#RecomendacionesColCERT 📢 Los invitamos a participar en el Seminario de Inteligencia Artificial y Defensa Digital: Nuevas fronteras de la Seguridad Integral, organizado por @COLADCA, @URosario y la Escuela de Postgrados de la FAC, con el apoyo del ColCERT. ✅
📅 Jueves 21 de mayo de 2026
🕢 7:30 a. m. – 12:30 p. m.
📍 Aula Mutis – Universidad del Rosario
🖱️ Regístrate en: https://t.co/wyUE1l7It8 👉Cupos hasta completar aforo.
#MásPreparados #MinTIC #MásResilientes
ClickFix just leveled up.
One user-pasted command now drops scheduled task persistence + PySoxy (a 10-year-old open-source Python SOCKS5 proxy) for encrypted backup access.
Blocking the first C2? Doesn’t stop it — the task keeps retrying for hours.
Read: https://t.co/YYKwKrR2Qz
🚨ALERTA CSIRTPONAL – Boletín No. 029-2026 (TLP: GREEN)⚠️¡Alerta! Phishing suplantando plataforma de Pagos Acueducto Bogotá... los actores maliciosos emplean la técnica de SEO Poisoning para posicionar sitios web falsos...🔗https://t.co/05iLpDYi7p #CSIRTPONAL#Ciberseguridad
🚨 CRITICAL CYBER THREAT ALERT: SECOND ALLEGED EXFILTRATION OF CITIZEN DATA – NATIONAL REGISTRY OF COLOMBIA 🇨🇴🏛️📂🔓
The offering for sale of a second massive database belonging to the official portal of the National Registry of Civil Status of Colombia (https://t.co/Y37MP4vkc7) has been detected. Threat actor NyxarGroup—in collaboration with the profiles Petro_Escobar, CryptoDead, and ArcRaidersPlayer—claims that this batch corresponds to a new leak resulting from their recent operations against Colombian state infrastructure.
- UNVERIFIED
🏢 Affected Entity: National Registry of Civil Status, Colombia.
👤 Threat Actor: NyxarGroup and associates.
📂 Asset Type: Citizen Database (EfeData).
📅 Publication Date: May 2, 2026.
📊 Breach Scope (PII and Identification Data)
The provided sample reveals the exposure of highly sensitive personal information fields that enable the unequivocal identification of citizens:
NUIP: Unique Personal Identification Number (National ID/Cédula).
Full Identity: First and last names (first and second surnames).
Direct Contact: Mobile and landline telephone numbers.
Geolocation: Detailed residential addresses (e.g., neighborhoods such as Bosa, Pontevedra, El Dorado).
Digital Information: Personal email addresses.
Administrative Data: Municipalities of issuance and residence, document issuance dates, and web status records.
🛡️ Immediate Response Recommendations
🔒 "EfeData" Infrastructure Audit: The National Registry is urged to investigate the security of its data modules (identified within the structure as data.EfeData) to halt this recurring data exfiltration.
🔑 Citizen Security Alerts: Colombian citizens are advised to remain vigilant regarding any unsolicited administrative procedures and to change the passwords for their linked email accounts.
Monitor: https://t.co/wk9bZJ2Nli
#CyberSecurity #Colombia #Registraduria #DataBreach #NUIP #Cédula #NyxarGroup #VECERT #InfoSec #CyberAlert 🇨🇴🛡️⚠️🚨🏛️
#DcRAT#AsyncRat#DarkCrystal esta siendo distribuido actualmente desde el fichero 02a4812ad5c4caf9f3f3887589f1b2cb9895680c10bffcd762826d4a19b4c9a0
IOCs
dianegov[.]co
consultaprocesosramajudicialgov[.]run[.]place
C2 151.243.109.231
🚨Operation PowerOFF continues with a global crackdown against criminal DDoS-for-hire infrastructure. Read more about this coordinated enforcement & prevention action: 🔗https://t.co/REDvq1uk1y
Learn more about the FBI's role in combatting DDoS attacks: 🔗https://t.co/b3mVkCLhML
🚨 CYBERSECURITY ALERT: SUPPLY CHAIN COMPROMISE (ABAI GROUP / DALE! - GRUPO AVAL) 🇪🇸🇨🇴
A massive data breach affecting the Colombian digital wallet Dale! has been confirmed. The entry point was a compromise of Abai Group's systems. 👤 Threat Actors: Petro_Escobar ft. NyxarGroup.
🏢 Source Company: Abai Group
💼 Affected Entity: Dale! (Grupo Aval, Colombia).
Threat Actor: Petro_Escobar ft. NyxarGroup.
📑 Compromised Information:
Identity and PII: Names, surnames, ID numbers, and email addresses of thousands of users.
Field Data: Exact geolocation (GPS) of enrollment points and Visits.
Technical Logs: Integration errors (Kafka/PTS), exposing weaknesses in communication between the provider in Spain and the infrastructure in Colombia.
Personnel Data: Detailed information on Abai/Atento agents and supervisors. This incident highlights the vulnerability of Grupo Aval companies to security breaches in their international technology providers.
🔍 Monitor: https://t.co/wk9bZJ2Nli
#CyberSecurity #AbaiGroup #Madrid #Spain #Colombia #Dale #GrupoAval #DataBreach #SupplyChainAttack #VECERT #Cybersecurity #Hacking #GDPR #InfoSec
🇨🇴 Colombia - Multiple Financial Institutions Face Alleged Data Breach
Colombian Financial Institutions Confront Alleged Data Breach
Multiple Colombian financial institutions, including Banco de Occidente, EmergiaCC, and Conalcreditos, have allegedly been compromised. The claims, made by threat actors, surfaced on an underground forum where data samples were reportedly posted from various Colombian banks. While a specific threat actor group has not been identified in connection with these claims, the incident is part of a broader alleged cyberattack impacting the Colombian financial sector.
The allegedly compromised data includes:
* Customer names
* Login and logout timestamps
* Location data
* Insurance plan details
* Phone numbers
* Physical addresses
* Advisor records
These types of records align with data samples posted in related incidents targeting other major Colombian financial institutions by the same threat actors.
* **Banco de Occidente** (🇨🇴): A prominent commercial bank in Colombia.
* **EmergiaCC** (🇨🇴): A contact center and business process outsourcing (BPO) company, likely providing services to the financial sector.
* **Conalcreditos** (🇨🇴): A Colombian financial services institution, focusing on credit and financial solutions.
#Colombia, #FinancialSector,#DataBreach, #BancodeOccidente,#EmergiaCC,#Conalcreditos,#Cybersecurity,#FinancialServices,#DataLeak