Cybersecurity in Latin America - Stories of Resilience & Innovation

Giovanni Forero

DEF CON 33 · Day 1 · Main Stage

Overview

Giovanni Forero's talk, "Cybersecurity in Latin America - Stories of Resilience & Innovation," delivers a compelling narrative about the unique cybersecurity landscape in Latin America. Far from being a region lagging in security, Forero illuminates a vibrant, community-driven ecosystem that thrives on ingenuity despite significant resource constraints. The presentation highlights how adversity has fostered a distinctive approach to cybersecurity, leading to both innovative defensive strategies and sophisticated offensive capabilities within the region.

Watch on YouTube

Visual summary for Cybersecurity in Latin America - Stories of Resilience & Innovation by Giovanni  Forero
Visual summary for Cybersecurity in Latin America - Stories of Resilience & Innovation by Giovanni Forero

Key moments

  1. 0:00 Speaker's personal journey into cybersecurity and Defcon
  2. 2:00 Igniting a community movement: founding Lava in LATAM
  3. 4:00 Unique challenges of the Latin American digital landscape
  4. 5:50 Innovation through open-source tools due to budget limits
  5. 7:00 Case study: $1M lost to a low-tech WhatsApp scam
  6. 8:50 Overview of Latin American developed malware (Machete, Grandato)
  7. 10:00 LATAM talent in offensive security and red teaming

Cybersecurity in Latin America - Stories of Resilience & Innovation

Speakers: Giovanni Forero

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=br2RPtCOzB0

Overview

Giovanni Forero's talk, "Cybersecurity in Latin America - Stories of Resilience & Innovation," delivers a compelling narrative about the unique cybersecurity landscape in Latin America. Far from being a region lagging in security, Forero illuminates a vibrant, community-driven ecosystem that thrives on ingenuity despite significant resource constraints. The presentation highlights how adversity has fostered a distinctive approach to cybersecurity, leading to both innovative defensive strategies and sophisticated offensive capabilities within the region.

Forero, a seasoned DEF CON attendee and a pivotal figure in fostering Latin American cybersecurity communities, shares his personal journey and the collective experiences that shape the region's digital defense. He emphasizes the critical role of grassroots collaboration, open-source adoption, and a pragmatic, street-wise approach to security challenges that often differ dramatically from those encountered in more resource-rich environments. The talk serves as a powerful call to action, urging the global cybersecurity community to recognize, support, and integrate the invaluable perspectives and talent emerging from Latin America.

This article delves into the core themes of Forero's presentation, exploring the contextual backdrop of Latin American cybersecurity, dissecting specific technical findings, and outlining the profound implications for both regional and global defenders. It underscores the message that true innovation in cybersecurity is not solely dependent on budget or advanced tooling, but often flourishes in environments where creativity is born from necessity, and community acts as the ultimate force multiplier.

Background

▶ Watch: Speaker's personal journey into cybersecurity and Defcon (0:00)

Giovanni Forero's journey into cybersecurity began much like many in the early days of the field, but with a unique challenge: he decoded his first book, "Hacking Exposed 1999," using a dictionary and Google Translate. This foundational experience, coupled with his first visit to DEF CON 16, exposed him to the vibrant knowledge-sharing culture of the community but also highlighted the significant language and cultural barriers for Spanish and Portuguese speakers. This personal experience became the catalyst for a broader mission: to ignite a movement for community-driven knowledge sharing within Latin America.

The urgent need for community became evident as Forero observed the stark differences in the availability of resources and infrastructure compared to regions like the United States. While a typical DEF CON attendee might have access to a plethora of switches and advanced technology for traffic capture and analysis, Latin American researchers often operate with limited resources, necessitating a deep understanding of the tools at hand and creative problem-solving. This led to his involvement in establishing the OWASP chapter in Bogota, Colombia, and subsequently co-founding LAVA (Latin American Vulnerability Assessment/Analysts), a thriving community and conference dedicated to Spanish and Portuguese-speaking cybersecurity professionals. LAVA's mission is to provide a comfortable and accessible platform for sharing knowledge, research, and innovation, addressing the fear or discomfort many feel when communicating in English.

