Skip to content

Know the adversaries
before they reach your network

APT group profiles with attribution, MITRE ATT&CK techniques, public sources and detection guidance, focused on the threats that affect Latin America and Colombia.

groups profiled
8
ATT&CK techniques mapped
108
with documented LATAM activity
8
public sources cited
67

Why Ventura Systems Intelligence

Verifiable sources

Every statement is backed by public sources: MITRE ATT&CK, CISA advisories and vendor reports. If there is no source, it is not published.

MITRE ATT&CK mapping

Techniques normalized to ATT&CK IDs to compare groups, prioritize detections and communicate risk in a common language.

Latin America focus

We flag which groups have documented activity in the region and in Colombia, with detection guidance written for local SOCs.

By the numbers

Computed from the profiles at build time. A group can count in more than one row.

Groups by attributed country
Groups by attributed country
Russia3
North Korea2
China1
Iran1
Undetermined1
Groups by motivation
Groups by motivation
Espionage8
Financial3
Sabotage / destructive2
Groups by targeted region
Groups by targeted region
Latin America8
North America6
Europe6
Middle East5
East Asia5
Africa3
Oceania3
South Asia2
Southeast Asia2
Central Asia1
Global1
Profiled groups active per year

Number of profiled groups active each year from 2004 to 2026: 2004: 1, 2005: 1, 2006: 1, 2007: 1, 2008: 2, 2009: 4, 2010: 4, 2011: 4, 2012: 6, 2013: 6, 2014: 6, 2015: 6, 2016: 6, 2017: 7, 2018: 8, 2019: 8, 2020: 8, 2021: 8, 2022: 8, 2023: 8, 2024: 8, 2025: 8, 2026: 6.

featured

All groups →
apt-c-36.yml G0099

APT-C-36

Blind Eagle · BlindEagle · TAG-144

Group that MITRE describes as a suspected South American actor, active since at least 2018, combining espionage and financial fraud against government, banking, energy and other sectors in Colombia, Ecuador and the rest of Latin America.

Attributed origin
Undetermined
Activity
2018 → Jul 2026
EspionageFinancial LATAM · Colombia Draft
apt28.yml G0007

APT28

Fancy Bear · Forest Blizzard · STRONTIUM

Cyberespionage group attributed by the U.S. and the UK to Unit 26165 of Russia's GRU (85th GTsSS), active since at least 2004 against governments, defense, logistics and political organizations.

Attributed origin
Russia
Activity
2004 → Apr 2026
Espionage LATAM Draft
apt29.yml G0016

APT29

Cozy Bear · Midnight Blizzard · NOBELIUM

Cyberespionage group attributed by the U.S. and the UK to Russia's Foreign Intelligence Service (SVR), active since at least 2008; responsible for the SolarWinds compromise and for persistent intrusions into cloud and identity environments.

Attributed origin
Russia
Activity
2008 → Jul 2026
Espionage LATAM Draft
lazarus-group.yml G0032

Lazarus Group

Labyrinth Chollima · Diamond Sleet · ZINC

North Korean state-sponsored group attributed to the Reconnaissance General Bureau (RGB), active since at least 2009, that combines espionage, sabotage and financial theft against banking, crypto assets and defense, with documented cases in Latin America.

Attributed origin
North Korea
Activity
2009 → Aug 2026
EspionageFinancialSabotage / destructive LATAM Draft

latam

Threats with documented activity in the region

Not every global APT operates in Latin America. This list only includes groups with public reports of campaigns against organizations in the region, and marks those that have targeted Colombia.

Filter groups active in LATAM
  • APT-C-36

    · Undetermined Colombia

    Colombia is the main target: according to Kaspersky, 87% of the victims detected in its May and June 2024 espionage campaigns were in Colombia. There are also documented campaigns against Ecuador (Check Point, 2023), Chile and Panama (Kaspersky, Recorded Future). Recorded Future also mentions occasional campaigns against Spanish speakers in North America.

  • APT28

    · Russia

    ESET (Operation RoundPress, 2025) documents a spearphishing email sent in July 2024 to a military organization in Ecuador and mentions government victims in South America. Trend Micro (2024) reports Pawn Storm targets in South America: armed forces, the defense industry and ministries of Agriculture and Finance, without specifying countries. No specific public reports concerning Colombia as of the date of this review.

  • APT29

    · Russia

    According to Microsoft (December 2020), victims of the later stage of the SolarWinds compromise included organizations in Mexico, in addition to the U.S., Canada, Europe and the Middle East. No public reports of campaigns specifically targeting Colombia were found as of the date of this review.

  • APT41

    · China

    According to FireEye/Mandiant (March 2020), the campaign exploiting Citrix, Cisco and Zoho ManageEngine included organizations in Mexico. The DOJ indictment of September 2020 mentions victims in Brazil and Chile. No public reports of victims in Colombia as of this review.

  • Kimsuky

    · North Korea

    Brazil: according to Kaspersky (May 2026), the PebbleDash cluster attributed to Kimsuky compromised Brazilian defense organizations in recent years. It is the only publicly documented Latin American case. No public reports on Colombia as of this review.

  • Lazarus Group

    · North Korea

    Chile: intrusion into Redbanc (Dec. 2018) linked to Lazarus tools according to Flashpoint. Mexico: fraudulent transfers against Bancomext (Jan. 2018) according to the DOJ indictment; MITRE assigns Bancomext and Banco de Chile to the APT38 subgroup. Watering holes in Mexico, Uruguay and Peru (Kaspersky, 2017), Latin American financial institutions (Trend Micro, 2018), online casinos in Central America (DOJ) and defense-sector victims in Brazil (Check Point, 2026). No public reports on Colombia as of this review.

  • MuddyWater

    · Iran

    Symantec/Carbon Black (May 2026) includes a Latin American financial services provider, without specifying the country, among at least nine organizations compromised in an espionage campaign in the first quarter of 2026. There are no public reports of campaigns against Colombia.

  • Sandworm

    · Russia

    According to Mandiant's report on APT44 (April 2024), the group has maintained access and espionage operations in Latin America, without specifying countries. No public reports identifying victims in Colombia as of this review.

updates

Recently updated profiles

  • APT-C-36

    Group that MITRE describes as a suspected South American actor, active since at least 2018, combining espionage and financial fraud against government, banking, energy and other sectors in Colombia, Ecuador and the rest of Latin America.

  • APT28

    Cyberespionage group attributed by the U.S. and the UK to Unit 26165 of Russia's GRU (85th GTsSS), active since at least 2004 against governments, defense, logistics and political organizations.

  • APT29

    Cyberespionage group attributed by the U.S. and the UK to Russia's Foreign Intelligence Service (SVR), active since at least 2008; responsible for the SolarWinds compromise and for persistent intrusions into cloud and identity environments.

  • APT41

    Chinese group that combines state-sponsored espionage with operations for personal profit, active since at least 2012 against healthcare, telecommunications, technology, government and the video game industry.

ventura defend

From intelligence to detection, 24/7

The Ventura Systems managed detection and response (MDR) service turns this intelligence into detection rules, threat hunting and incident response for your organization.