CiberLATAMbywhalemate

Qilin and Fortinet Exploitation Keep Pressure on Chile as

Chile faced 8.8 billion cyberattack attempts in 2025, and between January and June 2026

Whalemate Labs · AI-assisted researchPublished:38 min read

Chile came under 8.8 billion cyberattack attempts in 2025, according to a regional report cited by G5 Noticias and La Tercera. That figure did not stand alone. The same SEK study, summarized by G5 Noticias and Zoom Tecnológico, recorded 58 incidents affecting or exposing Chilean organizations between January and June 2026. Of those, 18 ended up as data posts on ransomware leak sites and 40 appeared in dark web cybercrime forums. Within that ransomware subset, Qilin accounted for 61 percent of the leak-site posts, with 11 of 18 victims, making it the most active actor targeting Chile in that period.

Executive summary

Chile faced 8.8 billion cyberattack attempts during 2025, according to SEK’s regional report cited by G5 Noticias and La Tercera. That number does not by itself describe a specific intrusion, but it does show the scale of pressure on Chilean organizations. The same SEK research, also summarized by Zoom Tecnológico, recorded 58 incidents affecting or exposing Chilean organizations between January and June 2026. Of those, 18 became data posts on ransomware leak sites and 40 appeared in dark web cybercrime forums. Within the ransomware slice, Qilin accounted for 61 percent of the leak-site posts, with 11 of 18 victims, and was identified as the most active actor against Chile during that period.

The technical picture is consistent across several sources. Qilin, also known as Agenda, has operated as ransomware-as-a-service since 2022, encrypts Windows, Linux and VMware ESXi environments, and uses double extortion. Its initial access chain combines phishing, stolen credentials and exposed remote services, with a clear preference for VPN gateways and edge devices. The consolidated material repeatedly points to two Fortinet flaws, CVE-2024-21762 and CVE-2024-55591, as initial access vectors tied to Qilin campaigns. The first affects FortiOS and FortiProxy in SSL VPN, allows remote code execution and has been in CISA’s KEV catalog since February 2024. The second is an authentication bypass in FortiOS and FortiProxy, disclosed in Fortinet’s PSIRT advisory FG-IR-24-535 and also listed as actively exploited.

The exploitation pattern is not theoretical. Scrutex.ai, Paubox, Viakoo, The Hacker News, Arctic Wolf, Hispasec, Devel Group and the Canadian Centre for Cyber Security describe mass credential-compromise campaigns against FortiGate devices exposed to the internet. Estimates range from more than 30,000 to 86,644 compromised devices, with references to tens of thousands of additional systems affected or exposed. Bitsight details the use of legacy SHA-256 hashes and an offline cracking infrastructure built around 45 GPUs. The Hacker News adds that Fortinet attributed the activity to credential reuse from earlier incidents, along with brute force against devices with weak passwords and no MFA. Devel Group, meanwhile, reported a custom tool, FortiGateSniffer, that abuses the native diagnose sniffer packet command to silently intercept authentication and maintain persistence.

The regional dimension shows the Chile case is not isolated. Ransomware.live records 74 victims linked to Chilean organizations and lists Qilin victims on multiple dates in 2026, including Valbifrut, Graneles de Chile, Noi Hotels, SAAM Towage, Calidra and Comercial Echave Turri Limitada. Paraguay appears in Ransomware.live and Legal-ISAC dashboards as a jurisdiction with at least one victim associated with Qilin, while Bolivia appears in Scrutex.ai’s tally and Brazil shows up as a regional exposure and activity hub, with parallel phishing campaigns and compromised emergency alerts. Taken together, the data point to a ransomware ecosystem that shares infrastructure, affiliates and access vectors, and where Fortinet functions as a repeated entry point.

Context and background

The material paints a scenario in which the threat does not depend on a single malware family, but on a mix of actors, affiliates and RaaS brands that share techniques and infrastructure. Qilin emerges as the dominant actor in ransomware leak-site posts against Chilean organizations, but it does not operate alone. Ransomware.live lists Chilean incidents also attributed to LockBit5, Incransom and Anubis. Red Piranha places Securotrop inside Qilin’s affiliate network, with confirmed infrastructure overlap and use of Qilin software without code changes. ESET, Group-IB and Securonix place The Gentlemen in the same leak-site ecosystem, with operators largely drawn from Qilin’s affiliate network.

