
Peru has become one of the countries most affected by the cyber attack method known as Click Fixwhich represents 6% of global detections of this type of threat. This is evidenced by a recent analysis by ESET, which studied the evolution of so-called infostealers, malicious programs designed to steal sensitive information from users.
According to the report, this method relies on social engineering to trick victims with fake messages or system alerts that force them to execute commands on their devices.
It should be noted that As soon as the user performs the indicated action, the malware can install itself and start collecting access credentialsfinancial data and other private information stored on your computer.

Experts warn that although the overall volume of detection of infostealers for 2025 has decreased, companies have become more sophisticated and targeted. In this context, Latin America has established itself as a region of particular interest for cybercriminalssignificant activity is noted in several countries.
“Information stealers continue to be one of the favorite tools of cybercriminals because they allow for the stealthy theft of large amounts of credentials and sensitive information,” explained David Gonzalez, ESET’s Latin America computer security specialist.
According to the expert, last year, in the second half of 2025, there was a decrease in the number of detections by 18%. However, this reduction does not mean that the threat has disappeared. On the contrary, Attackers have adopted new strategies, including more targeted campaigns and the use of advanced technology to increase the effectiveness of attacks.

One of the elements of this evolution was the refusal of the creators to develop the well-known malicious program Agent Tesla. Since this change, other malware families have taken center stage in the information theft ecosystem.
Among them, Formbook stands out, which at the end of 2025 was positioned as the most detected family of infixers in the world, with 17.3% of the total number of recorded incidents. This malware is often distributed through phishing campaigns that include emails with malicious attachments..
Another important threat is Lumma Stealer, which has been running massive campaigns targeting users in Mexico in particular. Its main goal is to steal credentials and data stored in web browsers.

In the field of mobile communications, new threats have also been discovered, such as NGate or PhantomCard, spyware programs that mainly target the Brazilian financial ecosystem. These tools have the ability to access phone contacts and collect bank card data.
Another family that continues to be present in the region is Spy.Banker, a type of JavaScript-based Trojan that targets financial services users and maintains a detection rate close to 9.5% worldwide.
The analysis also highlights specific developments in various Latin American countries. Mexico, for example, experienced a peak of 70% of global Lumma Stealer detections on July 8, 2025, caused by a massive Spanish-language spam campaign.

Brazil, for its part, has positioned itself as one of the main sources of fraud using NFC technology, with mobile malware designed to impersonate banking applications or e-commerce platforms. NGate-related activity has also been detected in Chile, while Colombia and Argentina are consistently present on regional phishing detection maps.
Researchers have identified several infection vectors used by cybercriminals to distribute this type of malware. Among the most common are phishing campaigns with attachments that imitate invoices or commercial documents, as well as spam messages that try to trick users.
The ClickFix technique also plays a key role in these attacks. In these cases, Victims receive messages that simulate system errors or instructions to activate the suspected software. The goal is to convince the user to execute commands that end up downloading malware onto their device.

Another common method is to use malware loaders such as CloudEyE (GuLoader), tools that are responsible for installing additional malware when they manage to infiltrate the system.
Experts also warn about fraudulent sites imitating official platforms, such as Google Play, in order to distribute infected applications.
Faced with this panorama, experts recommend taking basic digital security measures. Among them stand out avoid executing commands or downloading files from suspicious messagesalways verify the origin of emails and use updated security solutions.

They also advise strengthening your credentials with strong passwords and two-factor authentication. With the development of a model known as Malware as a service and the growing use of artificial intelligence to optimize attacks, experts predict that these threats will continue to evolve in the coming years.

