Skip to content
Operation Escaneo Targets Latin American Critical Infrastructure

Operation Escaneo Targets Latin American Critical Infrastructure

First seen 18 Jun 2026, 12:12 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 19, 2026 at 11:55 UTC
  • Operation Escaneo involved sophisticated tools and tactics targeting Latin American infrastructure.
  • The MexicanMafia group is attributed with medium confidence for this multi-stage campaign.
  • Over 150GB of sensitive data was reportedly stolen, affecting various government and financial entities.

Operation Escaneo is a coordinated cyberattack attributed to the MexicanMafia group, targeting critical infrastructure across Latin America, primarily Mexico. The campaign, which spanned from 2025 to 2026, utilized sophisticated tools including a proprietary reconnaissance engine named Kimera and exploits for vulnerabilities in Fortinet and Ivanti systems. Researchers reported that over 150GB of sensitive data was stolen, including personal records and SSL private keys. The attack vector involved exploiting internet-facing security appliances and lateral movement within victim networks. Despite claims of massive data theft, some Mexican authorities denied any breaches occurred. The operation's complexity and scale indicate a significant threat to national security and critical services.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 91d ago How this analysis works

Timeline

2020-02-21
Public exploit for CVE-2020-1938 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2020-08-17
CVE-2020-1472 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2022-01-28
CVE-2021-4034 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2022-12-13
CVE-2022-42475 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2023-06-13
CVE-2023-27997 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-01-10
CVE-2024-21887 added to CISA KEV
CVE-2024-21887, a vulnerability in Ivanti Connect Secure, was added to the CISA Known Exploited Vulnerabilities list.
Infosecurity-Magazine
2024-01-10
CVE-2023-46805 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2024-01-12
CVE-2024-46805 published
CVE-2024-46805, another Ivanti vulnerability, was published and added to CISA KEV.
Infosecurity-Magazine
2024-02-09
CVE-2024-21762 published
CVE-2024-21762, a critical vulnerability in Fortinet, was published and added to CISA KEV.
Infosecurity-Magazine
2025-01-08
CVE-2025-0282 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (5)

Following this threat?

Track Mexican Mafia, Neo-reGeorg and Estado De México Government in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed