The Jalisco New Generation Cartel, commonly known as CJNG and formally Cártel de Jalisco Nueva Generación, is a Mexico-based transnational criminal organization. It is widely associated with large-scale narcotics trafficking and violent organized crime activity, and has also been linked to fraud operations used to generate illicit revenue. Reporting ties the group to timeshare telemarketing and advance-fee fraud schemes targeting owners, with proceeds assessed as supporting broader criminal enterprises including synthetic drug trafficking. CJNG has been associated with violent confrontations with Mexican security forces, roadblocks, and broader cartel-linked disruption in Jalisco, particularly around Guadalajara. Following the reported killing of longtime leader Nemesio Rubén Oseguera Cervantes, also known as El Mencho, violence linked to the organization highlighted its capacity to rapidly mobilize coercive and disruptive activity. Beyond physical violence, CJNG has been linked to organized fraud infrastructure involving impersonation, social engineering, and financial extraction from victims over extended periods. Available reporting also indicates some Mexican cartels obtained access to commercial spyware through corrupt police assistance, but attribution of specific spyware use directly to CJNG is not established at high confidence. Known naming variants include Jalisco New Generation Cartel and Cártel de Jalisco Nueva Generación (CJNG).
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
15 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Mexico-based transnational criminal organization assessed as a persistent physical security threat around the 2026 FIFA World Cup, particularly in Guadalajara and transit corridors. The group is described as capable of disruptive acts such as road blockades, arson attacks, and coordinated armed confrontations.
A Mexico-based transnational criminal organization assessed as a persistent physical security threat around the World Cup, capable of disruptive acts such as road blockades, arson attacks, and coordinated armed confrontations that could affect mobility and logistics.
Linked by FBI/FinCEN to Mexico-based boiler-room style call centers running complex, long-running timeshare telemarketing/impersonation/advance-fee fraud schemes; proceeds used to diversify revenue and finance other criminal activity (including fentanyl/synthetic drug manufacturing and trafficking).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.