{"id":4327,"date":"2026-06-01T09:00:48","date_gmt":"2026-06-01T14:00:48","guid":{"rendered":"https:\/\/www.itechsas.com\/blog\/?p=4327"},"modified":"2026-06-01T09:01:03","modified_gmt":"2026-06-01T14:01:03","slug":"everest-ataca-de-nuevo-epm-y-otras-empresas-comprometidas","status":"publish","type":"post","link":"https:\/\/www.itechsas.com\/blog\/ciberseguridad\/everest-ataca-de-nuevo-epm-y-otras-empresas-comprometidas\/","title":{"rendered":"Everest ataca de nuevo: EPM y otras empresas comprometidas"},"content":{"rendered":"\n<p>El grupo de ransomware <strong>Everest <\/strong>public\u00f3 en su portal de la dark web un aviso de extorsi\u00f3n contra <strong>SOLATI S.A.S.<\/strong>, empresa contratista de <strong>EPM <\/strong>y la <strong>Central Hidroel\u00e9ctrica de Caldas<\/strong> (CHEC). El ataque expuso informes especializados de cartera de ambas entidades y reaviva la alarma sobre la seguridad de la cadena de suministro tecnol\u00f3gico en Colombia.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Lo que se sabe del ataque<\/h2>\n\n\n\n<p>El viernes 29 de mayo amaneci\u00f3 con una notificaci\u00f3n en el portal Tor del grupo <strong>Everest<\/strong>: dos nuevas v\u00edctimas colombianas a\u00f1adidas a su lista de extorsi\u00f3n. Una de ellas identificada como \u00ab<strong>\u0415\u0420\u041c<\/strong>\u00bb \u2014usando caracteres cir\u00edlicos para eludir filtros\u2014 y la otra <strong>Asopagos S.A.<\/strong>, operador de pagos de seguridad social con cobertura nacional.<\/p>\n\n\n\n<p>Horas despu\u00e9s, EPM emiti\u00f3 un comunicado oficial que aclara la naturaleza real del incidente: el ataque no comprometi\u00f3 los sistemas propios de la empresa. La v\u00edctima directa fue <strong>SOLATI S.A.S.<\/strong>, una empresa contratista encargada de procesos de gesti\u00f3n de cartera, cuyos sistemas fueron penetrados por lo que el mismo contratista describi\u00f3 como \u00abuna organizaci\u00f3n criminal de alcance internacional\u00bb.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-4.png\"><img data-opt-id=806050519  fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"552\" src=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1024\/h:552\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-4.png\" alt=\"\" class=\"wp-image-4328\" srcset=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1024\/h:552\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-4.png 1024w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:300\/h:162\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-4.png 300w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:768\/h:414\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-4.png 768w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:830\/h:447\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-4.png 830w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1267\/h:683\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-4.png 1267w\" sizes=\"(max-width: 650px) 100vw, 650px\" \/><\/a><figcaption class=\"wp-element-caption\"><a href=\"https:\/\/www.epm.com.co\/institucional\/sala-de-prensa\/noticias-y-novedades\/incidente-ciberseguridad-contratista-solati-cartera-epm\/\">EPM informa incidente de ciberseguridad en contratista<\/a><\/figcaption><\/figure>\n\n\n\n<p>Por su parte la empresa <strong>SOLATI S.A.S<\/strong>., empresa colombiana de tecnolog\u00eda especializada en software de gesti\u00f3n de cobranzas, automatizaci\u00f3n de cartera y<br>CRM para procesos de recaudo con inteligencia artificial, p\u00fablico un aviso en su p\u00e1gina web confirmando el incidente de ciberseguridad, el cual se debi\u00f3 por el <strong>acceso no autorizado que aprovecharon los atacantes para exfiltrar informaci\u00f3n<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-5.png\"><img data-opt-id=350181461  fetchpriority=\"high\" decoding=\"async\" width=\"917\" height=\"578\" src=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-5.png\" alt=\"\" class=\"wp-image-4330\" srcset=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:917\/h:578\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-5.png 917w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:300\/h:189\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-5.png 300w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:768\/h:484\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-5.png 768w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:830\/h:523\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-5.png 830w\" sizes=\"(max-width: 650px) 100vw, 650px\" \/><\/a><figcaption class=\"wp-element-caption\"><a href=\"https:\/\/www.solati.co\/comunicado-opinion-publica\/\">Comunicado opini\u00f3n P\u00fablica &#8211; Software para la Gesti\u00f3n de Cobranza<\/a><\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">El vector: la cadena de suministro<\/h2>\n\n\n\n<p>El incidente ilustra con precisi\u00f3n una t\u00e1ctica que los grupos de ransomware han perfeccionado en los \u00faltimos a\u00f1os: <strong>en lugar de atacar frontalmente a organizaciones reconocidas y protegidas, los atacantes identifican a sus proveedores y contratistas, que suelen tener menores niveles de defensa digital, pero acceso a informaci\u00f3n sensible de sus clientes<\/strong>.<\/p>\n\n\n\n<p>Un ataque a la cadena de suministro (<strong>Supply Chain Attack<\/strong>) es una t\u00e9cnica en la que los atacantes comprometen a un <strong>proveedor, contratista, desarrollador de software o tercero de confianza<\/strong> para llegar indirectamente a la organizaci\u00f3n objetivo.