Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors NyxarGroup

Also known as: tracked as, APT28, Pawn Storm, Fancy Bear, Sednit

Description

NyxarGroup is a threat actor involved in a coordinated data brokerage ecosystem across Latin America, primarily targeting government infrastructure. They have published high volumes of data, including 110,000 records from Chile's Servicio Civil platform and 250GB from the Ley del Lobby platform, which tracks lobbying activities. The data exfiltrated includes limited fields but provides a directory of Chilean government employees, enhancing the visibility of the public sector workforce. NyxarGroup's activities indicate a focus on exploiting government transparency and training systems for data leaks.

Goals & Targeting

Targeted Sectors

Defense
Financial services
Manufacturing
Energy
Government
Aviation
Critical infrastructure
Utilities

Targeted Countries / Regions

KP

AI Analysis

· 1 week ago

Executive Summary

NyxarGroup is a threat actor primarily operating in Latin America, focusing on exploiting government infrastructure for data exfiltration and brokerage. They have targeted platforms like Chile's Servicio Civil and Ley del Lobby, extracting large volumes of sensitive information. Their activities suggest a sophisticated approach to data collection with potential links to financial gain or strategic influence.

Goals & Targeting

NyxarGroup's strategic objectives likely include financial gain from selling stolen data and possibly influencing government operations by exposing sensitive information. They target sectors with high-value or personally identifiable information (PII), particularly within the public sector. Their focus on Latin American countries suggests a regional operational scope, though they may have global ambitions.

Enhanced Description

NyxarGroup operates within a coordinated ecosystem in Latin America, with a focus on government infrastructure as their primary target. They have successfully exfiltrated significant datasets, including over 110,000 records from Chile's Servicio Civil platform and 250GB of data from the Ley del Lobby platform. These actions highlight their ability to exploit public sector systems and infrastructure for financial gain through data brokerage. Their targeting of government transparency platforms underscores an intent to leverage systemic weaknesses for profit, potentially undermining national security and governance.

Key Capabilities

  • Data exfiltration
  • Exploitation of public sector platforms
  • Spear-phishing
  • Data brokerage

Campaigns & Victims

NyxarGroup has demonstrated a consistent focus on government and public sector targets in Latin America. Their campaigns involve large-scale data extraction, indicating well-organized operations. Notable past activities include significant breaches of Chilean government systems, suggesting a pattern of targeting high-value data sources.

IOC Patterns

  • Large-scale data exfiltration from government platforms
  • Spear-phishing attempts against public sector employees
  • Data leaks involving lobbying activities

Recommended Actions

  • Enhance email security protocols to mitigate phishing risks
  • Monitor data integrity and implement robust logging for suspicious activity
  • Conduct regular security audits of public-facing systems

Suggested Tags

APT
cyber espionage
government targeting
Latin America

Confidence Assessment

Moderate confidence in NyxarGroup's activities based on available details. Specific tools and exact campaign tactics remain unclear, impacting confidence levels.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. redcanary.com — Cited by web research for: T1078.004
  2. attack.mitre.org — Cited by web research for: Interception
  3. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl
  4. www.splunk.com — Cited by web research for: Expand

Intel Summary

10

Techniques

46

Tools

0

Campaigns

5

IOCs

0

Observed Data

4

Tactics

Tags

Data Exfiltration
Government Targeting
APT
cyber espionage
government targeting
Latin America

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.