MexicanMafia, also tracked as PanchoVilla and in some reporting associated with Mexican Mafia Team, is a Latin America-focused threat actor linked with medium confidence to a sophisticated multistage intrusion campaign known as Operation Escaneo. The actor has been observed targeting critical infrastructure and public-sector organizations primarily in Mexico, with additional activity in Ecuador and limited activity in Portugal. Reported victim sectors include government, tax authorities, utilities, transportation, telecommunications, financial services, judicial entities, and energy organizations. The actor demonstrates mature offensive capability across Windows, Linux, enterprise application, and network infrastructure environments. Observed tradecraft includes automated reconnaissance, exploitation of internet-facing perimeter systems, deployment of web shells and reverse tunnels, credential theft, extraction of cryptographic material, Active Directory mapping, privilege escalation, lateral movement, and long-term persistence. Tooling associated with the actor includes a proprietary reconnaissance framework called Kimera, Neo-reGeorg web shells, Chisel reverse tunnels, and persistence through compromised Cisco routers using GRE tunnels. The actor has also been reported exploiting vulnerabilities in Fortinet, Ivanti, Apache Tomcat, Windows SMB services, and Linux polkit, and using techniques and tooling such as Zerologon, EternalBlue, PwnKit, RDP, PsExec, and Impacket. Post-compromise activity has included access to SAP ERP and Oracle database systems for command execution and data theft, theft of service-account material and browser-stored credentials, extraction of large identity datasets, and compromise of SSL private keys and mobile device management infrastructure. Reporting indicates the actor maintains redundant persistence mechanisms and is capable of adapting public exploit code and combining host-level and network-level access to evade detection and preserve long dwell time. MexicanMafia has also been described as making breach claims against Mexican government, judicial, and energy targets during 2024, sometimes framing activity as protest or hacktivism. At the same time, technical reporting on Operation Escaneo indicates a blend of opportunistic monetization and possible intelligence collection, making the actor’s characterization somewhat mixed. In March 2026, Mexican Mafia Team reportedly merged with Chronus Team to form Chronus Mafia, suggesting overlap with the broader Latin American hacktivist and cybercriminal ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
76 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
13 CVEs this actor has used in observed campaigns. 13 of them exploited in the wild.
Privilege escalation and lateral movement are achieved through a combination of exploiting vulnerabilities (Zerologon, EternalBlue, and PwnKit flaw CVE-2021-4034 among them)...
Privilege escalation and lateral movement are achieved through a combination of exploiting vulnerabilities (Zerologon, EternalBlue, and PwnKit flaw CVE-2021-4034 among them)...
These include FortiGate SSL-VPN vulnerabilities CVE-2022-42475, CVE-2023-27997, and CVE-2024-21762...
...as well as the CVE-2023-46805/CVE-2024-21887 Ivanti Connect Secure authentication bypass and command injection chain.
These include FortiGate SSL-VPN vulnerabilities CVE-2022-42475, CVE-2023-27997, and CVE-2024-21762...
8 more CVEs tied to this actor tracked in Mallory.
17 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A dark web criminal marketplace advertising alleged murder-for-hire, weapons, forged documents, affiliate programs, escrow services, and cryptocurrency-based anonymous transactions across multiple onion mirrors and related Telegram/payment infrastructure.
Named group referenced as merging with Chronus Team to form Chronus Mafia.
A suspected hacktivist-linked group that allegedly claimed breaches against Mexican government, judicial, and energy targets and was attributed with medium confidence to Operation Escaneo.
Financially motivated threat actor behind Operation Escaneo, conducting a sophisticated multistage campaign against critical infrastructure in Latin America while combining large-scale data theft and opportunistic monetization with possible intelligence collection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.