The Gulf Cartel is a Mexican organized crime group primarily associated with drug trafficking and related criminal activity. Available reporting in this context links the group to illicit firearms procurement networks, including allegations that trafficked weapons were funneled to criminal organizations such as drug cartels and that a leader of the Gulf Cartel was among prospective customers in a firearms-trafficking investigation. The group is also referenced in connection with senior cartel leadership, including mention of Dario Antonio Usuga David under the label of a former Gulf Cartel leader, but that specific leadership characterization is not sufficiently reliable to generalize further here. Based on the supplied facts, the Gulf Cartel should be characterized as a criminal actor involved in narcotics-trafficking ecosystems and associated weapons acquisition rather than as a ransomware or state-sponsored cyber threat actor. No high-confidence cyber intrusion tradecraft, malware usage, or digital attack lifecycle behaviors are directly supported in the available information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a criminal organization allegedly receiving firearms trafficked by Jorge Enrique Alberts Ponce and associates.
Referenced as a Colombian drug trafficking organization allegedly connected through Pabon and Otoniel.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.