Operation Escaneo Latin America intrusion campaign targeting government and finance
Campaign
Summary
Hide ▲
Show ▼
The Operation Escaneo campaign exposed a coordinated intrusion effort against government and financial targets across Latin America, with confirmed victim access and data theft. The operation reached critical infrastructure in Mexico, with additional activity in Ecuador and Portugal. Attackers used Fortinet FortiOS SSL-VPN and Ivanti Connect Secure flaws, plus Apache Tomcat, EternalBlue, Zerologon, and Log4Shell, to penetrate perimeter systems. The exposed tooling and access paths show an active cross-border campaign rather than isolated scans.
Related Happenings
FortiBleed Fortinet/FortiGate VPN credential leak
Data Leak
H score80
First: 17.06.2026 18:12
Last: 17.06.2026 18:12
Sources 1
About this happening:
FortiBleed is a data leak of Fortinet/FortiGate VPN credentials that now includes a verified database of 86,644 confirmed working credentials collected from inte...
FortiBleed Fortinet/FortiGate VPN credential leak
Data LeakAbout this happening: FortiBleed is a data leak of Fortinet/FortiGate VPN credentials that now includes a verified database of 86,644 confirmed working credentials collected from inte...
Latest development: 19.06.2026 09:47
CISA urged Fortinet customers to secure FortiGate appliances after nearly 74,000 firewall and VPN credentials were exposed in the FortiBleed leak. The agency advised affected owners to terminate SSL VPN and administrative sessions, reset VPN and administrative passwords, enable phishing-resistant multifactor authentication, review logs for unauthorized access or lateral movement, store admin credentials with PBKDF2, restrict firewall management interfaces from public internet access, and remove unauthorized accounts.
Earth Lusca Operation FishMedley espionage campaign
Campaign
H score38
First: 16.06.2026 12:44
Last: 16.06.2026 12:44
Sources 1
About this happening:
A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
Earth Lusca Operation FishMedley espionage campaign
CampaignAbout this happening: A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
Shadow-Aether-040 AI-augmented campaign against Mexican government entities
Campaign
H score41
First: 13.05.2026 16:00
Last: 13.05.2026 16:00
Sources 1
About this happening:
The Shadow-Aether-040 campaign used AI agents and custom tooling to compromise six government entities in Mexico, increasing the risk of follow-on intrusion and data...
Shadow-Aether-040 AI-augmented campaign against Mexican government entities
CampaignAbout this happening: The Shadow-Aether-040 campaign used AI agents and custom tooling to compromise six government entities in Mexico, increasing the risk of follow-on intrusion and data...
Static Tundra destructive campaign against Polish energy and manufacturing targets
Campaign
H score32
First: 31.01.2026 09:05
Last: 31.01.2026 09:05
Sources 1
About this happening:
The Static Tundra campaign is a destructive cyber activity tied to FSB Center 16 that targeted more than 30 wind and photovoltaic farms, a manufacturing company*...
Static Tundra destructive campaign against Polish energy and manufacturing targets
CampaignAbout this happening: The Static Tundra campaign is a destructive cyber activity tied to FSB Center 16 that targeted more than 30 wind and photovoltaic farms, a manufacturing company*...
Timeline
-
18.06.2026 14:30 2 articles · 27d ago
CloudSEK exposes Operation Escaneo campaign against Latin American government and financial targets
Initial DisclosureCloudSEK's analysis of Operation Escaneo mapped a coordinated intrusion campaign against government and financial targets across Latin America, with activity in Mexico and smaller activity in Ecuador and Portugal. The operation used exposed perimeter appliances and tuned exploits for Fortinet FortiOS SSL-VPN and Ivanti Connect Secure flaws, plus Apache Tomcat, EternalBlue, Zerologon, and Log4Shell, then maintained access with Neo-reGeorg webshells, Chisel reverse tunnels, and a compromised Cisco router fitted with a GRE tunnel. CloudSEK confirmed beacons from at least five victims and large-scale data theft, including access to SAP and Oracle systems and sensitive data such as SAP service-account hashes and browser-stored passwords.
Show sources
- LATAM Infrastructure Hit by Fortinet and Ivanti Exploits — www.infosecurity-magazine.com — 18.06.2026 14:30
- LATAM Infrastructure Hit by Fortinet and Ivanti Exploits — www.infosecurity-magazine.com — 18.06.2026 14:30