--[ Anomaly #15 - Surveillance in expanded version ]--
August 21, 2026
By: ZoqueLabsThis writing is distributed under a Creative Commons CC BY-SA (Acknowledgment - Share Alike) license.
Spanish version
Â
This week we read the report published by Amnesty International about Argentina and it left us thinking. At first glance it seems like a story about artificial intelligence: social media monitoring, facial recognition, drones and new intelligence capabilities. But as we continued reading, another feeling appeared: many of the things the report describes are not really new.
We have been seeing these technologies appear in different places in Latin America for years. Sometimes in the form of spyware. Others, such as facial recognition systems, biometric databases or platforms to monitor social networks. We have also seen them appear in investigations into state intelligence, non-transparent public purchases or surveillance programs whose true scope is only known years later.
Examples abound. Pegasus continues to appear in the regional conversation more than a decade after its first deployments. Just a few weeks ago we commented on the ruling that forces Sedena to continue providing information on contracts related to Pegasus in Mexico. In Colombia, discussions about cyber patrolling during the 2021 mobilizations already showed how the monitoring of digital platforms was beginning to occupy an increasingly important place within state surveillance strategies.
Separately, each of these cases seemed to belong to a different category. Spyware. Facial recognition. Network monitoring. Intelligence. Biometric databases. However, the Amnesty report is interesting because it allows us to observe what happens when all these pieces begin to coexist within the same system.
Perhaps that is the most relevant part of the story: in accumulation. For years, States have incorporated tools to collect information, identify people, monitor physical and digital spaces and analyze large volumes of data. Artificial intelligence reaches a scenario where a good part of these capabilities already exist.
What changes is the scale.
Processes that previously required teams dedicated to reviewing information, classifying content, or following conversations can now be automated, at least partially. This allows you to monitor more information, for longer and with much less friction.
That is why the Argentine case seems interesting to us beyond Argentina. It shows something that we are probably going to start to see more frequently in the region: technologies that we previously observed separately working closer and closer to each other. AI, spyware, facial recognition, network monitoring, databases and intelligence systems are beginning to connect within increasingly extensive surveillance infrastructures.
And perhaps that is one of the most important questions for the coming years. Not just what new technology appears, but what happens when all the previous ones start working together.
With this, now Anomaly.
--[Technical analysis ]--
France — This is how EncroChat encrypted phones were hacked
A Computer Weekly investigation reconstructs how a French state team managed to compromise more than 32,000 EncroChat Android phones in 2020. The implant exploited Bad Binder to obtain privileges and used Frida, the well-known open source dynamic instrumentation tool, to hook the messaging application and copy messages practically in real time before or after encryption. The curious thing is that a good part of the operation was supported by code and tools publicly available on GitHub and, according to the analysis, the implant had errors and failed frequently. Researchers from the Czech company Invasys also managed to “rehack the hack”:they recovered the malware deployed by the French and, using reverse engineering, reconstructed how the interception worked. The method remained protected as a national security secret for years, despite the fact that the information obtained was used as evidence in thousands of European judicial processes. Very good case of how forensic analysis can end up revealing the tools of those who were originally doing the hacking.Very good case of how forensic analysis can end up revealing the tools of those who were originally doing the hacking.Very good case of how forensic analysis can end up revealing the tools of those who were originally doing the hacking.
Malicious SVGs reappear in campaigns aimed at Colombia
An investigation reconstructed a campaign with DCRat aimed at Colombian users that uses SVG files as an entry point. The technique looked familiar: a few months ago we analyzed campaigns in our Blind Eagle Diaries series that used these same types of files to simulate official notifications and execute JavaScript code directly in the browser. In the case analyzed, the decoy is an alleged Colombian judicial resolution (like the ones we have seen). When interacting with the SVG, the browser locally reconstructs a password-protected archive that is subsequently deployed by DCRat.
Follow ClickFix in Latin America using compromised WordPress
ClickFix appears again in our notes. This time, researchers documented a campaign that uses fake CAPTCHA to convince people to run commands in PowerShell and deploy an infection chain that ends in ransomware, credential theft, USB propagation, and regular screenshots. What is interesting is not so much the final malware but the persistence of the technique: we continue to see how very different operations use the same pattern of social engineering to gain initial access. In this case, researchers found thousands of infections and victims in dozens of countries, including several in Latin Americaplus evidence of an infrastructure dedicated to compromising WordPress sites and massively deploying fake human verification pages. After several Anomalies talking about ClickFix, it no longer seems like a passing curiosity but rather one of the most reused initial access techniques of the moment.
