Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Guacamaya

Description

Guacamaya has conducted multiple hack and leak campaigns against military and police agencies and mining companies across Latin America, which they believe have played a role in the region’s environmental degradation and repression of native populations.

AI Analysis

· 2 weeks ago

Executive Summary

Guacamaya represents a cyber threat group conducting hack-and-leak operations primarily in Latin America. They target military, police, and mining sectors, aiming to expose information to reveal ties between these entities and environmental degradation and repression of native populations. The group's activities are regionally focused but have significant implications for targeted organizations.

Goals & Targeting

Guacamaya targets sectors they believe contribute to environmental degradation and social repression, such as military, police agencies, and mining companies. Their focus is on Latin American countries involved in these industries. By targeting these sectors, the group seeks to influence public perception, drive policy changes, and promote social justice through the exposure of sensitive information.

Enhanced Description

Guacamaya is a cyber threat actor known for their hack-and-leak campaigns against military, police agencies, and mining companies across Latin America. Their primary targets include state institutions and corporate actors involved in industries perceived to contribute to environmental damage or social repression of indigenous populations. Guacamaya's operations are politically motivated; they seek to expose sensitive information and internal communications to the public through leaks. This approach aims to raise awareness about environmental issues, promote transparency, and bring attention to human rights violations, aligning their activities with a broader hacktivist agenda.

Key Capabilities

  • Cyberattack execution
  • Data exfiltration
  • Spear-phishing campaigns
  • Network intrusion

MITRE ATT&CK Tactics

Initial Access
Defense Evasion
Credential Access

ATT&CK Techniques

T1059.003
T1566
T1078

Software / Tooling

Custom tools for data exfiltration and network intrusion
Potential use of phishing tools

Campaigns & Victims

Guacamaya's campaigns are characterized by their focus on Latin American targets. Their operational strategy involves compromising systems, extracting sensitive data, and leaking it to the public, often through forums or news outlets. Notable past operations include attacks against mining companies and law enforcement agencies in countries where environmental issues are prominent.

IOC Patterns

  • Spear-phishing emails targeting military and police sectors
  • Use of custom tools for network intrusion

Recommended Actions

  • Monitor spear-phishing attempts targeting state institutions
  • Enhance access controls and implement multi-factor authentication
  • Conduct regular security audits and vulnerability assessments
  • Implement log monitoring and analysis capabilities to detect potential intrusions

Suggested Tags

Hacktivism
Environmental activism
Latin America

Confidence Assessment

Low confidence due to limited available information on Guacamaya's exact TTPs, tools used, and full attack patterns. The group's activity is relatively new or emerging, leading to gaps in historical data.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Government Targeting
Hacktivism
Environmental activism
Latin America

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.