Chronus Team is a Latin American hacktivist group that emerged in late 2025 and became known for targeting institutions across Mexico and other parts of the region. The group is also referred to as Chronus Group and Chronus. Its activity has been especially associated with Mexico, with additional targeting reported in Argentina, Brazil, and Bolivia. Chronus Team has claimed responsibility for compromises and data leaks affecting public-sector and adjacent organizations, including entities in education, insurance, law enforcement, healthcare, and government. The group’s operations have centered on web defacements and data-theft-driven leak activity, often using Telegram for publicity, propaganda, and dissemination of stolen information. Reported behavior indicates an emphasis on exposing security weaknesses and pressuring victims through publication of exfiltrated data rather than relying on ransomware encryption. Chronus has also been described as operating in a regional environment where hacktivist and criminal ecosystems overlap, and it has shown affiliations with other hacktivist and criminal groups. In February 2026, Chronus Group claimed to have stolen data from 25 Mexican government agencies and groups. The actor has been cited as compromising Mexican government targets through traditional human-led intrusion activity and exfiltrating substantial volumes of data. In March 2026, Chronus Team merged with Mexican Mafia Team to form Chronus Mafia, expanding its operational scope. Chronus is best characterized as a hacktivist actor focused on politically charged and publicity-oriented intrusions, with data exfiltration and leak operations as core tradecraft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist group conducting attacks and claiming data leaks across Mexico and Latin America, affecting education, insurance, law enforcement, healthcare, and government sectors.
Hacktivist group targeting public-sector and other institutions in Latin America, especially Mexico, using data leaks, web defacements, and financially motivated data sales while seeking publicity.
Cybercriminal collective claiming theft of data from numerous Mexican government agencies, aligned with the regional pattern of stealing and monetizing government-held citizen or administrative data.
Hacktivist collective that compromised the Mexican government using traditional human-led hacking and exfiltrated a large volume of data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.