Guacamaya is a hacktivist collective active primarily in Central and Latin America. The group is known for intrusions and large-scale data leaks targeting state institutions, armed forces, and corporations, especially organizations associated with mining, oil, extractive industries, and security services. Guacamaya presents its activity as politically motivated, framing operations around anti-imperialism, environmentalism, opposition to extractivism, and resistance to what it characterizes as oppressive state and corporate power in Latin America. The group became widely known in 2022 after operations against major corporate and government targets. It claimed attacks against mining and energy companies in Latin America and later announced “Operation Fuerzas Represivas,” a campaign directed at the armed forces of several Latin American countries. High-profile incidents attributed to Guacamaya include the compromise of Chile’s Joint Chiefs of Staff, the large-scale breach of Mexico’s Secretariat of National Defense known as the SEDENA leaks, military-related leaks in Peru, and the compromise of Colombia’s prosecutor’s office that later underpinned the NarcoFiles investigation. Guacamaya has also been associated with attacks affecting the governments of El Salvador and Guatemala. Operationally, Guacamaya is best characterized by unauthorized access followed by exfiltration and public disclosure of sensitive internal communications and documents. Its tradecraft, as supported here, centers on initial access to high-value institutional targets, post-exploitation collection of internal data, and exfiltration for strategic leaking rather than financially motivated extortion or ransomware deployment. The group has used leak-publishing channels including Distributed Denial of Secrets and Enlace Hacktivista to disseminate stolen material. Its operations have had significant political and public-interest impact, exposing alleged military surveillance, corruption, ties between state actors and criminal organizations, and abuses linked to security forces and extractive projects. Guacamaya is an international rather than state-sponsored actor. Based on the available facts, it should be understood as a regional hacktivist threat actor focused on politically charged disclosures across Latin America rather than a conventional cybercriminal or espionage service.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist group that targeted Mexican defense institutions as part of a broader ideological campaign focused on environmental and indigenous-rights issues in Latin America.
Guacamaya is referenced as a possible background influence or as a group whose name is being used to obscure the real perpetrators of the El Salvador biometric data breach.
Hacktivist collective conducting intrusions and large-scale data theft/leaks against Latin American governments (notably defense/military institutions) and extractive-sector companies (mining/oil), publishing stolen data via leak platforms and media partners; campaigns include 'Operation Fuerzas Represivas' and major email/data leaks such as the SEDENA/Guacamaya Leaks and NarcoFiles source emails.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.