
Map of current malware attacks, showed that the context of Art cyber security experience in Latin America. In the report provided by ESET, it was clear that threats move quickly between countries and mainly target public, medical and government environments.
Campaigns are no longer isolated events, but rather coordinated operations that demonstrate a network of cooperation between criminal groups, with consequences affecting the critical infrastructure of the most vulnerable countries.
This is evidenced by the numbers and cases collected over the past year Peru, Mexico and Argentina They lead the ranking of the most attacked countries in the region.
These countries not only receive the largest volume of threats, but have also become laboratories for testing new variants of malware, which are then spread to other countries in Latin America.

The report shows that malware attacks in Latin America have a dynamic pattern: they start in one country, such as Peru, and then spread to other neighbors. This phenomenon is explained by the existence of common threats, families of adapted malware and, sometimes, cooperation between criminal groups that share methods and resources to increase the effectiveness of their operations.
The public and health sectors were particularly vulnerable. Government institutions in Peru have been hit by high-precision attacks, while in Argentina healthcare and government organizations continue to suffer from infectionseven due to old exploits running due to lack of system updates.
In Peru, malicious activity grew gradually and The country has become the “zero patient” of companies that later spread to other latitudes.
In recent months, an attack known as the “Dirin Leaks” has exposed sensitive data from the National Intelligence Service, including agents’ personal information and presidential security protocols.

In second place is Mexico. This is a profitable target for attackers who use mainly phishing and social engineering-based ransomware campaigns.
Argentina has seen a steady increase in attacks, taking third place. The health care sector and public organizations were the most affected. Of note is the attack on the Argentine military in the first quarter of 2025, when the Monti ransomware group stole 300 GB of data from Fabricaciones Militares Sociedad del Estado, including strategic military projects.
Brazil is the fourth country in the number of incidents, concentrating most of its problems in the theft of financial data. A notable case was C&M Software, where the employee sold his credentials and facilitated the diversion of over 800 million Brazilian reals.
In Colombia, the number of attacks on one organization is increasing at a rapid rate. The persistent threat group Blind Eagle attacked an airline company using old vulnerabilities to infiltrate systems.

Recurring threats in all countries include – Rugmia bootloader that acts like a scanner: it analyzes the infrastructure, checks for protection, and only when it detects a vulnerability, downloads the underlying malware, which is usually ransomware or another type of disruptive threat.
This modus operandi allows attackers to avoid early warnings, as the initial impact appears to be small and discreet.
Phishing remains the dominant strategy. Attackers use PDF files and HTML pages with specific options designed to trick users into obtaining credentials or banking information. These campaigns affect both individuals and employees in important sectorsfacilitating access to internal systems.
A feature of the Argentine script is the persistence of the CVE-2012-0143 exploit, which exploits memory flaws in older versions of Office. That this vulnerability, which is over fourteen years old, remains effective, points to delays in software updates and the presence of outdated systems in critical infrastructures.

