Operation Escaneo is a coordinated intrusion campaign targeting organizations in Latin America, with the strongest concentration of activity in Mexico and additional observed activity in Ecuador and Portugal. Victims have included government entities, tax authorities, utilities, transport organizations, telecommunications providers, and banks, indicating a focus on public sector, financial, and critical infrastructure environments. The operation has been associated with large-scale data theft and sustained post-compromise access. The campaign’s initial access has centered on exploitation of internet-facing security appliances, especially Fortinet FortiOS SSL-VPN and Ivanti Connect Secure vulnerabilities. Operators also maintained exploit capability for GhostCat, EternalBlue, Zerologon, and Log4Shell, showing a broad toolkit for opportunistic and tailored intrusion. Reconnaissance and target triage were supported by a custom scanning engine known as Kimera, which was used to identify viable targets and feed them into exploitation workflows. For persistence and covert access, the operators used Neo-reGeorg webshells, Chisel reverse tunnels, and a compromised Cisco router configured with a GRE tunnel to create a network-level channel that could help evade host-based defenses. Post-compromise activity included access to SAP and Oracle systems for command execution and movement within victim environments. Reported theft included large volumes of personal data, Active Directory information, SSL private keys, SAP service-account hashes, and browser-stored passwords, demonstrating strong capabilities in reconnaissance, credential theft, persistence, defense evasion, and exfiltration. Operation Escaneo has been linked with medium confidence to a suspected hacktivist group tracked as Mexican Mafia, also known as Pancho Villa. That association is not definitive, but the campaign has been connected to actors previously claiming breaches against Mexican government, judicial, and energy targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.