Fortinet’s relevance in this corpus is not incidental. CVE-2024-21762 is a buffer overflow in FortiOS and FortiProxy SSL VPN that allows remote code execution or denial of service through specially crafted requests. CISA lists it in KEV. CVE-2024-55591, meanwhile, is an authentication bypass in FortiOS and FortiProxy, disclosed in the context of FortiBleed and patched by Fortinet across all affected versions, according to The Network DNA. The combination of both flaws appears in Scrutex.ai, Paubox, Viakoo and The Hacker News coverage as one of the paths Qilin may have used to automate initial access to exposed VPN gateways.

The FortiBleed campaign is not limited to one group, but it does expose a structural problem that helps explain some of Qilin’s success and that of neighboring actors. CSIRT Telconet reported more than 73,932 Fortinet firewall URLs compromised in 194 countries through credentials stolen by infostealers, with a pivot into Active Directory. Arctic Wolf raised the estimate of compromised FortiGate devices to 75,000, while The Hacker News put the figure at 86,644 as of June 19, 2026. Devel Group added operational detail by describing a Russian-origin Initial Access Broker and a Go tool called FortiGateSniffer. In practice, the issue is no longer just the exploitation of a CVE, but the accumulation of credentials, exposed configurations, open external administration and the lack of MFA.

In Chile, that exposure overlaps with sectors that appear repeatedly in the SEK report: Government with 10 combined incidents, Finance with 8, Education with 6, Health with 6, and Energy or Mining with 5. The pressure also reaches tourism through NOI Hotels, and industrial and logistics sectors, considering the Chilean Qilin victims recorded by Ransomware.live. The picture is one of a market hit by volume, but also by target selection. Initial access is sought on vulnerable perimeters and then monetized through data theft, hypervisor encryption and public extortion.

Operational timeline2024-02CVE-2024-21762in KEV2026-06-08Securotropaffiliated withQilin2026-06-15Scrutex:Fortinet asvector2026-06-17Telconet:FortiBleedwidespread2026-06-26Ransomware.live:74 victims inChile2026-07-06SEK: 8.8trillionattempts
Qilin, FortiBleed, and the pressure on Chile — timeline — Verifiable milestones from 2024 through July 2026, focusing on Fortinet, Qilin, and the rise in incidents in Chile.

Key facts table

Date Event Source Confidence
2024-02 CVE-2024-21762 enters CISA’s KEV catalog as an actively exploited vulnerability Jimber, CISA confirmed
2026-06-08 Red Piranha describes Securotrop as a Qilin-affiliated brand with infrastructure overlap Red Piranha confirmed
2026-06-09 CISA gives U.S. agencies three days to patch CVE-2024-21762 because of active exploitation linked to Qilin DiarioBitcoin confirmed
2026-06-15 Scrutex.ai identifies CVE-2024-21762 and CVE-2024-55591 as Qilin initial access vectors Scrutex.ai confirmed
2026-06-15 Check Point Research documents exploitation of CVE-2026-50751 and links at least one case to Qilin Check Point Research confirmed
2026-06-16 ProvenData models Qilin’s attack chain and detection signals ProvenData confirmed
2026-06-17 CSIRT Telconet warns about FortiBleed and more than 73,932 compromised URLs CSIRT Telconet confirmed
2026-06-18 Canada issues AL26-014 and urges immediate patches for CVE-2024-55591 Canadian Centre for Cyber Security confirmed
2026-06-18 Bitsight reports offline cracking using 45 GPUs against FortiOS credentials Bitsight confirmed
2026-06-19 The Hacker News counts 86,644 FortiGate devices compromised through FortiBleed The Hacker News confirmed
2026-06-23 Devel Group reports FortiGateSniffer and ghost accounts on Fortinet firewalls Devel Group confirmed
2026-06-25 Hispasec recommends credential rotation, MFA and reduced exposure Hispasec confirmed
2026-06-26 Ransomware.live records 74 victims in Chile and multiple Qilin cases Ransomware.live confirmed
2026-07-01 La Tercera reports that Chile received more than eight billion attack attempts in 2025 La Tercera confirmed
2026-07-02 G5 Noticias and Zoom Tecnológico summarize 58 incidents in Chile between January and June 2026 G5 Noticias, Zoom Tecnológico confirmed
2026-07-02 Comparitech ranks Qilin as the most prolific group in H1 2026 Comparitech confirmed
2026-07-06 G5 Noticias reports 8.8 billion attempts in Chile during 2025 and 61% of DLS posts for Qilin G5 Noticias confirmed

