Skip to main content
Mallory
Back to threat actors
🇲🇽 MX

jalisco_new_generation_cartel

Also known asjalisco_new_generation_cartel

The Jalisco New Generation Cartel (Cártel de Jalisco Nueva Generación; CJNG) is a Mexico-based transnational criminal organization. The content identifies Nemesio Rubén Oseguera Cervantes, alias "El Mencho," as the former head of CJNG, and states that his killing in a Mexican military operation on February 22, 2026 was followed by violent incidents in Guadalajara, Jalisco, including shootouts with security forces and roadblocks linked to organized crime. The reporting assesses transnational criminal organizations as a major physical security threat in Mexico, particularly around Guadalajara, with risks including theft, extortion, express kidnapping, fraud, transport disruption, and cartel-linked violence. Separate FBI and FinCEN-linked reporting in the content states that timeshare fraud schemes have been linked to CJNG in Mexico, including telemarketing, impersonation, and advance-fee fraud targeting timeshare owners, and that proceeds from these schemes are used to diversify revenue and finance other criminal activities, including illicit fentanyl and other synthetic drug trafficking into the United States. The content also notes reporting that some Mexican cartels obtained access to commercial spyware with police assistance, but does not attribute that specifically to CJNG. Known aliases directly mentioned in the content are Jalisco New Generation Cartel, Cártel de Jalisco Nueva Generación, and CJNG.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Transportation
  • Consumer Services

Where they target

Geographies tied to known operations.

  • 🇲🇽 Mexico

Where they're from

Attributed origin per open-source reporting.

  • MX
MITRE ATT&CK

Tradecraft

9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

6 of 15 tactics9 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
2 techniques
T1589
Gather Victim Identity Information
T1591
Gather Victim Org Information
TA0001
Initial Access
1 technique
T1566
Phishing
TA0002
Execution
1 technique
T1059
Command and Scripting Interpreter
TA0007
Discovery
1 technique
T1018
Remote System Discovery
TA0011
Command and Control
1 technique
T1105
Ingress Tool Transfer
TA0040
Impact
3 techniques
T1496
Resource Hijacking
T1499
Endpoint Denial of Service
T1531
Account Access Removal
IOCS

Observables

15 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping9

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables15

Domains, IPs, and hashes tied to this actor, refreshed continuously.