Chronus
Chronus Team is a hacktivist group that emerged in late 2025 and primarily targeted institutions in Latin America, especially in Mexico, Argentina, Brazil, and Bolivia. Reporting cited in the content describes the group as particularly active against Mexican organizations, including public-sector entities in education, insurance, law enforcement, healthcare, and government. Chronus Team is associated with web defacements and Telegram-based data leaks intended to expose security vulnerabilities. The group has also been described as using affiliations with other hacktivist and criminal groups. One cited account states that Chronus compromised the Mexican government using traditional human-led intrusion activity and exfiltrated more than 15 times the data obtained in a later AI-assisted breach by another collective. In March 2026, Chronus Team reportedly merged with Mexican Mafia Team to form Chronus Mafia. Known names and related designations mentioned in the content include Chronus, Chronus Team, and Chronus Mafia.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
- Public Safety
- Health Care Equipment & Services
- Insurance
- Academia & Research
Where they target
Geographies tied to known operations.
- 🇲🇽 Mexico
- 🇦🇷 Argentina
- 🇧🇷 Brazil
- 🇧🇴 Bolivia
Tradecraft
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist group targeting public-sector and other institutions in Latin America, especially Mexico, using data leaks, web defacements, and financially motivated data sales while seeking publicity.
Hacktivist collective that compromised the Mexican government using traditional human-led hacking and exfiltrated a large volume of data.
Hacktivist group conducting defacement attacks and data leaks, primarily against organizations in Mexico, while using Telegram for communication and propaganda.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.