remote access trojan spyware campaign

'Packrat' Cyberspying Campaign Using Remote-Access Trojans Targeting Journalists, Activists, and Politicians in Venezuela and Other Latin American Countries

In December 2015, Citizen Lab revealed Packrat, a regional malware, phishing, and disinformation campaign active since approximately 2008 targeting independent journalists, activists, opposition figures, and political figures in several Latin American countries, including Venezuela and its diaspora. Citizen Lab identified fake infrastructure related to Venezuelan issues, such as PanCaliente and Chavistas24, but explained that it found no evidence that those two sites were used for phishing or malware delivery. The record is maintained as a regional campaign, rather than as individual Venezuelan incidents, because public sources do not name specific Venezuelan victims who could be identified separately.

Overview

Missing evidence

Individual Venezuelan victims identified for separate records by victimForensic attribution to a specific government

Impact details

Citizen Lab documented that Packrat was a regional espionage campaign that used phishing, fake websites, and RATs against journalists, activists, politicians, and public figures, including attacks targeting individuals associated with Venezuela. The record is maintained at the campaign level because public sources do not identify specific Venezuelan victims for individual incidents.

communicationsemailsmessageskeystrokesdevice audio and video capabilitiesaffected devices

Classification & severity

Category
Malicious code
Subtype
remote access trojan spyware campaign
Confidence
High

Citizen Lab documents Packrat as a multi-year Latin American espionage campaign that used phishing, fake websites, and common remote-access Trojans against journalists, activists, and political figures, including targets linked to Venezuela.

Severity assessment

High
Functional impact
None
Information impact
Sensitive personal data
Affected scope
Cross-sector
Critical service
None
Public confidence
Moderate
Recoverability
Extended

Regional espionage campaign targeting Venezuela-related entities and using RAT capabilities; high sensitivity, but at the campaign level, no specific Venezuelan victims have been identified.

Data exfiltration· Claimed Confidentiality

Timeline

Compromise

Estimated start of activity by the Packrat actor, distributing RATs (CyberGate, XTreme RAT) and setting up phishing and disinformation infrastructure in Latin America.

Compromise

Use of the latest RATs (AlienSpy, Adzok) and notable cases such as the attacks on Argentine prosecutor Alberto Nisman and journalist Jorge Lanata; in Venezuela, operation of fake websites such as pancaliente.info.

Disclosure

Citizen Lab publishes the report “Packrat: Seven Years of a South American Threat Actor,” publicly revealing the campaign; media outlets such as SecurityWeek, PCWorld, and CBC cover the story that same day.

Disclosure

The Register and other international media outlets are expanding their coverage of the Packrat campaign.

Evidence & sources

6 sources