--[ Anomalía #16 - Forensics, but with permission ]--
September 18, 2026
By: ZoqueLabsThis writing is distributed under a Creative Commons CC BY-SA (Acknowledgment - Share Alike) license.
Spanish version
Hello hello!
Today we want to talk a little about digital forensics.
When we think of a forensic investigation we probably imagine a phone connected to some specialized machine, a complete copy of the device, hashes, bags of evidence, chains of custody and eventually a report that could end up being presented to a judge.
And yes, that is digital forensics.
But it is not necessarily the type of forensic that we do from civil society.
When a journalist, activist or human rights defender arrives with the suspicion that their phone or computer may be compromised, our first reaction is usually not to copy everything on their device. In fact, we try to do exactly the opposite: collect as little information as possible so we can answer the questions we have at that moment.
If with a few artifacts we can advance, we start there. If we find something that warrants looking a little further, we go back to the person, explain what we found, what we need now, and why, and keep moving forward.
This way of working has been called consensual forensic and is a fairly common practice among those of us who investigate digital threats against civil society and human rights.
The difference may seem only technical, but in reality it is much deeper.
A phone is probably one of the most intimate objects we have. It contains conversations, photographs, locations, contacts, personal relationships, medical information, journalistic sources and a lot of things that have absolutely nothing to do with the research we are doing. Having the technical capacity to extract them does not mean that we need to do so.
That is why we try to advance the research progressively. First a question, then some artifacts, then maybe another question and other artifacts. The affected person is not simply the owner of a piece of evidence: it is part of the investigation process and can decide how far they want us to go.
This also changes what we mean by successful research.
In a police investigation or in a large part of the commercial forensic investigation, it may be essential to preserve a perfect chain of custody, make a complete acquisition of the device or document each procedure thinking that the evidence could end up being used in a judicial process. For this, there are specialized tools and equipment capable of making very deep extractions of phones and computers, including products such as those developed by Cellebrite.
We are usually trying to solve another problem.
We want to know what happened, how it happened, who else might be at risk, and what we can learn from the attack. We want to find infrastructure, malware, vulnerabilities, indicators or techniques that allow us to understand a threat and, when possible, expose it.
Sometimes that work ends up contributing to a judicial process. Other times it serves to protect other organizations, advocate, change public policy, document abuse, produce threat intelligence, or simply help a person understand what happened to their device.
And that difference matters.
The same forensic capabilities that allow huge amounts of information to be retrieved from a phone to investigate a crime can be converted into surveillance capabilities when used against journalists, activists, human rights defenders or anyone else whose device ends up under the control of an authority. A very powerful forensic tool is still a very powerful tool regardless of who is sitting in front of the screen.
Therefore, for those of us who do this work from civil society, the question should not only be how much information we can extract from a device, but how much information we really need to continue the investigation.
This does not mean that chain of custody, evidence preservation, or traditional forensics methodologies do not matter. There are investigations where they will be fundamental and cases that will eventually need to take that leap. It simply means that our starting point and our objective may be different.
Our work is often more like following clues than building a file.
A strange artifact takes us to a domain. The domain to an IP. The IP to another campaign. A malware sample takes us to infrastructure that has been active for months. An anomaly in a phone ends up connecting with attacks against other people in another country. And at some point those little pieces begin to show us a threat that was previously hidden.
For us, one of the greatest technical achievements of a forensic investigation occurs precisely there: when we manage to bring a threat to light.
Because once we can see it, we can investigate it. We can share it. We can look for it in other cases. We can help other people detect it and we can start asking who is using it, against whom and for what.
And perhaps that is a good way to explain how we understand forensics from civil society.
Enter only as far as we need to enter, learn everything we can from the clues we found and, above all, try to stop what was happening in silence from being silent.
And well, that’s where we are.