Operation timeline

Date Event Actor/vector Verified source
2024-02 CVE-2024-21762 is treated as an actively exploited vulnerability Fortinet, CISA Jimber, CISA
2026-06-08 Securotrop is described as a Qilin affiliate with overlapping infrastructure Qilin ecosystem Red Piranha
2026-06-09 CISA gives U.S. agencies three days to patch a critical Fortinet flaw associated with Qilin CVE-2024-21762 exploitation DiarioBitcoin
2026-06-15 Scrutex.ai identifies CVE-2024-21762 and CVE-2024-55591 as entry points used by Qilin Fortinet SSL VPN, FortiProxy Scrutex.ai
2026-06-15 Check Point Research confirms active exploitation of CVE-2026-50751 with one case linked to Qilin Remote access VPN Check Point Research
2026-06-16 ProvenData summarizes Qilin’s attack chain, with compromised VPNs, phishing and ESXi Ransomware-as-a-service ProvenData
2026-06-17 Telconet publishes on FortiBleed and large-scale compromise of Fortinet URLs Stolen credentials, SSL VPN CSIRT Telconet
2026-06-18 Canada, Bitsight and Fortinet describe the scope of the compromise and offline cracking FortiOS credentials, CVE-2024-55591 Canadian Centre for Cyber Security, Bitsight, The Network DNA
2026-06-19 The Hacker News reports 86,644 FortiGate devices compromised through FortiBleed Automated two-stage attack The Hacker News
2026-06-23 Devel Group publishes on FortiGateSniffer and fake administrative accounts Persistence, authentication sniffing Devel Group
2026-06-25 Hispasec stresses password rotation and MFA as defensive priorities FortiGate hardening Hispasec
2026-06-26 Ransomware.live consolidates 74 Chilean victims on its map DLS and multiple attributions Ransomware.live
2026-07-01 La Tercera describes attack volume and Qilin and The Gentlemen activity in Chile RaaS, poorly managed cloud, double extortion La Tercera
2026-07-02 G5 Noticias and Zoom Tecnológico summarize 58 incidents in Chile and Qilin’s 61% share of DLS posts DLS, dark web, targeted sectors G5 Noticias, Zoom Tecnológico
2026-07-02 Comparitech quantifies 4,217 global ransomware attacks in H1 2026 and says Qilin leads the ranking Leak sites worldwide Comparitech
2026-07-06 SEK, via G5 Noticias, places Chile at 8.8 billion attempts and Qilin as the main DLS actor Regional pressure and ransomware G5 Noticias

Attack chain and TTPs

The Qilin attack chain described in the consolidated material follows a repeated structure. Initial access comes first. The sources do not show a single method, but rather a hybrid pattern built on phishing, stolen credentials, exposed remote services and exploitation of edge appliances. In the Fortinet case, Scrutex.ai, Paubox and Viakoo place CVE-2024-21762 and CVE-2024-55591 among the most relevant entry points. The first allows remote code execution through SSL VPN. The second enables authentication bypass. Together, they create a path for large-scale automation against FortiGate and FortiProxy firewalls that remain exposed or out of date.

After entry, the sources describe internal reconnaissance and lateral movement. LinkedIn’s June 9, 2026 analysis of Qilin mentions RDP, SMB and WMI as mechanisms used to move across networks. ProvenData adds anomalous VPN or RDP authentications, domain admin activity from non-administrative workstations, mass LSASS access correlated with lateral movement, bulk deletion of shadow copies and simultaneous service termination as high-value signals. The end goal is to reach higher-impact systems, especially VMware ESXi hypervisors, because encrypting the hypervisor can take down multiple workloads at once.

