--[ Anomaly #16 - The open Windows. ]--
September 4, 2026
By: ZoqueLabsThis writing is distributed under a Creative Commons CC BY-SA (Acknowledgment - Share Alike) license.
Spanish version
Â
Hello hello,
Today we want to talk a little about Windows, the omnipresent operating system in governments, industry and civil society that we often do not look at enough, but which represents one of the most persistent attack surfaces that we find in our work.
The civil society digital security community is usually highly concentrated on attacks on mobile devices (iOS/Android) and much less on attacks on desktop systems (Windows/Linux/macOS). However, the latter often represent a much larger, easier and cheaper attack surface to exploit than the spyware chains that we usually study on mobile phones.
We know that a good part of these attacks are perpetrated by criminal organizations, but we also know that these types of techniques and malware are fundamental pieces in attacks directed against journalists, media, human rights defenders, civil society organizations and activists.
And there’s something interesting there: perhaps because many of these threats are associated with cybercrime they seem “less interesting” to our community. But its effects on the daily functioning of organizations can be enormous.
Much of the public or cheap spyware available on the market works on Windows and there are a huge number of techniques to ensure that malware normally detected by antiviruses passes by and ends up compromising computers around the world.
This has quite concrete consequences. Many civil society organizations use Windows for a good part of their administrative tasks and store sensitive information there about their operation, their members and the communities with which they work. Compromise of just one of these workstations can quickly become a problem for the entire organization.
At ZoqueLabs, as an exercise, we have been following for some time the activities of an actor in Colombia called Blind Eagle -of which, by the way, we have news in this edition of Anomaly because apparently this time they were the ones who ended up infected with malware-. This actor has been attacking Windows systems via email for years and using techniques ranging from a simple encrypted ZIP attachment to things a little more elaborate, such as SVG files that make the infection process from a malicious email more fluid.
Blind Eagle does not use particularly sophisticated malware or super 1337\ infection chains. Use relatively simple and cheap techniques, but effective enough. The result is often financial fraud, credential theft, initial access for other attacks, or compromised accounts that then serve as a springboard to new victims by leveraging, for example, the trust generated by receiving an email from a well-known organization.
Thus, the attack stops affecting only the organization that originally received the email and begins to spread to the people and organizations that trust it.
Let’s also think about small, grassroots organizations, with tight budgets but with important work on public policies, the environment, community protection, human rights and many other issues. A theft of money can paralyze your work or even put the continuity of the organization at risk. Ransomware can leave critical information inaccessible. A compromised email account can expose nearby members, sources, communities, and organizations.
In this context, it matters relatively little whether a spyware company, a state actor or a group of criminals looking for money was behind it: the commitment of one of the computers with which the organization works can become the difference between being able to continue doing its job. or not.
AsyncRAT (open source), DCRat (Malware as a Service) or Remcos (commercial spyware) are just some examples of what we usually find in our monitoring. They are the tip of the iceberg of a Windows malware ecosystem that has been growing for decades and to which we must pay attention if our job, as part of the civil society digital security ecosystem, is to prevent digital threats from compromising security, privacy or the continuity of the work of organizations that rely on us to take care of their technological assets.
In addition, investigating this malware has another advantage: there is a lot.
We have samples, infrastructure, campaigns, code, public analytics, incidents and actors to study. That gives us a lot more material with which to learn infection, persistence, evasion, lateral movement, and command and control techniques than we normally have available when researching mobile operating systems. Malware that at first glance may seem uninteresting can end up teaching us a lot about how real systems are compromised.
So this editorial is an invitation not to neglect the study of attacks against Windows. In many organizations it can be the difference between being able to continue working or not and, for various reasons -outdated systems, unlicensed software, known vulnerabilities or absence of updated security tools-it still represents a huge attack surface.
Maybe it doesn’t always have a 0-day exploit, a super-sophisticated chain, or the name of a surveillance company behind it.
But an open window is still an open window.
And being no more, dear people, we leave you with Anomaly. :)
--[Technical analysis ]--
AI again in intrusion campaigns in LATAM
Unit 42 analyzed two active campaigns that affected organizations in Mexico and Brazil and found an element that we have already seen recently in Anomaly: the use of language models as part of the attackers’ operation. The cases include intrusions against public entities, transportation services and financial sector organizations. According to the report, operators used tools such as GPT and Claude to generate scripts, fix bugs and resolve problems during different phases of attacks. The evidence appeared on exposed servers where traces of conversations, NextChat interfaces, and multiple versions of files created during the process remained.