We leave you with the Anomaías of this edition:
--[Surveillance ]--
CyberGlobes - first find the target, then hack it
An investigation by TheMarker based on leaked documents shows how the Israeli company CyberGlobes turned OSINT, facial recognition, fake accounts and leaked credential bases into tools to identify and map LGBT activists, protesters, dissidents and people. Documented cases include participants in protests in Nigeria and Mozambique and assisting an Indonesian government entity to create lists of LGBT people and map the groups to which they belonged. Perhaps most revealing is its relationship with NSO Group: for years both companies offered their products together under simple logic -before compromising someone’s phone with Pegasus, you first have to know who to attack-.An example of how the surveillance ecosystem goes far beyond spyware and how seemingly public information can be part of the chain that makes a person a target. The article has paywall, but can be found on services that store cached copies of web pages.
Anthropic is building systems to monitor activists and protests
An investigation by The American Prospect shows how Anthropic is expanding its internal capabilities to monitor activists, protests and other mobilizations around the company and its executives. The company uses real-time monitoring services and even talks about moving towards a “predictive” model that allows anticipating possible incidents. It is particularly striking coming from a company that has publicly placed limits on the use of its models for mass surveillance: the same intelligence and monitoring capabilities that we usually discuss when we talk about governments are also beginning to appear within large technology companies.
DarkSword - a leaked chain ends in Russian operations against NATO-linked targets
We continue to find new operators of DarkSword, the chain of six exploits for iOS that we have been following since its leak. Trellix documented a campaign attributed with high confidence to a Russian state actor related to COLDRIVER/Star Blizzard, spear-phishing senior government and defense officials of NATO-aligned organizations. The links filtered victims by device and location before delivering the exploit and could compromise iPhones running iOS 18.4–18.7. Trellix has medium confidence that DarkSword was specifically the string used because the server was already offline when they investigated, but the case adds another sign of how quickly a leaked string can end up in the hands of completely different state actors.
Venezuela - CIA cyber operations were used to locate Maduro
CIA Deputy Director Michael Ellis publicly stated that the agency’s cyber operations were instrumental in building the intelligence used by US forces to locate and capture Nicolás Maduro in Caracas in January. Ellis did not explain which systems were compromised or what techniques were used, but described information obtained through cyber operations as a central part of the intelligence landscape that allowed it to be located. It’s an unusual public admission about the CIA’s digital operations and a fairly straightforward example of how a cyber operation can end up connected to a physical operation.
--[Technical analysis ]--
Threat Intel - from a malicious GitHub repository to an entire credential marketplace
Winslow publishes a highly recommended writeup that starts with a malicious GitHub repository and ends up rebuilding much of the ecosystem that existed behind it. Based on forks, stars, Git history, infrastructure and malware, the research connects fake repositories with a modular RAT, RedHive Stealer, theft of credentials and sessions and, finally, channels where those accesses end up resold and reused by other actors. A good practical demonstration of threat intelligence: start with a small artifact and follow the clues until you understand who operates behind it, how its infrastructure works and what happens to the information after it is stolen.
LATAM - FamousSparrow puts Latin America in the spotlight
ESET found a rather striking change in FamousSparrow operations: as of mid-2025, around 90% of the targets observed in its telemetry are in Latin America. The group, aligned with China, is using a new modular backdoor called SparroWocky against government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela. The malware allows you to execute commands and files, function as a proxy, take screenshots and exfiltrate information. It is unusual to find an espionage operation linked to China with such a strong and sustained concentration in our region.
--[Malware ]--
LATAM - fake tax documents end up installing an HVNC
ANY.RUN documented a campaign targeting Latin American organizations that uses fake tax documents, DocuSign, and ClickFix-related techniques to deploy a HVNC backdoor. Once installed, the malware allows Windows to be controlled using a hidden desktop that the victim does not see, in addition to registering keys, stealing browser information, and maintaining access after reboots. The chain uses separate infrastructure for delivery, staging and C2 and searches for more than twenty AV/EDR products on infected computers. Another example of how completely everyday documents within an organization’s administrative processes can become a fairly effective vector of persistent access.
