logo

Top 10 Cyber Threat Actors Targeting Brazil

ID: 15b20552-7f7e-5c50-b020-04d148416e10

STIX ID: report--15b20552-7f7e-5c50-b020-04d148416e10

Feed Name: SOCRadar Blog

Threat Score
90/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: Ameer Owda

...
...

This SOCRadar report profiles the top 10 threat actors targeting Brazil in 2025–2026, detailing active ransomware groups (LockBit 5.0, Qilin, Akira, The Gentlemen, KillSec, Cl0p, DragonForce), a China-linked APT (Salt Typhoon), and a long-running Brazilian cybercrime syndicate (TA2725). It highlights large-scale, high-impact incidents including the Petrobras seismic data theft (~176 GB) and the FGV university breach (~1.52 TB), ongoing mass-exploitation campaigns (Oracle EBS zero-day), and active malware campaigns (Grandoreiro, BTMOB RAT), concluding that Brazil faces widespread, sophisticated, and ongoing cyber threats across critical sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.