AmnesiaStealer converts browser sessions to remote access
Researchers analyzed AmnesiaStealer, a new infostealer for macOS that goes one step beyond password and cookie theft. In addition to extracting information from browsers, keychains and applications, it incorporates a module capable of taking control of active sessions in Chromium using Chrome DevTools Protocol. In practice, this allows an operator to interact with already authenticated accounts from a hidden browser, turning a traditional infection into a form of remote access that is much more difficult to detect and revoke.
Android — Manic can pull information even from offline phones
ThreatFabric discovered Manic, a new Android malware that mixes banking Trojan, spyware and remote control capabilities and primarily targets users in Ukraine. In addition to abusing Accessibility to capture PINs, passwords and authentication codes, monitor the screen and remotely control the device, Manic has a quite particular capability: if the phone loses Internet access, it encrypts and stores the stolen information and searches for other infected devices nearby to use as a relay, communicating via Wi-Fi Direct or Bluetooth and forming chains of up to four hops until finding a route to the C2.A very interesting technique that makes simply isolating a phone from the Internet not necessarily stop exfiltration.
--[Threat Intelligence ]--
Mustang Panda falls into the trap
[IBM. This allowed them to observe their hands-on-keyboard activity for several days: recognition of systems and networks, search for credentials, extraction of documents and even errors when writing commands that confirm that a good part of the operation was manual. During the follow-up they also discovered Havencode, a new backdoor with hidden VNC capabilities that allows you to remotely navigate and control the victim’s desktop.The observed campaign is mainly focused on government and energy sector organizations in India and uses decoys related to geopolitical and hydroelectric tensions between India and China.
Russian espionage abuses WhatsApp device pairing
Google is tracking three Russian-linked spy clusters that target diplomats, academics, researchers, nonprofits, and other high-profile individuals by abusing legitimate authentication mechanisms. One of them, UNC7005, uses fake WhatsApp pages to convince the victim to scan a QR or enter a code that actuallyd links their account to a device controlled by the attackers, giving them access to their conversations. After the engagement, the same page simulates calls while requesting access to the microphone and camera to record the victim. The group also uses device-code phishing, OAuth theft, and malware for Windows and macOS.A good reminder that compromising an account doesn’t always require breaking the platform’s security: sometimes it’s enough to abuse existing features.
--[Cyber-security Panorama ]--
Brazil - New campaign abuses Microsoft authorization codes to take control of corporate accounts
Kaspersky researchers alerted about a campaign targeting corporate users in Brazil that exploits Microsoft’s code authorization mechanism to gain access to business accounts without needing to steal passwords. The technique uses phishing emails that lead to fake pages where victims enter codes generated by Microsoft’s own platform, unknowingly authorizing access to a device controlled by the attackers. Once the process is complete, operators can access emails, files stored in the cloud, and Microsoft Teams conversations.The case shows how legitimate functions designed to facilitate access to corporate services continue to be reused in social engineering campaigns.
The business of expired domains
A report shows how criminal groups are purchasing thousands of expired domains to take advantage of their historical reputation, residual traffic, and the trust still placed in them by some security systems. According to the research, about one in five domains registered daily already had a previous owner, and some actors have invested millions of dollars in acquiring them to distribute malware, redirect users to fraudulent sites or fuel other criminal operations. The report shows how a domain’s reputation has become an asset that can also be bought, resold and reused within the cybercrime economy.
Brazil/Mexico — Grandoreiro remains active after police operation
Researchers identified a new Grandoreiro campaign aimed primarily at users in Mexico. The banking Trojan, originally attributed to Brazilian developers, uses sideloading DLL techniques and new evasion capabilities to make it harder to detect. The finding shows that the threat is still active and adapting two years after an international operation that sought to dismantle its infrastructure.