Chile and Colombia - malware designed specifically for FortiGate
A campaign is exploiting FortiGate devices to install PivotC2, a Node.js framework designed specifically for these computers. The malware can extract device settings and decrypt credentials stored there, including VPN keys, SSL-VPN credentials, Wi-Fi passwords, and administrative accounts, and then automatically scan internal networks. Operators scanned more than 30,000 devices and compromised 178; After the United States, Chile and Colombia appear among the countries with the highest concentration of infections. Quite relevant because the device that should protect the network border ends up becoming the point from which credentials are obtained to enter it.
Argentina and Chile - BambooToken uses MQTT as a C2 channel
BambooToken is a new family of malware for Windows and Linux that uses MQTT, a protocol much more associated with IoT, as a communication channel with its operators. The campaign has been active since at least 2023 and among the identified victims are a biomedical company in Argentina and a law firm in Chile. Interestingly, this is not the first time that MQTT has appeared in malware: among the antecedents is Tizi, a malware for Android that also used the protocol for C2. A good example of how technologies designed to connect devices end up being reused to control compromised machines.
Argentina - Red Heron compromises Gitea and deploys a new rootkit for Linux
Acronis documented Red Heron, a Chinese-speaking actor that quickly exploited CVE-2026-60004 against exposed Gitea servers and gained access to organizations in Canada, Argentina, Taiwan, the United States, and Sri Lanka. The operation includes theft of source code and credentials, persistence via SSH, lateral movement and a new rootkit for Linux; Among the compromised objectives in Argentina is a quantitative trading company. The actor also classified potential government, electoral, energy, aerospace and telecommunications targets.
--[Phishing ]--
Mexico - AI is also beginning to automate phishing calls
A Phishing-as-a-Service platform called Balonx, seen primarily in attacks against Mexico, incorporated CallFlow, a system that combines several AI services to automate vishing calls with almost no human intervention. The idea is to turn something that traditionally requires operators speaking individually with each victim into an operation capable of maintaining multiple personalized conversations in parallel. The service is also promoted on Telegram and Facebook groups dedicated to the purchase and sale of databases. A quite logical evolution of industrialized phishing: the stolen bases provide the information and the AI also begins to take care of the call.
--[Leaks ]--
Costa Rica - a huge leak, but first you have to show what is real
Costa Rica is investigating an alleged massive leak after an actor claimed to have millions of records with identification photographs, salaries, addresses, telephone numbers, vehicles, court records and other personal data; He even used information from President Laura Fernández as a sample. What is interesting is how the case is being handled: instead of assuming that the seller’s claims are true, the National Cybersecurity Directorate is trying to determine authenticity, origin, volume and affected population. An initial analysis of about 10,000 lines confirmed that some of the information corresponds to real people, but its origin is not yet known.An important distinction in an ecosystem where “someone posted a base on a forum” becomes “X organization was hacked” too quickly.
Colombia - Cali investigates an alleged leak of more than 600,000 records
The Cali Mayor’s Office confirmed that it is investigating a base of more than 600,000 records that appeared in a forum and was attributed to the entity, but assures that so far it has not found evidence of an intrusion into its systems. The Mayor’s Office even suggests that some of the material could have been compiled from legitimately public documents and later presented as the product of a hack. As with the case of Costa Rica, we find it interesting to see a leak treated as something that still needs investigation: finding real data in the hands of an actor does not automatically prove where it came from, when it was obtained, or whether an intrusion existed.
--[Vulnerabilities ]--
Colombia - compromising a SonicWall can survive even the update
An investigation into attacks against SonicWall SMA1000 describes a chain that combines two vulnerabilities to obtain root on the device and turn the VPN itself into a platform for authentication persistence and theft. The attackers went so far as to extract the TOTP seeds used for MFA, allowing them to generate valid codes even after changing passwords; in addition, they modified system files, and there were cases where attackers rolled back updates installed during the response. Colombia appears among the countries with identified victims, along with the United States, Australia, the United Arab Emirates and Switzerland. The important thing: once the device is compromised, updating it is not enough;you have to rebuild it from a trusted state and rotate the credentials and MFA seeds stored there.