Extortion happens on two tracks. The technical track uses encryption across Windows, Linux and ESXi. The public pressure track relies on prior data theft, threats to publish or sell the data, contact through email and Tor chats, and a price increase after 72 hours, according to the Qilin material on LinkedIn. That double-extortion component explains why leak sites are central to the ecosystem. The damage is measured not only in downtime, but also in exposure risk and the secondary monetization of stolen information.

FortiBleed adds a second tactical layer. This is no longer just about exploiting a perimeter vulnerability, but about mass credential compromise followed by reuse. Bitsight describes legacy SHA-256 hashes and offline cracking with 45 GPUs. The Hacker News explains an automated two-stage approach: first testing known username and password combinations, then passively observing authentication traffic crossing the firewall to collect new credentials. Devel Group adds the use of FortiGateSniffer, a Go tool that abuses the diagnose sniffer packet command, and the creation of ghost administrative accounts with names that mimic legitimate Fortinet components.

Attack flowInitial accessPhishing, credentials,Unpatched FortinetLateral movementRDP, SMB, WMIPersistenceGhost accountsAuthentication snifferImpactWindows, Linux, ESXiExtortionDLS, Tor, email
Qilin-attributed attack chain — Initial access, lateral movement, encryption and extortion, focusing on Fortinet, VPN, and ESXi.
TTP Description Source
T1190 Exploitation of exposed applications, including gateways and vulnerabilities such as CVE-2024-55591 Securonix
T1133 Abuse of external remote services such as SSL VPN and RDP Securonix
T1078 Use of valid accounts obtained through brute force or credential theft Securonix
Initial access Phishing, stolen credentials, exposed remote services, unpatched Fortinet systems ProvenData, Scrutex.ai, Paubox, Viakoo
Persistence Fraudulent administrative accounts, passive traffic inspection with FortiGateSniffer Devel Group
Lateral movement RDP, SMB, WMI, domain admin activity, LSASS LinkedIn, ProvenData
Impact Encryption of Windows, Linux and VMware ESXi, service termination and shadow copy deletion ProvenData, LinkedIn
Extortion Data theft, DLS publication, Tor and email contact, 72-hour time pressure LinkedIn, Comparitech

The relationship between Qilin and Fortinet is also structural. Fortinet coverage, CISA, the Canadian Centre for Cyber Security and Arctic Wolf show the issue has grown beyond a single incident. Credentials are compromised, configurations are exposed, firewalls remain unpatched, and initial access ecosystems are bought and sold. That helps explain why different groups, including linked brands such as The Gentlemen and Securotrop, converge on the same attack surface.

Regional impact

Regional overview

The available material does not allow for one unified metric across Latin America, but it does show a broadly consistent pressure pattern. Chile is the most measured case, with 8.8 billion cyberattack attempts in 2025 and 58 incidents logged in just the first six months of 2026. Brazil appears as one of the regional centers for ransomware victims and for exposure to phishing and public-sector compromise campaigns. Paraguay and Bolivia appear in ransomware monitoring panels, though with less public detail on the names of affected organizations. Colombia and Peru have no additional verifiable facts in the material provided, which does not mean there is no risk, only that the corpus contains no consolidated evidence for those countries.

Regional exposure mapChileStrongest evidenceBrazilHigh exposureParaguayMixed signalsBoliviaOne to three casesArgentinaNo verified factsPeruNo verified factsColombiaNo verified factsU.S.Technical context
Regional map of exposure visible in the corpus — Countries with consolidated evidence and the level of detail available in the source material.

Argentina

There are no additional verifiable facts in the research for Argentina. The material does not provide victims, campaigns or confirmed attributions for the country within the corpus supplied.

