๐ค CYBER INTELLIGENCE: PROFILING OF THE INFRASTRUCTURE THREAT ACTOR โ URUGUAY ๐บ๐พ
๐ฅ CRITICAL THREAT: DETAILED PROFILE AND TIMELINE OF LAPAMPALEAKS ATTACKS
The CTI unit has consolidated the technical and operational profile of the threat actor LaPampaLeaks, an active group since April 2020 specializing in data leaks, doxing, and defacement. Analysis of its infrastructure reveals a highly organized ecosystem that uses decentralized networks and Tor exit nodes to evade attribution, primarily targeting government, healthcare, education, and telecommunications sectors in Uruguay.
๐ข Affected Entities: Critical infrastructure of the Uruguayan State, corporate, education, and healthcare sectors.
๐ค Threat Actor: LaPampaLeaks / PampaLeaks
โ๏ธ Main Tactics and Vectors: Exploitation of public-facing applications, Web Shells, API scraping (abuse of unrestricted requests), and traffic redirection through subdomain takeover.
๐ Status: Correlated historical activity from 2020 to the recent massive compromise of the DNIC (5.8M citizens) in May 2026.
โ ๏ธ TECHNICAL CAPABILITIES AND TTPs ANALYSIS (MITRE ATT&CK)
The LaPampaLeaks operational ecosystem demonstrates advanced persistence and impact capabilities:
๐ก๏ธ Defense Evasion and Persistence: Mandatory use of Tor routing and persistence based on backdoors and hidden Tor services. Additionally, they perform log clearing and session manipulation to escalate privileges.
๐ก Command and Control (C2) Infrastructure: Redundant and heavily encrypted communication channels operated through Telegram and Tox, protecting their real identities by using the anonymous email service u**********@mail2tor.com.
๐ INDICATORS OF COMPROMISE (IoCs) & ASSOCIATED INFRASTRUCTURE
The map of domains and hosts used for distributing manifests and hosting the compromised databases has been identified:
๐ Key Domains and Infrastructure:
lapampaleaks(.)info (Seen since 2025-04-26)
lapampaleaks(.)lol (Seen since 2025-04-24)
lapampaleaks(.)pw (Seen since 2025-04-21)
*.lapampaleaks.pages(.)dev / *.lapampaleaks.workers(.)dev (Use of Cloudflare Workers/Pages)
๐ Compromised/Taken Subdomain:
lapampaleaks.fiscalia.gub(.)uy (Registered in 2024-12-23)
๐
HISTORICAL TIMELINE AND PUBLICATIONS
The history of posts on underground forums reveals the chronological evolution of their attacks:
๐ก๏ธ 2020-04-25 [First Appearance]: Official presentation of the actor on darkforums, releasing their first batch of databases and confidential documents (presentation: lapampaleaks [Databases] [Documents] [Leaks]).
๐๏ธ 2024-12-19: Publication and leak of the complete database and source code of the Las Piedras Shopping mall (uruguay: Las Piedras Shopping [Database] [Source Code]).
๐ฅ March 9, 2025: Exfiltration and release of COVID-19-related medical databases belonging to the State Health Services Administration (ASSE) (Uruguay:
asse.com.uy [Database] [COVID-19]).
โ๏ธ March 17, 2025: Visual alteration attack and leak of confidential documents from the National Directorate of Civil Aviation and Aeronautical Infrastructure (Uruguay:
dinacia.gub.uy [defaced] [confidential documents]).
โก March 30, 2025: Defacement attack and data leak on the energy efficiency portal (Uruguay:
eficienciaenergetica.gub.uy [defaced] [Data Leak]).
โ๏ธ March 31, 2025: Defacement attack targeting the justice system of the Uruguayan Attorney General's Office (Uruguay:
fiscalia.gub.uy [defaced] [justice system]).
๐ September 24, 2025 / April 3, 2026: Massive data leak of members of ORT Uruguay University, finally released for free (ORT University [Database] [Members] [FREE] [Uruguay]).
๐ป September 30, 2025 / April 7, 2026: Consecutive attacks and leaks of citizen databases and device history of the Ceibal Plan (Uruguay: Plan Ceibal [Database] [Device history] [33k Sample] [Free]).
๐ April 3, 2026: Consolidated data breach involving multiple government entities, including cross-referenced data from the DNIC, ANEP, CEIBAL, SUCIVE fines, and IMV (Uruguay: Data breaches and services [DNIC] [ANEP] [CEIBAL] [SUCIVE fines] [IMV]).
๐ฑ May 7, 2026: Leak of an 8GB batch of government data through the Antel TuID Digital mobile identity platform (Antel TuID Digital [8GB] [Data Leak] [Government]).
๐ฅ May 18, 2026: Deployment of an active doxing service using government data of Uruguayan citizens (Uruguay: doxing service [Government data] [Citizens]).
๐จ 2026-05-20 [Recent Incident]: Publication of the massive exploit against the DNIC, compromising the civil registry of 5.8 million Uruguayan citizens (Uruguay: DNIC [5.8M] Citizens).
๐ Historical tracing and infrastructure mapping confirm that LaPampaLeaks is not an opportunistic, entry-level attacker, but rather a persistent and highly focused threat actor with a sustained campaign spanning over six years, aimed at eroding Uruguayโs identity, healthcare, and justice systems. The use of combined techniquesโranging from classic web shell injection to advanced state subdomain hijacking and API abuseโdemonstrates a meticulous reconnaissance methodology. Their latest action against the DNIC (compromising 5.8 million citizens) solidifies a critical and enduring risk of identity theft at the national level. Mitigation can no longer be reactive; it demands a fundamental redesign of trust in state portals and rigorous monitoring of exposed assets within government infrastructure.
#CyberSecurity #Uruguay #LaPampaLeaks #ThreatIntelligence #DNIC #DataLeak #Doxing #Defacement #TorNetwork #SubdomainTakeover #VECERT #Infosec #CyberAlert