<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Ventura Systems Intelligence — APT profile updates</title><description>APT (advanced persistent threat) group profiles focused on Latin America and Colombia: attribution, MITRE ATT&amp;CK TTPs, public sources and detection guidance. By Ventura Systems.</description><link>https://intelligence.venturasystems.tech/</link><language>en-us</language><item><title>[Draft] APT-C-36 (G0099)</title><link>https://intelligence.venturasystems.tech/apt/apt-c-36/</link><guid isPermaLink="true">https://intelligence.venturasystems.tech/apt/apt-c-36/</guid><description>Group that MITRE describes as a suspected South American actor, active since at least 2018, combining espionage and financial fraud against government, banking, energy and other sectors in Colombia, Ecuador and the rest of Latin America.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>espionage</category><category>financial</category><category>latam</category></item><item><title>[Draft] APT28 (G0007)</title><link>https://intelligence.venturasystems.tech/apt/apt28/</link><guid isPermaLink="true">https://intelligence.venturasystems.tech/apt/apt28/</guid><description>Cyberespionage group attributed by the U.S. and the UK to Unit 26165 of Russia&apos;s GRU (85th GTsSS), active since at least 2004 against governments, defense, logistics and political organizations.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>espionage</category><category>latam</category></item><item><title>[Draft] APT29 (G0016)</title><link>https://intelligence.venturasystems.tech/apt/apt29/</link><guid isPermaLink="true">https://intelligence.venturasystems.tech/apt/apt29/</guid><description>Cyberespionage group attributed by the U.S. and the UK to Russia&apos;s Foreign Intelligence Service (SVR), active since at least 2008; responsible for the SolarWinds compromise and for persistent intrusions into cloud and identity environments.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>espionage</category><category>latam</category></item><item><title>[Draft] APT41 (G0096)</title><link>https://intelligence.venturasystems.tech/apt/apt41/</link><guid isPermaLink="true">https://intelligence.venturasystems.tech/apt/apt41/</guid><description>Chinese group that combines state-sponsored espionage with operations for personal profit, active since at least 2012 against healthcare, telecommunications, technology, government and the video game industry.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>espionage</category><category>financial</category><category>latam</category></item><item><title>[Draft] Kimsuky (G0094)</title><link>https://intelligence.venturasystems.tech/apt/kimsuky/</link><guid isPermaLink="true">https://intelligence.venturasystems.tech/apt/kimsuky/</guid><description>North Korean cyberespionage group active since at least 2012, focused on foreign policy, national security and nuclear issues on the Korean Peninsula, that targets governments, think tanks, academia and defense through spearphishing and social engineering.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>espionage</category><category>latam</category></item><item><title>[Draft] Lazarus Group (G0032)</title><link>https://intelligence.venturasystems.tech/apt/lazarus-group/</link><guid isPermaLink="true">https://intelligence.venturasystems.tech/apt/lazarus-group/</guid><description>North Korean state-sponsored group attributed to the Reconnaissance General Bureau (RGB), active since at least 2009, that combines espionage, sabotage and financial theft against banking, crypto assets and defense, with documented cases in Latin America.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>espionage</category><category>financial</category><category>sabotage</category><category>latam</category></item><item><title>[Draft] MuddyWater (G0069)</title><link>https://intelligence.venturasystems.tech/apt/muddywater/</link><guid isPermaLink="true">https://intelligence.venturasystems.tech/apt/muddywater/</guid><description>Cyberespionage group that the FBI, CISA, US Cyber Command and the UK&apos;s NCSC identify as a subordinate element of Iran&apos;s Ministry of Intelligence and Security (MOIS). Active since at least 2017 against governments, telecommunications, energy and finance.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>espionage</category><category>latam</category></item><item><title>[Draft] Sandworm (G0034)</title><link>https://intelligence.venturasystems.tech/apt/sandworm/</link><guid isPermaLink="true">https://intelligence.venturasystems.tech/apt/sandworm/</guid><description>Sabotage and espionage unit attributed to Russia&apos;s GRU Unit 74455, active since at least 2009 and responsible for the blackouts in Ukraine and for NotPetya, one of the most destructive cyberattacks on record.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>sabotage</category><category>espionage</category><category>latam</category></item></channel></rss>