HomeNewsRansomware Built in Venezuela Used to Target Institutions Across Latin America
NEWS

Ransomware Built in Venezuela Used to Target Institutions Across Latin America

CYBERCRIME / 24 MAY 2022 BY SCOTT MISTLER-FERGUSON EN

Venezuela has emerged as a potential base for the development of ransomware tools to cybercriminals after one man was charged with designing software used to carry out a range of cyberattacks.

Earlier this month, Moises Luis Zagala Gonzalez, from Bolivar City, was charged in the Eastern District Court of New York for attempted computer intrusions and conspiracy to commit intrusions owing to his "use and sale of ransomware, as well as his extensive support of, and profit sharing arrangements with, the cybercriminals who used his ransomware programs."

SEE ALSO: Major Ransomware Attacks in Peru and Costa Rica Spell More Trouble for Region

Going by aliases 'Nosophoros,' 'Aesculapia' and more recently 'Nebuchadnezzar,' the cardiologist had amassed a long list of criminal clients over the years.

He primarily offered clients access to a tool for creating fully customizable ransomware programs known as 'Thanos'. Additionally, he leased and operated his own ransomware program known as 'Jigsaw v. 2', reportedly charging $500 a month to use the software and $3,000 for the underlying source code.

Zagala's Thanos program was used as the model for a slew of offshoots that plague international institutions. Prometheus, Haron and Midas are all variants of Zagala's original program that dabble in this extortive economy. Prometheus in particular, has a long list of Latin American victims with a special appetite for institutions in Chile and Brazil.

For several years, undercover agents with the US Federal Bureau of Investigation (FBI) tracked his business as well as the dedicated cybercrime team he himself allegedly led.

According to the FBI, Zagala sold his Thanos ransomware builder to at least 38 clients, accepting payments via PayPal and cryptocurrencies, including at least one "Iranian state-sponsored hacking group," according to the criminal complaint.

InSight Crime Analysis

Ransomware as a Service (RaaS) has been widely used to target companies and institutions across Latin America for their sensitive data. It also provides a low barrier to entry, thus fueling the proliferation of ransomware programs.

Zagala's Thanos tool fits this mold perfectly.

Boasting a wide array of customization features and the added benefit of continued tech support from Zagala himself, the ransomware builder gives cybercriminals access to a new frontier of victims even if they themselves are not expert hackers. "Numerous users responded to Zagala... posting that they had used the software and praising its quality," stated FBI agent Chris Clarke in his testimony.

For Steph Shample, a cybersecurity expert and fellow at the Middle East Institute, RaaS providers are opening the floodgates for further data theft and extortion, especially in an internet space as poorly regulated as Latin America's.

Shample explained "these RaaS actors can essentially cater and do absolutely everything for you. If you can pay that fee to have more of the hand-holding; plus the fact that that it's all remote means anybody can purchase their tools to conduct ransomware attacks."

SEE ALSO: Latin American Governments Easy Prey for Ransomware During COVID-19

In July 2021, one report detailed how Prometheus had been used to target a wide range of victims in Brazil, Mexico, Peru and Chile, including government institutions, customs agencies, financial institutions and private companies.

Brazilian private and public institutions report the largest portion of attacks from ransomware gangs. In 2020, the country accounted for nearly half of all such reported attacks in the region with Mexico and Colombia trailing behind.

This regional disparity may also be due in part to more consistent attention paid to the issue in those countries. Shample noted "Colombia and Brazil are a little bit better in terms of cyber security," but that their high rates of connectivity make for nice potential targets in "finance, supply chains and the manufacturing sector."

share icon icon icon

Was this content helpful?

We want to sustain Latin America’s largest organized crime database, but in order to do so, we need resources.

DONATE

What are your thoughts? Click here to send InSight Crime your comments.

We encourage readers to copy and distribute our work for non-commercial purposes, with attribution to InSight Crime in the byline and links to the original at both the top and bottom of the article. Check the Creative Commons website for more details of how to share our work, and please send us an email if you use an article.

Was this content helpful?

We want to sustain Latin America’s largest organized crime database, but in order to do so, we need resources.

DONATE

Related Content

CARIBBEAN / 15 OCT 2021

Merchants travelling to Trinidad and Tobago, fishing vessels, even the occasional tourist – all are tempting targets for pirates off…

COCAINE / 29 JUN 2022

Turkish and foreign law enforcement have seized record quantities of cocaine heading from South America to Turkey, revealing the growing…

BRAZIL / 15 JUN 2023

From Colima to Caracas, some parts of Latin America have stubbornly high homicide rates, far higher than the rest of…

About InSight Crime

THE ORGANIZATION

InSight Crime Contributes Expertise Across the Board 

22 SEP 2023

This week InSight Crime investigators Sara García and María Fernanda Ramírez led a discussion of the challenges posed by Colombian President Gustavo Petro’s “Total Peace” plan within urban contexts. The…

THE ORGANIZATION

InSight Crime Cited in New Colombia Drug Policy Plan

15 SEP 2023

InSight Crime’s work on emerging coca cultivation in Honduras, Guatemala, and Venezuela was cited in the Colombian government’s…

THE ORGANIZATION

InSight Crime Discusses Honduran Women's Prison Investigation

8 SEP 2023

Investigators Victoria Dittmar and María Fernanda Ramírez discussed InSight Crime’s recent investigation of a massacre in Honduras’ only women’s prison in a Twitter Spaces event on…

THE ORGANIZATION

Human Trafficking Investigation Published in Leading Mexican Newspaper

1 SEP 2023

Leading Mexican media outlet El Universal featured our most recent investigation, “The Geography of Human Trafficking on the US-Mexico Border,” on the front page of its August 30…

THE ORGANIZATION

InSight Crime's Coverage of Ecuador Leads International Debate

25 AUG 2023

This week, Jeremy McDermott, co-director of InSight Crime, was interviewed by La Sexta, a Spanish television channel, about the situation of extreme violence and insecurity in Ecuador…