Chile

Chile has the densest set of data and therefore serves as the best gauge of the phenomenon. SEK, according to G5 Noticias, recorded 58 incidents affecting or exposing Chilean organizations between January and June 2026. Of those, 18 were posts on ransomware leak sites and 40 were posts in dark web cybercrime forums. That split matters because it shows the problem is no longer limited to attempts or detections, but to actual public exposure of data and to extortion processes that end on leak sites. Leak-site posts also increased 50 percent versus the same period in 2025.

Qilin was the most visible actor in that subset. G5 Noticias assigns it 11 of the 18 ransomware leak-site posts, or 61 percent of the total. La Tercera reaches the same general conclusion: Chile was identified as one of the countries where international data hijacking and credential theft groups operate actively, affecting the public sector, critical infrastructure, financial services and major companies. The article also describes Qilin as an RaaS group specialized in automated campaigns and abuse of poorly managed cloud configurations, and The Gentlemen as another active actor in Chile, focused on double extortion.

Ransomware.live adds operational context. Its Chile page reports 74 victims linked to organizations in the country, all aggregated from leak-site posts. Among the victims attributed to Qilin in 2026 are Valbifrut, Graneles de Chile, Noi Hotels, SAAM Towage, Calidra and Comercial Echave Turri Limitada. Their discovery dates cluster between January and May 2026, reinforcing the idea of sustained activity rather than an isolated event. Ransomware.live also tracks other actors such as LockBit5, Incransom and Anubis, confirming that the local environment is fragmented across several extortion families and brands.

Chile, incidents by sectorGovernment10Finance8Education6Health6Energy/Mining5
Chilean sectors most exposed, according to SEK — Distribution of combined incidents between January and June 2026, according to the count cited by G5 Noticias.

There are also sector signals. SEK’s report summary, cited by G5 Noticias, places Government at the top with 10 combined incidents, followed by Finance with 8, Education with 6, Health with 6 and Energy or Mining with 5. That not only identifies high-value sectors, it also points to where exposed systems may be located and where the operational impact could be most severe if encryption or exfiltration occurs. NOI Hotels expands the picture into tourism and hospitality, a segment that depends heavily on operational uptime and guest data protection.

A Care Telecom reference mentions a clinic in Chile among 15 new victims claimed by Qilin during a 72-hour window in the first week of June 2026. The source does not identify the clinic by name, so the claim cannot go beyond an indication of health-sector exposure. Even so, it fits the broader regional pattern, where Qilin targets organizations that do not always have strong controls over remote access, segmentation or incident recovery.

Paraguay

Paraguay appears in the corpus in two ways. The first is institutional. Check Point Research reports active exploitation of CVE-2026-50751 in remote access gateways and says at least one case was linked to Qilin ransomware activity. The indexed excerpt of the report also includes Paraguay in that context, although the material does not let us attribute a specific victim or determine whether the country was hit by the same campaign or simply referenced in the document.

The second appearance is operational. Ransomware.live’s Mexico panel includes an entry associated with Qilin that mentions Healthcare S.A. as a victim and describes it as a Paraguayan family-founded company, with the case discovered on June 15, 2026. The material does not clarify whether the incident affected operations in Paraguay, Mexico or a transnational corporate structure. What can be verified is the entity’s presence in the tracker and its association with Qilin.

Legal-ISAC, for its part, shows at least one Qilin-associated victim in Paraguay on its RansomWatch dashboard, classified in the information technology sector. That confirms the country is already appearing on ransomware tracking radars with activity attributed to the group. Added to that is an unconfirmed Instagram post describing an attack against the private clinics Migone, Grupo Británico and Reyva, with interruptions in medical records, appointments and billing. That information is not corroborated by an institutional source, so it should be treated as an indicator, not as a settled fact.

La Tribuna Paraguay also reported a ransomware attack attributed by a group calling itself CyberTeam against InfoCheck, linked to Equifax Paraguay. That item is confirmed in the corpus, although it does not establish any link to Qilin. Paraguay, then, shows ransomware activity, but the material does not support the conclusion that all of it belongs to the same actor.

