continuous monitoring and adaptation of defense strategies to safeguard sensitive information and maintain operational integrity.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