--[Platforms and censorship ]--
Venezuela - denounce the use of copyright claims to remove journalistic content
The National Union of Press Workers (SNTP) warned about a series of attacks directed against Venezuelan media through allegedly fraudulent complaints of copyright infringement. According to the organization, the claims seek to cause the elimination of publications or the temporary suspension of journalistic accounts on digital platforms, affecting the circulation of information of public interest. Here we see again how intellectual property moderation and protection mechanisms can be used as censorship tools when platforms process complaints without adequately verifying their legitimacy.
--[Digital violence ]--
Brazil - Ministry requests blocking of sites that generate fake nudes with AI
Brazil’s Ministry of Justice requested to evaluate the blocking of 80 websites that offer AI tools to generate nude images from real photographs. The measure arises after a complaint from SaferNet Brazil and is framed in a context of growing concern about the spread of deepnudes and other forms of digital violence. According to data cited by authorities, almost one in ten Brazilian women reported having suffered some type of digital violence during the last year, while local organizations have documented a sustained increase in cases of false sexual images created and disseminated without consent, including situations recorded in school environments.
Meta: from nudify ads to AI-generated child exploitation content
New research found that Meta allowed the publication of more than 50 ads on Facebook, Instagram, Messenger and Threads that contained AI-generated images of child sexual abuse or promoted services associated with this type of content. The finding comes just weeks after the mass circulation of ads for nudify apps within the same platform was revealed and shows how this ecosystem continues to expand despite moderation mechanisms. Although Meta later removed the ads, the case once again focuses on the platforms’ difficulties in detecting and blocking content linked to sexual exploitation and the generation of non-consensual synthetic images.
Chile - digital attacks against journalists and independent media increase
A report from the Right to Communication Observatory (ODC) documented 424 attacks against the press in Chile between 2022 and 2025, with an increase of close to 70% in incidents recorded during the period. Although physical attacks continue to be frequent, the study warns of a sustained growth in forms of digital violence, including harassment campaigns, attacks on platforms and discredit strategies aimed especially at female journalists. The report also points out that local and independent media are among those most affected by these dynamicsthat seek to wear down journalistic work and favor self-censorship processes.
--[Leaks ]--
Colombia — Ministry of Justice confirms ransomware attack reported weeks ago
The Colombian Ministry of Justice confirmed the ransomware incident that had been previously reported. According to the entity, some files were encrypted and several services were affected, although authorities indicated that they found no evidence of data exfiltration. The case adds to a series of recent incidents against public entities and strategic companies in the country.
--[ Exfiltradaz - Snapshot from 08/07/2026 to 08/21/2026 ]--
During this period, 19 references were identified to leaks and credential markets related to five Latin American countries. Brazil continues to concentrate most of the observed activity, mainly linked to compromised mail accesses, combolists and documents used for identity validation processes.
The main novelty of the period is the appearance of Nicaragua for the first time in the records monitored by Exfiltradaz. Among the references observed, a publication stands out that claims to market a database attributed to the Mayor’s Office of Managua, along with another related to photographs of Nicaraguan passports.
We also observed publications offering passports, ID cards, and driver’s licenses from different countries in the region, including Mexico, Brazil, Argentina, and Nicaragua, as well as references to documents used for identity fraud and KYC processes.
References to Guatemala and Peru were also recorded, while a new actor appeared, Kiwishio, associated with publications about credentials and compromised access.
More details of these leaks in Exfiltradaz
--[ ZOLIM --> Snapshot 08/21/2026 ]--
13 new and very interesting IPs for this ZOLIM snapshot. With these we have already completed 245 detected servers since we started the observatory. :)
Some interesting signs:
- Mexico: In the last snapshot we detected two new IPs hosting Sliver in AS8151. This time we find two new IPs in this same segment Geolocated in Jalisco and Querétaro. The first IP reports Sliver and the second Quasar. In a manual review we also found a Mythic C2 in the second IP . This is an interesting sign: 3 C2 frameworks on 4 IPs in the same ISP (Unitel) in a localized geographic space.
- Chile: In Chile we continue to detect growth in detections and various frameworks and we are very curious about the instance of Hack5 cloud C2 that moves in IPs of TelefĂłnica Chile (AS7418).
If you want to go deeper, take a look at ZOLIM. In the table at the bottom you can search and cross-reference the data by country, ASN, IP, threat, city and other fields. Each IP is a good excuse to start researching. :)