The broader Latin American digital landscape presents a complex array of challenges. The region experiences explosive digital growth, but primarily as consumers of technology, often without a complete understanding of its underlying mechanisms or inherent risks. This rapid adoption is coupled with chronic underinvestment in cybersecurity infrastructure and talent development. Budgets for security are often minuscule, making expensive training programs like SANS "completely insane" for local professionals. Furthermore, a significant lack of specialized cybersecurity training in Spanish or Portuguese forces professionals to rely heavily on self-learning and open-source projects, mastering tools like Bash and Python to develop custom solutions.

Adding to this complexity is the prevalent political volatility across the region, which often translates into fast-moving and evolving threat landscapes. Despite these formidable obstacles, a resilient and innovative community of "underground creators, defenders, and disruptors" has emerged. These individuals think differently, craft real solutions tailored to their unique environment, and leverage the power of collaborative communities to fill the gaps left by underinvestment. The emphasis on community as the primary engine for learning, innovation, and problem-solving is a defining characteristic of the Latin American cybersecurity paradigm.

Key Findings

▶ Watch: Unique challenges of the Latin American digital landscape (4:00)

Forero's talk unveils several critical findings that collectively paint a comprehensive picture of Latin America's distinct cybersecurity posture, characterized by "creativity from adversity." These findings highlight both the unique nature of threats and the innovative responses from the region's security community.

A significant discovery is the prevalence and impact of low-tech, high-impact attacks. Forero provided a compelling example from Colombia: a webpage that, for 20 days, impersonated a social security payment portal. Crucially, this was not a traditional malware-laden site or a phishing page designed to steal credentials directly via a form. Instead, it was a seemingly innocuous page that, upon clicking a link, redirected victims to a WhatsApp line where personal information and payments were illicitly collected. This attack, which resulted in an estimated $1 million lost, bypassed conventional security tools like VirusTotal because "nothing's malicious in the webpage" from a technical standpoint. It leveraged social engineering and human trust, proving incredibly difficult to detect and take down, demonstrating that sophisticated technical defenses are often irrelevant against well-executed, non-technical schemes.

Conversely, the region is also a hotbed for the development of highly sophisticated Latin American-made malware. Forero cited examples such as Machete, a malware specifically targeting governments within the region, extensively documented in Kaspersky reports. Another significant threat is Blind Eagle, which has had a considerable impact across LATAM. Perhaps most notably, Brazil has produced advanced financial malicious software like Grandato and Kasbano. These banking Trojans, initially designed to target Brazilian financial institutions, have evolved into commercially available tools, sold and replicated across different countries, enabling widespread financial fraud. This demonstrates a capacity for advanced software development and a thriving cybercrime economy within the region.

The talk also showcased significant innovation on the offensive side of cybersecurity, often born from local expertise and resourcefulness. Examples include a successful deserialization attack against a Colombian bank, which escalated to compromise a core "bank court" system. This illustrates the ability of local red teams to execute complex attack chains. Hardware hacking is also flourishing, with tools like Doggy, a new hardware attack tool developed by the Argentinian community, and Catnifer from Electronic Cats, which specializes in radio frequency (RF) attacks. Furthermore, an Argentinian researcher was responsible for Partole, a notable crime attack against TLS that allowed the extraction of cookies from TLS connections by sending specific bits, highlighting advanced protocol-level research. Even seemingly mundane objects are not immune, as demonstrated by the "hacking robots" incident where a child-protection robot with a camera was reprogrammed into a "little killer robot," showcasing expertise in embedded systems.

