logo

Operation Escaneo Targets LATAM Infrastructure with Fortinet and Ivanti Exploits

ID: 218e8800-687d-59da-b9f7-1fa263768d45

STIX ID: report--218e8800-687d-59da-b9f7-1fa263768d45

Feed Name: ThreatCluster

Threat Score
80/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

...
...

Operation Escaneo targeted critical infrastructure across Latin America (primarily Mexico) by exploiting Fortinet and Ivanti vulnerabilities to gain access to government and financial systems; attackers used a custom reconnaissance tool (Kimera), Neo-reGeorg webshells and Chisel reverse tunnels to maintain access and exfiltrate over 1.3 million personal records. CloudSEK attributes the campaign to the Mexican Mafia (Pancho Villa) with medium confidence and notes that exposure was aided by a misconfigured staging server; organizations are advised to patch affected appliances and monitor for unusual network activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.