Insights on Cyber Threats Targeting Users and Enterprises in Mexico
ID: ecb9d32b-a061-5d3e-8ebd-5451d815a21b
STIX ID: report--ecb9d32b-a061-5d3e-8ebd-5451d815a21b
Feed Name: Google Cloud Threat Intelligence
This report summarizes observed cyber espionage and cybercrime activity targeting users and organizations in Mexico since 2020, highlighting PRC-, North Korean-, and Russian-linked phishing campaigns, the presence and misuse of commercial spyware against journalists and officials, and financially motivated operations (ransomware, credential theft, cryptomining). It identifies common initial-access vectors (phishing, malvertising, infected USBs, password spray), names malware families seen in the region (METAMORFO/Horabot, BBtok, JanelaRAT), and notes the proliferation of surveillance tooling and initial access brokers that enable broader extortion and data-theft campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