An infection exposed part of Blind Eagle’s operation
We have been following the operations of Blind Eagle for some time, the Colombian APT to which we dedicated an entire chapter in The Blind Eagle Diaries. We know that they range from phishing campaigns that impersonate Colombian entities to the use of legitimate services to distribute malware, a good part of their activity has gone through Anomaly. This time the story is different: a LevelBlue investigation found traces of the operation after one of the computers associated with the actor was compromised by other malware. The exposed records allowed us to observe tools, phishing templates, infrastructure and part of the mechanisms that support their campaigns.
Brazil - BraZetsu and the sale of access
Group-IB published an analysis on BraZetsu, a tool used to compromise teams and fuel an underground marketplace where access to organizations is sold. The malware is mainly focused on Brazil and seeks information that allows assessing each compromised system, including browsing histories, digital certificates, corporate software and CNAB files used in financial processes. The accesses obtained are cataloged and put up for sale on a platform known as Infect Marketplace, where other actors can acquire them to deploy new tools or carry out subsequent operations. The report also describes the use of AI to automate victim classification and prioritize targets within this process.
--[Surveillance ]--
Serbia - detect a new wave of surveillance with Pegasus and spyware against students and opponents
The SHARE Foundation organization documented at least 14 cases of people attacked with spyware in Serbia during 2026, including students, activists and representatives of opposition parties. Forensic analysis confirmed an infection with Pegasus through a 0-click attack and also detected new variants of NoviSpy, spyware previously linked to surveillance cases in the country. According to the investigation, some devices were allegedly compromised after being confiscated by authorities during police interrogations. The findings come amid growing pressure on student movements, journalists and political actors ahead of this year’s election cycles.
--[Malware ]--
Dark Caracal appears again in Latin America with new tools
Researchers identified a new campaign attributed to Dark Caracal, a group known for its digital espionage operations in Latin America and other regions. The discovery arose from an attack against a communications organization in Venezuela and made it possible to identify a new tool called GoCaracal, along with updated versions of the Bandook malware, historically used by the group. The investigation found infrastructure and activity related to several countries in the region, including Brazil, Chile, Colombia, Ecuador, El Salvador and Uruguay. In addition to updating its tools, Dark Caracal incorporated new mechanisms to keep its campaigns operational even when part of its infrastructure is blocked.
--[Digital Violence ]--
Meta once again lets through ads for nudity apps
WIRED found ads on Facebook and Instagram promoting Kromix, an application that allows you to generate sexual images and videos from photographs of real people. Among the ads were references to female politicians and messages promoting AI tools “without restrictions”. Meta withdrew the campaign after inquiries from the media and Apple later removed the application from the App Store. The case appears a few weeks after Meta announced new measures to stop this type of services, showing the difficulties that platforms continue to have in detecting and blocking tools designed to create non-consensual intimate images.
Brazil - The “nude hit” that continues to appear on dating apps
Brazilian authorities warned about new cases of the so-called golpe do nude, a form of extortion through intimate content that usually begins on dating applications and social networks. The dynamic is what we already know: attackers establish contact with people, obtain intimate images and then threaten to publish them to demand money. Although it is not a new phenomenon, apparently this type of violence has increased in recent months, we do not know if it is because people are reporting more or because this type of aggression is increasing?
--[Platforms ]--
Colombia - Social networks and forced recruitment
Meta published details about an operation against networks linked to an armed organization that operates between Colombia and Venezuela. According to the company, these accounts spread propaganda, promoted external communication channels and sought to reach out to young people through social networks. The report is relevant because it puts back on the table something that is often left out of conversations about platforms: digital spaces are also part of disputes over influence, legitimacy and recruitment. For many armed organizations, social media is no longer just a place to post content, but also a channel to build relationships, expand audiences, and reach out to potential new membersmany of them minors. And this does not only happen in Meta, we will have to see how these platforms propose strategies that seek to limit these dynamics without the solution ending up expanding surveillance or restricting online rights.
