CyberTeam is a hacker group publicly associated with cyberattacks against Paraguayan public-sector entities. Reporting links the group to attacks on Paraguayan government websites and public institutions during 2025, and places it among multiple international groups that targeted Paraguay within a short period. Available information supports characterization of CyberTeam as an intrusion and disruption actor focused at least in part on government targets in Paraguay. High-confidence public details about its organizational structure, tooling, malware families, sponsorship, or broader victimology remain limited. There is insufficient corroborated information to attribute CyberTeam to a nation state or to assess whether it operates as a ransomware crew, hacktivist collective, or financially motivated criminal group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another named hacking group that allegedly compromised the Paraguayan government within the prior three months; no additional operational details provided.
Hacktivist-style group claiming a sustained campaign of intrusions/defacements against Paraguayan public institutions and government websites, including claims of unauthorized access to internal systems.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.