Operation Escaneo Targets Latin American Critical Infrastructure

Operation Escaneo Targets Latin American Critical Infrastructure

First seen 18 Jun 2026, 12:12 UTC Cloudsekwww.news9live.comInfosecurity-MagazineDarkreadingwww.cybersecuritydive.com 82% similarity 78.7

Article Content

Browse articles
ThreatCluster

Operation Escaneo is a coordinated cyberattack attributed to the MexicanMafia group, targeting critical infrastructure across Latin America, primarily Mexico. The campaign, which spanned from 2025 to 2026, utilized sophisticated tools including a proprietary reconnaissance engine named Kimera and exploits for vulnerabilities in Fortinet and Ivanti systems. Researchers reported that over 150GB of sensitive data was stolen, including personal records and SSL private keys. The attack vector involved exploiting internet-facing security appliances and lateral movement within victim networks. Despite claims of massive data theft, some Mexican authorities denied any breaches occurred. The operation's complexity and scale indicate a significant threat to national security and critical services.

Key Points: • Operation Escaneo involved sophisticated tools and tactics targeting Latin American infrastructure. • The MexicanMafia group is attributed with medium confidence for this multi-stage campaign. • Over 150GB of sensitive data was reportedly stolen, affecting various government and financial entities.

ThreatCluster AI How this analysis works

Timeline

2020-02-21
Public exploit for CVE-2020-1938 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2020-08-17
CVE-2020-1472 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2022-01-28
CVE-2021-4034 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2022-12-13
CVE-2022-42475 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2023-06-13
CVE-2023-27997 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-01-10
CVE-2024-21887 added to CISA KEV
CVE-2024-21887, a vulnerability in Ivanti Connect Secure, was added to the CISA Known Exploited Vulnerabilities list.
Infosecurity-Magazine
2024-01-10
CVE-2023-46805 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2024-01-12
CVE-2024-46805 published
CVE-2024-46805, another Ivanti vulnerability, was published and added to CISA KEV.
Infosecurity-Magazine
2024-02-09
CVE-2024-21762 published
CVE-2024-21762, a critical vulnerability in Fortinet, was published and added to CISA KEV.
Infosecurity-Magazine
2025-01-08
CVE-2025-0282 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

Community

Browse all →