Peru alert: 6% of ClickFix attacks are already concentrated in the country, and this is how they try to steal your data

6% of the global is concentrated in Peru
Peru is home to 6% of the global cyber attack known as ClickFix. (Illustrative image by Infobae)

Peru has become one of the countries most affected by the cyber attack method known as Click Fixwhich represents 6% of global detections of this type of threat. This is evidenced by a recent analysis by ESET, which studied the evolution of so-called infostealers, malicious programs designed to steal sensitive information from users.

According to the report, this method relies on social engineering to trick victims with fake messages or system alerts that force them to execute commands on their devices.

It should be noted that As soon as the user performs the indicated action, the malware can install itself and start collecting access credentialsfinancial data and other private information stored on your computer.

Cybercriminals trick their victims
Cybercriminals trick their victims into executing malicious commands. (Illustrative image by Infobae)

Experts warn that although the overall volume of detection of infostealers for 2025 has decreased, companies have become more sophisticated and targeted. In this context, Latin America has established itself as a region of particular interest for cybercriminalssignificant activity is noted in several countries.

“Information stealers continue to be one of the favorite tools of cybercriminals because they allow for the stealthy theft of large amounts of credentials and sensitive information,” explained David Gonzalez, ESET’s Latin America computer security specialist.

According to the expert, last year, in the second half of 2025, there was a decrease in the number of detections by 18%. However, this reduction does not mean that the threat has disappeared. On the contrary, Attackers have adopted new strategies, including more targeted campaigns and the use of advanced technology to increase the effectiveness of attacks.

Cybercriminals are increasingly adopting
Cybercriminals are increasingly using strategies to trick users. (Illustrative image by Infobae)

One of the elements of this evolution was the refusal of the creators to develop the well-known malicious program Agent Tesla. Since this change, other malware families have taken center stage in the information theft ecosystem.

Among them, Formbook stands out, which at the end of 2025 was positioned as the most detected family of infixers in the world, with 17.3% of the total number of recorded incidents. This malware is often distributed through phishing campaigns that include emails with malicious attachments..

Another important threat is Lumma Stealer, which has been running massive campaigns targeting users in Mexico in particular. Its main goal is to steal credentials and data stored in web browsers.

The malware spreads to
Malware is distributed through phishing campaigns that arrive via email. (Illustrative image by Infobae)

In the field of mobile communications, new threats have also been discovered, such as NGate or PhantomCard, spyware programs that mainly target the Brazilian financial ecosystem. These tools have the ability to access phone contacts and collect bank card data.

Another family that continues to be present in the region is Spy.Banker, a type of JavaScript-based Trojan that targets financial services users and maintains a detection rate close to 9.5% worldwide.

The analysis also highlights specific developments in various Latin American countries. Mexico, for example, experienced a peak of 70% of global Lumma Stealer detections on July 8, 2025, caused by a massive Spanish-language spam campaign.

There is a lot of attention in Latin America
Much of the cyberattacks are concentrated in Latin America. (Illustrative image by Infobae)

Brazil, for its part, has positioned itself as one of the main sources of fraud using NFC technology, with mobile malware designed to impersonate banking applications or e-commerce platforms. NGate-related activity has also been detected in Chile, while Colombia and Argentina are consistently present on regional phishing detection maps.

Researchers have identified several infection vectors used by cybercriminals to distribute this type of malware. Among the most common are phishing campaigns with attachments that imitate invoices or commercial documents, as well as spam messages that try to trick users.

The ClickFix technique also plays a key role in these attacks. In these cases, Victims receive messages that simulate system errors or instructions to activate the suspected software. The goal is to convince the user to execute commands that end up downloading malware onto their device.

Many times cyber criminals
Cybercriminals often pose as international companies and trick users into executing malicious code. (Illustrative image by Infobae)

Another common method is to use malware loaders such as CloudEyE (GuLoader), tools that are responsible for installing additional malware when they manage to infiltrate the system.

Experts also warn about fraudulent sites imitating official platforms, such as Google Play, in order to distribute infected applications.

Faced with this panorama, experts recommend taking basic digital security measures. Among them stand out avoid executing commands or downloading files from suspicious messagesalways verify the origin of emails and use updated security solutions.

Experts recommend being careful
Experts recommend being careful with messages from strangers and avoid following commands. (Illustrative image by Infobae)

They also advise strengthening your credentials with strong passwords and two-factor authentication. With the development of a model known as Malware as a service and the growing use of artificial intelligence to optimize attacks, experts predict that these threats will continue to evolve in the coming years.

Leave a Reply

Your email address will not be published. Required fields are marked *