China - 0-days of Chrome and Windows against civil society organizations
Volexity detected UTA0560, an actor linked to China, sending spear-phishing specifically against several non-governmental organizations. The emails directed victims to the legitimate site of an American university that had an XSS vulnerability and from there redirected them to infrastructure that deployed a chain of exploits, including Chrome 0-day CVE-2026-85046. Another Chinese actor, JungleBamboo/APT31, was using the same chain against other targets. A particularly relevant case for civil society: visiting a legitimate site from a carefully prepared link could be enough to enter a chain of browser and Windows exploitation.
--[ Critical infrastructure ]--
Colombia - when a cyberattack begins to affect medical care
A report by Biofile warns about the growing exposure of the Colombian health sector to computer attacks and indicates that six out of every ten cyberattacks reported in the country would target hospitals and clinics, taking IBM X-Force data as a reference. Beyond the figure, what is important is the impact: in a hospital it is not necessary to delete a medical history to cause harm; Preventing a doctor from consulting an allergy, medication, or outcome in time can delay procedures and directly affect patient care. According to the report, during the first half of 2026, 410 attacks and claims were also recorded against health providers and companies, 247 of them against hospitals, clinics and other direct providers. In health infrastructure,cybersecurity also ends up being a problem of continuity of essential services.
--[Cybercrime ]--
Brazil - government servers hijacked to promote illegal betting
A campaign attributed to the Chinese-speaking group Gambling Goblin is compromising servers of public entities and educational centers, mainly in Brazil, to take advantage of the reputation of their domains and position illegal betting sites. The servers function as reverse proxies, so a person may end up viewing fraudulent content while the browser bar continues to display the legitimate domain of a government or educational institution. The current target appears to be fraud and SEO, but the same compromised infrastructure could be used for phishing or malware distribution. Interesting precisely because it shows that compromising public infrastructure can have value for attackers even when data stored there is not targeted.
--[ Exfiltradaz - Snapshot from 09/04/2026 to 09/17/2026 ]--
During this period, 12 references to leaks, compromised accesses and publications associated with ransomware were identified in seven countries in Latin America. Brazil concentrated the largest number of records observed, mainly related to the commercialization of compromised email accesses, while Colombia, Chile and Ecuador recorded activity associated with credential markets and ransomware campaigns.
The activity of the period was dominated by publications linked to ransomware, with incidents reported in Argentina, Peru, Chile and Ecuador. Among them, a publication attributed to the N0n group stands out, which claims to have compromised information related to the Ministry of Education of Argentina, a case that deserves follow-up.
We also observed activity from the TheGentlemen group in Chile and new references to the Vexy Ransomware group in Ecuador. On the other hand, a new actor was identified in the monitoring, toxy, associated with a publication that announces an alleged leak attributed to the National Directorate of Civil Aeronautics (DINAC) of Paraguay.
More details of these leaks in Exfiltradaz.
--[ ZOLIM --> Snapshot 09/17/2026 ]--
15 new and very interesting IPs for this ZOLIM snapshot. With these we have already completed 272 detected servers since we started the observatory. :)
Some interesting signs:
- Colombia: Servers associated with Blind Eagle on the Colombian coast continue to move DCRat, AsyncRat and Quasar on residential IPs in Barranquilla.
- Brazil: we have an interesting pattern, last time we detected a new Sliver, this time we found another one with GoPhish running on the same server and a new instance of Cobalt Strike. All of these in the same ASN (AS7738) of ISP V Tal.
- Chile: Hack5 cloud C2 continues to move through dynamic IPs in Chile, we did not see Honduras in this snapshot.
If you want to go deeper, take a look at ZOLIM. In the table at the bottom you can search and cross-reference the data by country, ASN, IP, threat, city and other fields. Each IP is a good excuse to start researching. :)