CiberLATAMbywhalemate

Paraguay, LATAM Under China Spyware Focus

Regional alerts describe APT campaigns using AI-made fake identities and China-linked espionage networks in Paraguayan systems.

Whalemate Labs · AI-assisted researchJul 11, 20262 min read

Agence Andina released a cybersecurity alert for Latin America warning about advanced persistent threat, or APT, campaigns aimed at government entities and companies across the region. In parallel, coverage on Paraguay links intrusions into state systems to actors associated with China, although public attribution still lacks specific victims and a full technical confirmation.

APT campaigns across the region

Agence Andina released a cybersecurity alert for Latin America warning about advanced persistent threat, or APT, attacks targeting government entities and companies across the region. According to that material, the campaigns involve infiltration of organizations through fake identities created with artificial intelligence to gain access to internal networks and sensitive data.

The warning comes as other regional coverage and publications tied to the cybersecurity ecosystem describe sustained activity from groups that can stay inside compromised networks and operate with espionage goals.

Paraguay, China, and public attribution

In Paraguay, a post from radio Ñandutí reported that the Ministry of Information and Communication Technologies and the U.S. Embassy issued a joint statement denouncing cyberattacks attributed to actors linked to China against the country's infrastructure. That post, however, did not identify specific victims or provide a public technical attribution.

Other coverage echoed on social media added more context on the same episode. Infobae said the cyber intrusions attributed to actors linked to China may have affected Paraguayan state systems, while Milenio Diario referred to China-linked espionage networks in Paraguayan systems and described them as an advanced threat. Noticias al Día, for its part, said Paraguay and the United States are denouncing Chinese cyberespionage on state networks, again focusing on government infrastructure without naming specific agencies.

Persistence and vulnerable networks

An Instagram post about the joint U.S. and Paraguay investigation said the Chinese APT group would be deploying new malware to maintain persistence in compromised networks. According to that content, once access is gained, the group installs components that let it remain in place for long periods and continue exfiltrating information.

In the same vein, the ESET Security Days 2026 reel said, citing ESET's latest report, that activity has increased from a network associated with Chinese state actors that uses vulnerable network devices for cyberespionage operations in Latin America. El Toque expanded on that point by saying that network devices in several Latin American countries are being used for espionage and cyber reconnaissance operations by a network associated with Chinese state actors.

Taken together, these posts point to campaigns focused on persistence, access to critical infrastructure, and the collection of sensitive information, with a pattern that combines fake identities, malware built to stay active, and the exploitation of vulnerable network equipment.

Sources

View all