Forero emphasized that these innovations, whether defensive or offensive, often stem from a philosophy of "zero blame" rather than the pursuit of "zero days." This pragmatic approach focuses on effective, often simpler, solutions that address real-world problems. The region also operates with a high degree of digital informality, where threat intelligence is often shared through informal networks – "the gossip that you can share with your friend" – but this collaborative knowledge exchange still proves effective in strengthening controls and defenses. Ultimately, the core finding is that Latin America is actively "hacking the game," leveraging its unique circumstances to innovate, build robust defenses through collaborative knowledge sharing, and refusing to wait for an invitation to the global cybersecurity table, choosing instead to "bring our own table."

Technical Deep Dive

▶ Watch: Innovation through open-source tools due to budget limits (5:50)

The technical landscape of cybersecurity in Latin America, as presented by Giovanni Forero, is characterized by a blend of highly sophisticated, locally developed threats and remarkably effective, low-tech social engineering campaigns. This duality necessitates a versatile defensive posture that goes beyond conventional technical controls.

One of the most striking technical insights from the talk was the detailed account of the low-tech attack targeting social security payments in Colombia. This was not a traditional phishing attempt or a malware delivery. Instead, the attackers created a legitimate-looking webpage, hosted on a Canadian service, that mimicked the official social security payment portal. The critical technical detail is that the page itself contained no malicious code that antivirus software or URL scanners like VirusTotal would flag. Its malicious intent was realized through a social engineering vector: when a victim clicked the "payment" link, they were redirected not to a fraudulent payment gateway, but to a WhatsApp chat line. Here, the human element of the attack took over, with operators guiding victims to divulge sensitive information and make payments directly, resulting in an estimated $1 million in losses over a period of 20 days. This attack highlights a significant gap in automated threat detection, as the "malicious" activity occurs entirely outside the traditional technical analysis of the webpage content.

On the more technically advanced front, Latin America has birthed a range of potent malware. Machete, for instance, is a well-documented APT (Advanced Persistent Threat) group with malware specifically designed to target government entities in the region, focusing on espionage and data exfiltration. While the transcript doesn't detail its specific modules, Kaspersky reports have historically described its use of custom backdoors, keyloggers, and screenshot capabilities. Similarly, Blind Eagle represents another impactful threat actor, demonstrating the region's capacity for developing persistent and evasive malware. The Brazilian financial sector has been particularly affected by sophisticated banking Trojans like Grandato and Kasbano. These are not simple keyloggers but often involve complex techniques such as injecting malicious overlays into legitimate banking applications, intercepting two-factor authentication (2FA) codes, and automating fraudulent transactions. The fact that these tools are now "replicated now in different countries" and "sold as some kind of software to steal money" underscores their advanced design and effectiveness, transforming them into a significant component of the global cybercrime economy.

Beyond defensive challenges, Latin American offensive security researchers and red teams are demonstrating high-level technical prowess. The mention of a deserialization attack against a Colombian bank leading to a compromise of a "bank court" is particularly revealing. Deserialization vulnerabilities, often found in applications that process serialized data (e.g., Java, .NET, Python applications), can allow an attacker to inject arbitrary code, leading to Remote Code Execution (RCE). Gaining access to a "bank court" (likely referring to core banking systems or a critical internal application) through such an attack indicates a deep understanding of application security and complex exploitation chains.

Hardware security research is also thriving. Doggy, developed by the Argentinian community, is cited as a new hardware attack tool. While specific functionalities are not detailed, such tools typically target embedded systems, IoT devices, or physical access controls, often leveraging vulnerabilities in firmware, JTAG interfaces, or side-channel attacks. Another notable tool is Catnifer from Electronic Cats, which specializes in radio frequency (RF) attacks. This implies research and tools capable of exploiting vulnerabilities in wireless communication protocols (e.g., Wi-Fi, Bluetooth, LoRa, cellular networks) or even custom RF systems, potentially enabling eavesdropping, jamming, or unauthorized control.