--[Phishing ]--
Mexico - Phishing kit automates vishing campaigns with AI
Group-IB documented Balonx, a phishing-as-a-service platform that incorporates AI tools to automate scam calls. The system combines models from OpenAI, Whisper and ElevenLabs to hold real-time conversations with potential victims, simulating banking agents without human intervention. According to the research, the campaigns are currently aimed at people located in Mexico, however it is a pattern that we have seen grow more and more in other LATAM countries.
--[Leaks ]--
Brazil - They sell festival-goer data for financial fraud
A database with more than 412,000 buyer records from The Town 2025 festival appeared for sale on a Russian-speaking forum. Although it is still unclear whether the leak comes directly from Ticketmaster or one of the multiple actors involved in the ticket sales and processing chain, the data includes names, emails, telephone numbers and CPF numbers of people in Brazil and other countries. of the region According to the sales publication itself, the records would be useful for bank fraud, credit applications and registration of telephone lines.
Mexico - The cyberattack on Tlajomulco continues to leave more questions
Four months after the cyber attack that left more than 120 municipal procedures out of service in Tlajomulco (Mexico), details about the real impact of the incident remain unknown. While local authorities assure that services have been returning, doubts persist about the status of databases related to ownership, payments, beneficiaries and administrative records. The case once again shows a recurring problem in Latin America: when an incident occurs in a public entity, the discussion usually focuses on the interruption of services, but it is rarely clearly reported what information may have been lost, altered or exposed.
--[Vulnerabilities ]--
Colombia - Third wave of attacks against SonicWall VPN devices in less than a year
SonicWall again warned about the active exploitation of two critical vulnerabilities in its SMA1000 devices, used by companies and public entities to manage remote access. What is striking is not only the severity of the failures, but it is the third chain of zero-day exploitation against this equipment in less than a year. Previous research showed that ransomware-linked groups managed to gain privileged access, corporate credentials, and even multi-factor authentication (MFA) seeds, a scenario that is not always resolved by applying patches. Among the organizations affected during the campaigns observed this year,investigators also identified victims in Colombia.
--[Fraud ]--
Frauds with AI and voice cloning continue to grow in Latin America.
Different reports show an increase in account-taking attempts, identity theft and scams supported by deepfakes, synthetic voices and personalized messages. The phenomenon is fueled by both increasingly accessible AI tools and constant data leaks that expose phone numbers, emails, identity documents and other useful information to build more credible hoaxes. That is why at Exfiltradaz we follow the trail of leaks so much, with that information and other phishing techniques, financial fraud continues to increase.
--[ Exfiltradaz - Snapshot from 08/21/2026 to 09/04/2026 ]--
During this period, 28 references to leaks, compromised accesses and publications associated with ransomware were identified in six countries in Latin America. Brazil and Mexico concentrated most of the observed activity, followed by Colombia, Ecuador, Peru and Chile.
The activity was marked by the circulation of accesses to compromised email accounts, databases attributed to people in Brazil and publications related to financial services. In Brazil, new references to alleged databases associated with Serasa and SERPRO companies linked to the financial sector and government stood out, in addition to multiple offers of verified email credentials.
Publications linked to ransomware groups claiming to have compromised organizations in the region were also observed, including Italtel PerĂş, the Hospital ClĂnico de la Universidad de Chile, Mobilemed in Brazil and Quaker State Mexico.
In Colombia references related to digital credentials and services continued to appear, although with a lower volume than in other monitoring countries. Additionally, new actors were identified in the observed spaces, including cloudmarket_pro, evil zone bot, jirui, and peter_okcard.
More details of these leaks in Exfiltradaz.
--[ ZOLIM --> Snapshot 09/04/2026 ]--
12 new and very interesting IPs for this ZOLIM snapshot. With these we have already completed 257 detected servers since we started the observatory. :)
Some interesting signs:
- Colombia: The movements associated with Blind Eagle show us new infrastructure on the Colombian Caribbean coast, but this time we noticed several instances of the same malware running on the same IPs, for example a server with 3 instances of AsyncRAT* * and another server with 2 instances of **Quasar.
- Brazil: There is always a lot of activity in this country, but this time we see that it is beginning to follow trends from other countries this time with new instances of Sliver and Havoc. Interesting!
- Honduras / Chile: Hack5 cloud C2 continues to move through dynamic IPs in these countries.
If you want to go deeper, take a look at ZOLIM. In the table at the bottom you can search and cross-reference the data by country, ASN, IP, threat, city and other fields. Each IP is a good excuse to start researching. :)