Meet Batuta, our game-changing Cyber Defense Command and Control Center.
Magically simply cybersecurity.

Threats

Botnet Fenix: New botnet going after tax payers in Mexico and Chile

By Gerardo Corona & Julio Vidal Ocelot Team Context Ransomware gangs have found a profitable market in LATAM, but they are not alone, they need region-based actors to provide them the initial access to the companies. These local groups create phishing campaigns based on the government activities during the year, like Tax season, testament month, …

Botnet Fenix: New botnet going after tax payers in Mexico and Chile Read More »

Inside Mispadu massive infection campaign in LATAM

Fernando Garcia & Dan Regalado Ocelot team Context The Metabase Q Security Operations Center (SOC) triages millions of alerts a day but a recent attempt to infect a customer’s network caught our attention. Although the customers’ endpoint detection and response security tools properly blocked the initial payload, the use of fake certificates to try to …

Inside Mispadu massive infection campaign in LATAM Read More »

ImageMagick: The hidden vulnerability behind your online images

ImageMagick: The hidden vulnerability behind your online images

By Bryan Gonzalez from Ocelot Team Introduction ImageMagick is a free and open-source software suite for displaying, converting, and editing image files. It can read and write over 200 image file formats and, therefore, is very common to find it in websites worldwide since there is always a need to process pictures for users’ profiles, …

ImageMagick: The hidden vulnerability behind your online images Read More »

Ploutus is back, targeting Itautec ATMs in Latin America

By Jesus Dominguez from Metabase Q’s Ocelot Team Ploutus, one of the most sophisticated ATM malware families worldwide, is back with a new variant focused on Latin America. Discovered for the first time in 2013, Ploutus enables criminals to empty ATMs by taking advantage of ATM XFS middleware vulnerabilities via an externally connected device. Since …

Ploutus is back, targeting Itautec ATMs in Latin America Read More »

How does ALPHV operate the RaaS membership program?

By Ramses Vazquez & Miguel Gonzalez from Metabase Q’s Ocelot Team Context DARKSIDE/BLACKMATTER/ALPHV-BLACKCAT The ALPHV Ransomware group also known as BlackCat has positioned itself in the Top 5 of most active ransomware groups. Among the target industries of this group are construction, energy, financial, logistics, manufacturing, pharmaceuticals, retail, and technology. The scheme under which this …

How does ALPHV operate the RaaS membership program? Read More »