The Partole attack, another contribution from an Argentinian researcher, demonstrated a sophisticated understanding of TLS (Transport Layer Security). The ability to "send some kind of bits and got a cookie from a TLS connection" suggests a protocol-level attack, potentially a side-channel attack or a specific protocol flaw that allows for information leakage from encrypted sessions. This level of research indicates expertise in cryptography and network protocol analysis. Finally, the "hacking robots" incident, where a child-protection robot with a camera was reprogrammed into a "little killer robot," showcases practical skills in embedded system security, firmware modification, and the repurposing of consumer devices for unintended, malicious functions.

Forero also noted the emerging role of artificial intelligence (AI) in fueling basic social engineering attacks. AI can enhance impersonation capabilities, making phishing emails or voice calls more convincing and scalable, thereby increasing the effectiveness of already prevalent social engineering tactics. These diverse technical contributions, from low-tech human exploitation to advanced malware, hardware tools, and protocol-level attacks, demonstrate a dynamic and technically capable cybersecurity ecosystem in Latin America, often operating with a philosophy of "zero blame" rather than solely pursuing "zero days," focusing on practical and impactful solutions.

Demo / Proof of Concept

▶ Watch: Overview of Latin American developed malware (Machete, Grandato) (8:50)

While Giovanni Forero's talk did not feature a live technical demonstration or a real-time proof of concept, the presentation itself served as a powerful conceptual demonstration of the diverse capabilities and challenges within the Latin American cybersecurity landscape. Forero extensively detailed various attacks, tools, and research projects originating from the region, effectively showcasing the practical implementations and innovative solutions being developed. The descriptions of tools like Doggy (a hardware attack tool), Catnifer (for radio frequency attacks), and the Partole TLS attack, along with the narrative of the reprogrammed "killer robot," provided vivid examples of the technical prowess and ingenuity present in the community. These examples, though presented through narrative, function as compelling proofs of concept for the types of cybersecurity work being done.

Defensive Implications

▶ Watch: LATAM talent in offensive security and red teaming (10:00)

The insights shared by Giovanni Forero carry profound defensive implications for organizations and individuals, not just within Latin America but globally. The unique challenges and innovations highlighted necessitate a re-evaluation of traditional cybersecurity strategies, emphasizing adaptability, community intelligence, and a holistic approach.

Firstly, the prevalence of low-tech, high-impact attacks, such as the Colombian social security scam, underscores the critical need to look beyond purely technical defenses. Traditional security tools like antivirus software, firewalls, and URL scanners are often ineffective against social engineering attacks where the "malicious" activity occurs through human interaction (e.g., via WhatsApp) rather than through executable code or direct exploitation. Defenders must invest significantly in security awareness training that goes beyond recognizing phishing emails, focusing on identifying social engineering tactics, verifying identities, and understanding the risks associated with informal communication channels. Incident response plans must also account for these non-technical attacks, detailing procedures for taking down impersonating websites, engaging with communication platforms, and managing public relations fallout.

Secondly, the talk highlights the immense value of community-driven threat intelligence. In regions with chronic underinvestment and a lack of formal threat intelligence sharing platforms, informal networks ("the gossip that you can share with your friend") become vital. Defenders should actively foster internal and external communities for sharing threat indicators, attack methodologies, and defensive strategies. Participating in and supporting organizations like LAVA can provide access to localized, real-time intelligence that might not be available through commercial feeds. This collaborative knowledge exchange is crucial for understanding rapidly evolving local threats, such as new variants of Grandato or Kasbano banking malware.

Thirdly, the reliance on open-source projects and tools like Bash and Python due to budget constraints offers a powerful lesson. Defenders globally should embrace and contribute to open-source security solutions. This not only reduces costs but also fosters transparency, community collaboration, and the ability to customize tools to specific needs. Developing in-house scripting and automation capabilities with these languages can empower teams to build bespoke defenses and incident response tools tailored to their unique threat landscape.