Bolivia

Bolivia appears with less volume, but with clear thematic relevance. Scrutex.ai reported that Qilin led the posts on its leak site during the week under analysis with 25 victims, equal to 13 percent of the total. Within that universe, Bolivia is listed among the countries with between one and three affected organizations, although the report does not publish specific names. The same report identifies Qilin as an actor that mainly exploits edge vulnerabilities, remote management tools and hypervisors, and explicitly highlights Fortinet flaws CVE-2024-21762 and CVE-2024-55591 as entry points.

The value of that reference is not only Bolivia’s presence, but the technical similarity with what was seen in Chile and elsewhere in the region. Scrutex.ai cites PRODAFT and ReliaQuest in saying that tens of thousands of Fortinet devices remained exposed months after patching. If the perimeter stays open, the spillover effect in countries with less public visibility becomes difficult to measure but no less real. Orbital Laika reinforces that reading by explicitly mentioning threats in Bolivia in the context of Fortinet’s global FortiGuard report.

The material also includes two LinkedIn posts that, unconfirmed, say Krybit may have affected Bolivia’s Agency for Health Infrastructure and Medical Equipment, AISEM. Both posts describe a disruption to health and medical equipment infrastructure, but there is no official statement or technical detail on the access vector. They should therefore be read as signs of possible exposure, not as conclusive attribution.

Peru

There are no additional verifiable facts in the research for Peru. The corpus provides no confirmed victims, attributed campaigns or specific technical data for the country.

Colombia

There are no additional verifiable facts in the research for Colombia. The material contains no confirmed victims or campaigns tied to the country within the consolidated sources.

Brazil

Brazil is the other major regional reference point alongside Chile. La Tercera, citing a Fortinet study, says the country accounted for about 30 percent of ransomware victims in the region and saw 309 million phishing attempts in 2025, equal to 588 attacks per minute. That data is paired with a broader claim in the same article: Brazil is one of the countries where international data hijacking and credential theft groups operate actively against the public sector, critical infrastructure, financial services and major companies.

On the technical side, Check Point Research published a phishing campaign in Brazil that abuses the legitimate NinjaOne agent to install a signed agent on corporate devices, using Portuguese-language portals and social engineering phone calls. Although the case is not directly tied to Qilin, it does confirm heavy use of legitimate remote access to compromise endpoints in the country. The same report also mentions active exploitation of CVE-2026-50751 with one case linked to Qilin, reinforcing the idea that the group is following remote-access flaws closely.

CM Alliance adds another element. On June 22, 2026, Brazil was investigating a possible cyberattack against Defesa Civil Alerta, a platform under the National Secretariat for Protection and Civil Defense, after false emergency warnings were sent to thousands of mobile phones and the system was temporarily disconnected. The source does not attribute the event to Qilin, but it places the incident within a particularly active June for high-impact events in the country.

In terms of ransomware, Red Piranha places Brazil within a weekly report where The Gentlemen leads global activity and Qilin ranks second. The same document describes Securotrop, a Qilin-affiliated brand, and records activity in Brazil and Chile. Care Telecom also mentions a food-sector company in Brazil among the alleged victims claimed by Qilin during a 72-hour window in the first week of June. That reference is unconfirmed, but it fits the regional leak-site expansion pattern.

United States

There are no additional verifiable facts in the research for the United States within this regional section. There is, however, an indirect relevant reference: several technical analyses of Qilin and FortiBleed mention campaigns or victim clusters in U.S. law firms and consultancies, but the corpus provided here did not develop a country-specific block with concrete events for that jurisdiction.

Technical indicators

No classic IOCs, such as hashes, domains, IPs or file paths, were published in the consolidated material. There are, however, behavior indicators, vulnerable versions and operational artifacts that are useful for defense and hunting.

