A threat group that has been active for at least seven years has used malware, phishing and disinformation tactics to target activists, journalists, politicians and public figures in various Latin American countries. The threat actor, dubbed Packrat based on its preference for remote access Trojans (RATs) and because it has used the same infrastructure for several years, has been analyzed by Citizen Lab researchers John Scott-Railton, Morgan Marquis-Boire, and Claudio Guarnieri, and Cyphort researcher Marion Marschalek, best known for her extensive analysis of state-sponsored threats.
Executive Summary
Packrat, a long-active threat actor targeting individuals in Latin America, primarily uses malware, phishing, and disinformation tactics. The group has been operational for at least seven years, focusing on activists, journalists, politicians, and public figures. Their activities suggest a strategic focus on influencing political dynamics and gathering sensitive information.
Goals & Targeting
Packrat's strategic objectives appear to be tied to political manipulation, information gathering, and undermining the credibility of targeted individuals or institutions. The group's targeting profile focuses on individuals with high public visibility or influence, such as journalists, politicians, and activists, particularly in Latin American countries. This suggests a desire to shape public opinion, disrupt governance, or gain access to sensitive information.
Enhanced Description
Packrat is a sophisticated cyber threat actor that has operated for over seven years, primarily targeting high-profile individuals in Latin America. The group specializes in using remote access Trojans (RATs), phishing campaigns, and disinformation tactics to compromise its victims. Packrat's activities have been extensively studied by researchers such as Citizen Lab and Cyphort, who have identified the group's long-term use of stationary infrastructure and its focus on politically sensitive targets. The threat actor's campaigns often involve spear-phishing emails with malicious attachments or links, aiming to infect devices and establish persistent access for surveillance or data exfiltration. Packrat’s operations demonstrate a high level of operational security and persistence, making it a significant concern for governments, media organizations, and activists in the region.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Packrat has demonstrated a consistent operational pattern over the years, with a focus on long-term campaigns and targeted attacks. The group's use of stationary infrastructure and persistent access techniques indicates a patient and methodical approach. Notable past operations include numerous phishing campaigns targeting activists and public figures in Ecuador and other Latin American countries. Packrat's ability to remain active for over seven years underscores its resilience and operational effectiveness.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
There is high confidence in Packrat's existence and operational patterns due to multiple studies by reputable researchers. However, gaps remain regarding the group's precise motivations, exact membership, and full range of capabilities.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
1
Campaigns
122
IOCs
0
Observed Data
0
Tactics