Operation Escaneo Targets LATAM Infrastructure with Fortinet and Ivanti Exploits
ID: 218e8800-687d-59da-b9f7-1fa263768d45
STIX ID: report--218e8800-687d-59da-b9f7-1fa263768d45
Feed Name: ThreatCluster
Operation Escaneo targeted critical infrastructure across Latin America (primarily Mexico) by exploiting Fortinet and Ivanti vulnerabilities to gain access to government and financial systems; attackers used a custom reconnaissance tool (Kimera), Neo-reGeorg webshells and Chisel reverse tunnels to maintain access and exfiltrate over 1.3 million personal records. CloudSEK attributes the campaign to the Mexican Mafia (Pancho Villa) with medium confidence and notes that exposure was aided by a misconfigured staging server; organizations are advised to patch affected appliances and monitor for unusual network activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