Fourthly, the emergence of sophisticated, locally developed malware (e.g., Machete, Blind Eagle, Grandato, Kasbano) means that organizations must maintain robust endpoint detection and response (EDR) capabilities, advanced threat hunting, and malware analysis expertise. Generic signatures may not suffice for rapidly evolving or custom-made threats. Furthermore, the global proliferation of these tools (like the sale of Brazilian banking malware) means organizations worldwide could be targets, necessitating vigilance against region-specific TTPs.

Finally, the advanced offensive research showcased (deserialization attacks, hardware hacking with Doggy, RF attacks with Catnifer, TLS attacks with Partole, and embedded system hacking of robots) indicates that defenders must adopt a holistic security posture. This includes:

  • Application security testing for deserialization vulnerabilities.
  • Physical security and supply chain security for hardware components.
  • RF spectrum monitoring and wireless network security to counter sophisticated radio attacks.
  • Rigorous TLS configuration and patching, along with an understanding of protocol-level vulnerabilities.
  • Embedded system security audits for IoT devices and operational technology (OT).

The overarching defensive implication is that security is not a one-size-fits-all solution. Adapting to local contexts, fostering collaborative intelligence, investing in talent (even if informal), and embracing pragmatic, often open-source, approaches are essential for building resilient defenses against a diverse and rapidly evolving threat landscape. Organizations must realize that "we are not waiting to be invited to the table, we are bringing our own table" – a proactive, community-driven approach is paramount.

Key Takeaways

  • Community is Paramount: In resource-constrained environments, grassroots communities like LAVA are the primary drivers for knowledge sharing, talent development, and collective defense, enabling innovation from adversity.
  • Innovation from Adversity: Latin America demonstrates how limitations in budget and formal infrastructure can foster unique creativity, leading to effective, often low-tech, solutions and sophisticated offensive tools.
  • Diverse Threat Landscape: The region faces a dual threat: highly effective low-tech social engineering attacks that bypass traditional security tools, alongside advanced, locally developed malware and sophisticated offensive research.
  • Beyond Technical Controls: Defenders must expand their focus beyond purely technical solutions to include robust security awareness, human-centric defenses, and informal threat intelligence sharing to counter prevalent social engineering tactics.
  • Global Collaboration is Essential: The unique perspectives and experiences of Latin American cybersecurity professionals are invaluable for strengthening global defenses, necessitating greater support, sponsorship, and integration into international discussions.
  • "Hacking the Game": Latin America is actively "rewriting the odds" in cybersecurity, proving that resilience, ingenuity, and collaborative spirit can overcome significant challenges to build robust security capabilities.

About the Speaker(s)

Giovanni Forero is a seasoned cybersecurity professional and a passionate community builder with a long history in the field, dating back to his first DEF CON attendance at DEF CON 16. His journey began with self-taught expertise, famously decoding "Hacking Exposed 1999" using a dictionary and Google Translate, highlighting his dedication to learning and problem-solving despite initial language barriers.

Driven by a recognition of the need for accessible cybersecurity knowledge for Spanish and Portuguese speakers, Giovanni became instrumental in fostering community development. He played a key role in establishing the OWASP chapter in Bogota, Colombia, and is a co-founder of LAVA (Latin American Vulnerability Assessment/Analysts), a vibrant community and conference dedicated to promoting cybersecurity talent and knowledge sharing across Latin America. Giovanni is a strong advocate for engaging Latin American cybersecurity talent, discovering unique regional perspectives, and integrating these voices into global cybersecurity discussions. His work exemplifies the power of community and innovation in overcoming significant challenges within the cybersecurity landscape.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A genuine community-building talk with real regional context and some interesting threat examples, but it stays at survey altitude the entire time. Forero clearly knows the space and has lived experience worth hearing, but the talk doesn't go deep enough on any single finding to give a technical audience something they can take home and act on.

Heather Calloway (CISO) — WEAK

Forero is a credible voice with a real story to tell, and the community-building work behind LAVA is genuinely valuable. But the talk is a portrait, not a brief — it surfaces interesting signals without converting them into anything a defender, security leader, or policymaker can act on.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33