🚨 CYBERINTEL ALERT: POSSIBLE ACTIVE INTRUSION IN PROGRESS — POSSIBLE COMPROMISE OF THE CHILEAN ARMY 🇨🇱
⚠️ CRITICAL THREAT: THREAT ACTOR "EL ESPEJO DE TU SOMBRA" EXFILTRATING MILITARY RECORDS AND PERSONAL DATA (RUN) IN REAL TIME
[STATUS: ACTIVE MONITORING; AUTOMATED SQL EXPLOITATION TOOLS DETECTED]
Through active monitoring, the threat actor "El Espejo De Tu Sombra" (previously associated with high-impact incidents, such as the NemorisHacking breach in Guatemala) has been detected announcing and providing a technical demonstration of an active attack targeting government institutions within the Republic of Chile. The actor has published an exfiltration log (dump log) in JSON format, explicitly implying that the target is the Chilean Army, and has warned their audience that the data dumping process will remain active until all recent data has been extracted ("wait for us to finish extracting everything, including recent data").
🎯 Affected Entity: Likely the Chilean Army, or registration platforms linked to Chile's National Defense.
👤 Threat Actor: NemorisHacking
📂 Incident Type: Real-Time Structured Database Exfiltration (SQL Injection / API Scraping).
📊 FORENSIC ANALYSIS OF THE EXFILTRATION LOG (EXPOSED LOGS)
A detailed analysis of the JSON code sample—exfiltrated in real time—confirms the severity of the data leak, as it exposes military training records, identity information, and network telemetry pertaining to the affected individuals:
🪪 National Identity Information (PII):
Unique Identifiers: The logs explicitly show the extraction of Chile's *Rol Único Nacional* (National Unique Identifier), logically separating the base number from its verification digit (e.g., "RUN":"", "":"6"). Biographical Data: Full names and surnames correlated with each RUN (e.g., "FIRST_SURNAME":"", "SECOND_SURNAME":"").
🎖️ Military Records and Confirmed Training:
The data structure includes a key relational field ("COURSE") containing descriptions that validate the military nature of the target subject. One of the exfiltrated variables explicitly indicates: "COURSE":"" and "COURSE_TYPE":"INSTITUTIONAL", accompanied by an "EFFECTIVE_DATE". This suggests that the attacker is dumping historical records regarding military specialization, ranks, or the historical registry of cadets and permanent staff.
📡 Operational Telemetry (Device Fingerprints):
The data dump reveals that the compromised system stored precise user connection data (likely from an intranet portal or management platform), exposing IP addresses (, ), the browser used (), and the terminal's operating system ()—along with unique device identification hashes. Additionally, the attacker highlights record update timestamps within their console, noting that they have already successfully extracted information entered as recently as "2025-04-18".
🛡️ MITIGATIONS AND EMERGENCY TECHNICAL RECOMMENDATIONS
🛑 Immediate Connection Cutoff (Kill-Switch): The Joint Cyber Defense Command and the IT departments of the Chilean Ministry of Defense are urged to temporarily disconnect exposed web interfaces or APIs used for personnel lookup, institutional polytechnic intranet portals, and course evaluation systems—until the specific leakage point enabling this massive JSON-formatted data dump can be identified. ⚡ MONITORING AND EVALUATION
🌐 Intelligence System:
analyzer.vecert.io
🛡️ Quickly assess your website's security with:
monitor.vecert.io/
#CyberSecurity #Chile #ChileanArmy #TheMirrorOfYourShadow #DataExfiltration #MilitaryHack #RUN_Leak #NationalDefense #ActiveDumping #ThreatIntelligence #CyberAlert #VECERT #Infosec #StateSecurity