CiberLATAMbywhalemate

Mexico and Brazil Hit by Active Ransomware

Unit 42 found active campaigns in Mexico and Brazil, with regional ransomware tied to BlackCat/ALPHV, The Gentlemen, Qilin and LockBit 5.0.

Whalemate Labs · AI-assisted researchPublished:3 min read

Palo Alto Networks Unit 42 reported two active campaigns targeting organizations in Latin America, one in Mexico’s transportation sector and another in Brazil’s financial sector. The first also reached Mexican federal ministries and municipal water services in Mexico and Ecuador, while other intelligence reports pointed to broader regional ransomware activity across multiple sectors.

Palo Alto Networks Unit 42 reported two active campaigns targeting organizations in Latin America. One focused on transportation in Mexico and also reached Mexican federal ministries and municipal water services in Mexico and Ecuador. The other centered on Brazil’s financial sector. At the same time, other intelligence reports described broader ransomware activity across the region, with Mexico among the most affected countries.

What did Unit 42 find in Mexico and Brazil?

Unit 42 observed previously reported vulnerable web servers, job-themed phishing, custom remote access tools, and a Go-based SOCKS5 proxy using iterative file names. It also documented initial access through a phishing attachment themed around a résumé in February 2026. The activity was attributed to cluster CL-CRI-1163, although the available summary did not present it as a definitive attribution to a specific ransomware family.

Cloud Security Alliance expanded on that assessment and identified two separate but tactically overlapping clusters, CL-CRI-1131 and CL-CRI-1163. According to the technical note, the first affected transportation in Mexico, Mexican federal ministries, and a municipal water company in Ecuador, while the second focused on Brazil’s financial sector using résumé lures. CSA Labs also said both clusters used commercial large language models as operational support during the intrusions.

Machine Speed also said CL-CRI-1131 and CL-CRI-1163 used commercial language models within their attack chain. That initiative likewise placed the campaigns against transportation organizations, federal ministries, and water services in Mexico and Ecuador, as well as financial entities in Brazil. CSA recommended that government, transportation, water, and financial organizations in those countries review indicators of compromise such as C2 domains, IP addresses, and file hashes published by Unit 42 against their own telemetry.

What do the other reports show about ransomware in the region?

The rest of the reports point to a broader regional market with multiple active actors. Insomnia reported a campaign attributed with high confidence to BlackCat/ALPHV, with victims in 22 countries and techniques including spearphishing, exploitation of exposed infrastructure, use of valid accounts, data exfiltration to cloud storage, file encryption, and external defacement.

That analysis also said the BlackCat/ALPHV campaigns observed hit healthcare, energy, manufacturing, legal, and SaaS. Initial access varied between spearphishing, exploitation of unpatched edge appliances, and valid credentials that had been bought or stolen.

Regionally, El Economista cited a SCILabs report that recorded 290 ransomware attacks between January and June 2026 in Latin America, linked to 50 different variants. The same report said incidents rose 25.5% from the previous period and that Mexico accounted for 17.93% of regional activity, or about 52 cases, behind Brazil.

SCILabs also detailed that the services sector accounted for 19.66% of incidents, about 57 cases, followed by government with 11.72% and manufacturing with 8.28%. Among variants, The Gentlemen was the most active in Latin America with at least 49 attacks, ahead of Qilin with 46 and LockBit 5.0 with 43.

BlackFog also flagged a local government case involving a ransomware incident against the municipality of San Luis Potosí, Mexico, where the exfiltration of employee information was confirmed before an extortion attempt. On another front, Acronis named The Gentlemen as the most active group in July 2026 with 162 known victims, followed by Qilin with 128, a jump from June.

An emerging actor also appeared. Darkfield documented Vexy Ransomware and identified Engefitas, a Brazilian company tied to industrial sectors, as a victim in the energy and utilities vertical. The profile said Vexy had added eight public victims between September 3 and September 6, 2026, and that its focus on energy and utilities in Brazil warrants monitoring because of the implications for critical infrastructure.

Sources

View all