Los Ciberinfiltrados is a Colombian cybercriminal group associated with the illegal access of telecommunications systems and the commercial distribution of pirated streaming content, including major sports broadcasts such as World Cup matches. Public reporting links the group’s activity to at least 2024 and indicates that Colombian authorities arrested four suspected members during a broader multinational enforcement effort targeting illicit streaming and related intellectual property crime. The group’s operations have been described as relying on unauthorized access to telecommunications environments and abuse of service-provider infrastructure to enable piracy at scale. Reported tradecraft includes the use of fraudulent credentials, VPNs, interception of security codes, and manipulation of corporate system profiles. These methods indicate a blend of credential abuse, unauthorized account access, and operational security measures intended to conceal actor activity while maintaining access to systems used to redistribute protected content. Los Ciberinfiltrados appears to be financially motivated rather than espionage-oriented. Its known activity centers on cyber-enabled piracy and the monetization of unauthorized media distribution, rather than destructive operations or strategic intelligence collection. The group has been publicly tied to the sale of pirated streaming services through compromised or fraudulently obtained access to telecommunications systems. No widely used alternate name or formally identified sub-group is currently available from the provided reporting. There is no high-confidence public basis in this material to characterize the group as a nation-state actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Colombia-based criminal group accused of illegally accessing telecommunication systems and selling pirated streaming content, including unauthorized World Cup 2026 match streams.
Cybercriminal group involved in illegally accessing telecommunication systems and selling pirated streaming content, including World Cup matches.
Cybercrime group allegedly involved in illegally accessing telecommunication systems and selling pirated streaming content, including World Cup matches.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.