logo

Insights on Cyber Threats Targeting Users and Enterprises in Mexico

ID: ecb9d32b-a061-5d3e-8ebd-5451d815a21b

STIX ID: report--ecb9d32b-a061-5d3e-8ebd-5451d815a21b

Feed Name: Google Cloud Threat Intelligence

Threat Score
75/100

Date Published: 2024-09-10

Date Updated: 2026-04-27

Author: Threat Analysis Group

...
...

This report summarizes observed cyber espionage and cybercrime activity targeting users and organizations in Mexico since 2020, highlighting PRC-, North Korean-, and Russian-linked phishing campaigns, the presence and misuse of commercial spyware against journalists and officials, and financially motivated operations (ransomware, credential theft, cryptomining). It identifies common initial-access vectors (phishing, malvertising, infected USBs, password spray), names malware families seen in the region (METAMORFO/Horabot, BBtok, JanelaRAT), and notes the proliferation of surveillance tooling and initial access brokers that enable broader extortion and data-theft campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.