Structural Disadvantages Facing LATAM Security Practitioners
Political volatility accelerates threats across the region. Digital adoption outpaces security literacy. Investment in cybersecurity infrastructure and local talent development remains chronically low. SANS training prices are, by Cruz Forero’s account, completely insane for the LATAM market. Real training in Spanish or Portuguese barely exists. Practitioners build expertise with bash, Python, and open-source tools instead of commercial stacks, turning budget constraints into hard-won depth.
How Low-Tech Attacks Bypass Technical Detection
Two months before this talk, a webpage impersonating a Colombian social security payment provider ran for 20 days on a Canadian hosting service. No malware. Clicking the link opened a WhatsApp chat where attackers stole money from people trying to pay their social security fees. VirusTotal showed nothing malicious because the page contained nothing malicious. Losses reached $1 million. Insurance claims followed. Cruz Forero describes the attack as low tech: street-wise rather than sophisticated, and nearly impossible to force down quickly.
LATAM Malware Families With Global Reach
Machete is a LATAM-origin malware targeting government systems, documented in Kaspersky research. Blind Eagle has hit the region consistently. The Brazilian financial sector produced Grandato and Kasbano, banking trojans replicated across multiple countries and sold as off-the-shelf tools for stealing money. LATAM generates threats as well as absorbs them. Both attackers and defenders emerge from the same resource-constrained environments, shaped by the same lack of institutional support.
Hardware Tools and Offensive Research From LATAM Communities
From the Argentinian community: Doggy, a new hardware attack tool. From Electronic Cats: Catnifer, a tool for radio frequency attacks and also the physical badge for this year’s LaVilla. A Colombian red team engagement against a bank started with a deserialization vulnerability and reached critical bank infrastructure. An Argentinian researcher built a TLS attack called Partole that extracted session cookies from TLS connections. Social engineering attacks, now fueled by AI for impersonation, also appear. A group reprogrammed a child-safety robot, converting it into a mobile surveillance threat.
Community as Infrastructure for LATAM Security
Cruz Forero built a security chapter in Bogotá, then BSides Colombia, then LaVilla. LaVilla is a Defcon village for Spanish and Portuguese speakers, running in rooms 2020 and 2021. The point: community replaces the institutional support that never materialized. No formal threat-sharing infrastructure exists in the region. Knowledge passes through what he describes as informal conversation, the security equivalent of gossip between friends. His ask to the global community: sponsor LATAM projects, include Latin voices in threat intelligence exchanges, and remember how you started.
Notable Quotes
we are not waiting to be invited to the table we are bringing our own table Giovanni Cruz Forero · ▶ 15:40
nothing’s malicious in the web page Giovanni Cruz Forero · ▶ 8:50
Key Takeaways
- LATAM practitioners develop security expertise through open-source tools and community, not enterprise training budgets.
- Low-tech attacks like WhatsApp social security scams evade VirusTotal and cost millions with no malware present.
- LATAM-origin malware families including Grandato and Kasbano now operate globally as commoditized financial crime tools.
About the Speaker(s)
Giovanni Cruz Forero is a cybersecurity professional with 20 years of experience. He serves as COO of 7 Way Security and co-founded CSIETE. He organized BSides Colombia, HackLab Bogotá, and LaVilla at Defcon, focusing on building security talent across Latin America through shared knowledge.