NyxarGroup is a data-theft and leak-oriented threat actor associated with claimed intrusions into Latin American government systems, particularly in Colombia and Chile. The actor has been observed advertising or releasing allegedly stolen government data on public forums, including datasets tied to public-sector workforce systems, transparency and lobbying records, and regional government extranet services. Reported collaborators include ArcRaidersPlayer, Petro_Escobar, CryptoDead, and an alias identified as PescobarLegado in at least one operation. Activity attributed to NyxarGroup has centered on unauthorized access to public-facing government platforms and the extraction of structured records from information repositories. Reported victim organizations include Colombian regional and municipal government entities and Chilean government services. Claimed compromises have involved employee directories, personnel records, public-servant training platform data, and government transparency records, including information related to meetings and official roles. The actor has repeatedly monetized access by offering datasets for sale and has also published stolen records freely, indicating both financial and exposure-driven leak behavior. Observed tradecraft includes exploitation of public-facing applications, collection from information repositories, gathering of employee identity information, archiving of collected data, exfiltration over web services, and post-compromise publication or sale of stolen data. The available reporting supports exfiltration and post-exploitation data handling, but does not provide high-confidence evidence for ransomware deployment, encryption, disruptive attacks, or destructive operations. NyxarGroup appears primarily focused on government-sector data theft and exposure in Latin America rather than network disruption or conventional espionage persistence operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed involvement in an alleged breach and sale of 5.6GB of internal data from the Bogotá Mobility Secretariat.
Selling exfiltrated Colombian government data from the Huila Department extranet as part of a collaborative campaign targeting Latin American government infrastructure.
Claimed sale of allegedly stolen data from Chile's Ley del Lobby government transparency platform, including lobbying records, personal identifiers, contact information, meeting schedules, and details involving senior government and military officials.
Conducting data leak activity against Chilean government platforms, including Servicio Civil and previously Ley del Lobby, and publicly releasing stolen records.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.