CloudSEK has detailed Operation Escaneo, a sophisticated multistage cyberattack campaign attributed with medium confidence to the MexicanMafia/PanchoVilla threat group. Active between 2025 and 2026, the campaign primarily targeted critical infrastructure in Mexico, Ecuador, and Portugal. The group employs a proprietary reconnaissance engine (Kimera), exploits known CVEs in Fortinet, Ivanti, and Apache Tomcat, and uses layered C2 infrastructure including Neo-reGeorg webshells and Chisel reverse tunnels. Unusually for a financially motivated actor, MexicanMafia also appears to collect high-value intelligence such as SSL private keys and MDM infrastructure data — possibly without central coordination between monetization and espionage objectives. Researchers note this campaign signals a closing gap between cybercriminal and APT-level capabilities in Latin America, and recommend immediate patching of perimeter devices and improved network segmentation.

5m read timeFrom darkreading.com
Post cover image
Table of contents
Operation Escaneo Presents a Sophisticated CampaignA Change in Latin America's Threat Landscape
30 Impressions