Type Value Source
CVE CVE-2024-21762 Scrutex.ai, CVE Program, CISA, Tech Insider
CVE CVE-2024-55591 Scrutex.ai, Canadian Centre for Cyber Security, The Network DNA, Paubox, Viakoo
CVE CVE-2026-50751 Check Point Research
Tool FortiGateSniffer Devel Group
Abused command diagnose sniffer packet Devel Group
Fraudulent account forticloud Devel Group
Fraudulent account fortiuser Devel Group
Fraudulent account fortinet-support Devel Group
Fraudulent account fortinet-tech-support Devel Group
Operational vector Fortinet SSL VPN Scrutex.ai, ProvenData, Securonix, Gurucul
Operational vector VMware ESXi ProvenData, LinkedIn
Operational vector RDP, SMB, WMI LinkedIn, Securonix, ProvenData

Security team analysis

The defensive priority that emerges from the material is not ambiguous. Initial access remains the point of failure, and in this campaign initial access is closely tied to the perimeter. If an organization exposes FortiGate, FortiProxy or remote-access gateways without enough hardening, the attack surface matches the pattern seen in Qilin and the FortiBleed ecosystem. The fact that CISA, the Canadian Centre for Cyber Security and other national teams issued alerts within a narrow time window suggests the issue has moved beyond a single vulnerability.

At the operational level, the first step is to stop treating the firewall or VPN as just a transit point. In the material reviewed, those devices appear as compromise targets, persistence points and credential collection points. Devel Group describes ghost administrative accounts. The Hacker News describes an automated attack that first tests credentials and then captures authentication traffic. Bitsight adds that theft can continue offline through hash cracking. For that reason, hardening has to include not just patching, but also account hygiene, secret rotation and review of historical configuration.

The next layer is detection. ProvenData offers a useful set of signals: anomalous VPN or RDP logins from unusual times, locations or devices, domain admin activity from non-administrative hosts, mass LSASS access, bulk deletion of shadow copies, coordinated service termination and driver loads that do not match the endpoint baseline. In Fortinet environments, Devel Group recommends looking for abnormal executions of diagnose sniffer packet and auditing accounts with names designed to look like legitimate support. If the monitoring stack is not seeing those events, the first objective should be to enable enough telemetry to capture them.

Mitigation guidance is consistent across sources. Rotate administrative and VPN passwords immediately, enforce MFA, update FortiOS to the latest available version, close external administration unless it is truly necessary and restrict access to trusted hosts. When possible, external administration should be eliminated entirely. The Canadian Centre for Cyber Security and Fortinet, according to The Hacker News coverage, also recommend ending compromised administrative and VPN sessions and assuming prior credentials may have been reused from earlier incidents. That assumption matters because FortiBleed does not depend on a single vector, but on the combination of technical exposure and already leaked credentials.

For Chile, the risk reading is even more urgent. The 58 incidents between January and June 2026 and the 50 percent increase in DLS posts compared with the same period in 2025 show that the problem is persistent. The mix of targeted sectors, Government, Finance, Education, Health and Energy or Mining, suggests the adversary understands where operational and reputational impact can be maximized. For organizations that depend on ESXi hypervisors, defense should include segmentation, least privilege on admin tools and tested restoration plans. Qilin targets hypervisors because that speeds up damage across multiple systems. If ESXi is not protected, containment arrives too late.

Source limitations

The available corpus supports a strong technical and regional line of analysis, but it does not justify closing several specific attributions. The mentions of ATCOM Chile, the clinic in Chile, the food company in Brazil, AISEM in Bolivia, Healthcare S.A. in Paraguay and the private Paraguayan clinics appear in sources with varying levels of reliability, several of them using unconfirmed attribution language. For that reason, they are not treated as fully verified incidents in this research.

There are also no classic IOCs in the consolidated sources. No hashes, IP addresses, C2 domains or DLS URLs were provided in a way that offers direct operational value for technical hunting. What is available are tool names, abused commands, vulnerability families and fraudulent accounts observed by the cited researchers.

Another limitation is the geographic imbalance. Chile carries the strongest and most quantifiable evidence. Brazil appears with substantial context, but with less direct attribution to Qilin in specific incidents. Paraguay and Bolivia have signs of exposure and monitoring in intelligence platforms, but without the same density of detail. Argentina, Peru, Colombia and the United States do not contribute additional verifiable facts within the regional block requested.

Finally, the information on FortiBleed is abundant but heterogeneous in its scale estimates, ranging from more than 30,000 devices to 86,644 compromised FortiGate systems. That spread does not invalidate the campaign, but it does mean the numbers should be treated as estimates from different research teams, not as one consolidated total.

Sources

View all