Caliente BanditsCaliente Bandits

Also known as: TA2721 · Caliente Bandits

Known aliases
2

Profile

Caliente Bandits is a highly active threat group that targets multiple industries, including finance and entertainment. They distribute the Bandook remote access trojan using Spanish-language lures through low-volume email campaigns. The group primarily impacts individuals with Spanish surnames and conducts reconnaissance to obtain employee data. They masquerade as companies in South America and use Hotmail or Gmail email addresses.

Aliases· 2

TA2721Caliente Bandits

References

  1. https://www.proofpoint.com/us/blog/threat-insight/new-threat-actor-uses-spanish-language-lures-distribute-seldom-observed-bandook

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
Packrat
Actor
Dalbit
Actor
TA2722
Actor
El Machete
Actor
RevengeHotels
Actor
TA2725
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.