<\/p>\n\n\n\n<p>En este caso, el blanco no fue EPM directamente \u2014 que invirti\u00f3 significativamente en ciberseguridad tras el devastador ataque de diciembre de 2022 cuando el grupo <strong>BlackCat Ransomware<\/strong> comprometi\u00f3 los sistemas digitales de la empresa y dej\u00f3 sin funcionamiento m\u00faltiples servicios tecnol\u00f3gicos durante semanas que oblig\u00f3 a la compa\u00f1\u00eda a operar bajo contingencia y fue considerado uno de los ataques inform\u00e1ticos m\u00e1s severos registrados contra una empresa p\u00fablica en Colombia, \u2014 sino SOLATI, que operaba el CRM de cobranzas. El objetivo espec\u00edfico del ataque fue <strong>el servicio complementario de informes especializados asociados a ese CRM<\/strong>, lo que expuso datos de cartera de dos clientes: EPM y la <strong>Central Hidroel\u00e9ctrica de Caldas (CHEC)<\/strong>.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u00abLos contratistas y proveedores tecnol\u00f3gicos se han convertido en uno de los puntos m\u00e1s vulnerables para las grandes organizaciones. Los atacantes suelen buscar acceso indirecto a informaci\u00f3n sensible a trav\u00e9s de empresas aliadas con menores niveles de protecci\u00f3n digital.\u00bb \u2014 Expertos en ciberseguridad consultados por El Colombiano.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Cronolog\u00eda de los incidentes<\/h2>\n\n\n\n<p><strong>Diciembre 2022<\/strong>: EPM sufre el ataque de <strong>BlackCat\/ALPHV<\/strong>, uno de los m\u00e1s graves registrados en Colombia. Sistemas cifrados, miles de empleados en casa. La Fiscal\u00eda abre investigaci\u00f3n.<\/p>\n\n\n\n<p><strong>2022\u20132026<\/strong>: EPM refuerza su infraestructura de seguridad internamente. Colombia registra un aumento sostenido de intentos de ciberataque, superando los <strong>7.100 millones de intentos<\/strong> solo en el primer semestre de 2025.<\/p>\n\n\n\n<p><strong>29 mayo 2026<\/strong>: <strong>Everest publica<\/strong> en su blog de la dark web los nombres de \u00ab\u0415\u0420\u041c\u00bb y Asopagos S.A. como v\u00edctimas de extorsi\u00f3n. <\/p>\n\n\n\n<p><strong>29 mayo 2026<\/strong>: EPM emite comunicado oficial en la tarde aclarando que la v\u00edctima directa es <strong>SOLATI S.A.S.<\/strong> Se confirma que CHEC tambi\u00e9n est\u00e1 afectada. EPM reporta operaci\u00f3n normal en todos sus sistemas.<\/p>\n\n\n\n<p><strong>Entidades involucradas<\/strong>:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>EPM: Empresa p\u00fablica \u00b7 Medell\u00edn \u00b7 Energ\u00eda, gas, agua<\/li>\n\n\n\n<li>SOLATI S.A.S.: Contratista \u00b7 Gesti\u00f3n de cartera y CRM<\/li>\n\n\n\n<li>CHEC: Central Hidroel\u00e9ctrica de Caldas \u00b7 Afectada indirecta<\/li>\n\n\n\n<li>Asopagos S.A.: Fintech \u00b7 Operador PILA \u00b7 Bogot\u00e1<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Dark web y exposici\u00f3n a los ladrones de informaci\u00f3n<\/h2>\n\n\n\n<p>Realizando una revisi\u00f3n r\u00e1pida con herramientas de monitoreo de ataques de ransomware e inteligencia de amenazas en internet y la dark web, se encuentra la siguiente informaci\u00f3n:<\/p>\n\n\n\n<p><strong>epm.com.co<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-8.png\"><img data-opt-id=486678685  data-opt-src=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1024\/h:314\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-8.png\"  decoding=\"async\" width=\"1024\" height=\"314\" src=\"data:image/svg+xml,%3Csvg%20viewBox%3D%220%200%201024%20314%22%20width%3D%221024%22%20height%3D%22314%22%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Crect%20width%3D%221024%22%20height%3D%22314%22%20fill%3D%22transparent%22%2F%3E%3C%2Fsvg%3E\" alt=\"\" class=\"wp-image-4333\" old-srcset=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1024\/h:314\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-8.png 1024w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:300\/h:92\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-8.png 300w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:768\/h:235\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-8.png 768w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:830\/h:254\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-8.png 830w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1334\/h:409\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-8.png 1334w\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-9.png\"><img data-opt-id=1701147742  data-opt-src=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1024\/h:640\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-9.png\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"640\" src=\"data:image/svg+xml,%3Csvg%20viewBox%3D%220%200%201024%20640%22%20width%3D%221024%22%20height%3D%22640%22%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Crect%20width%3D%221024%22%20height%3D%22640%22%20fill%3D%22transparent%22%2F%3E%3C%2Fsvg%3E\" alt=\"\" class=\"wp-image-4334\" old-srcset=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1024\/h:640\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-9.png 1024w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:300\/h:188\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-9.png 300w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:768\/h:480\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-9.png 768w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:830\/h:519\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-9.png 830w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1166\/h:729\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-9.png 1166w\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-10.png\"><img data-opt-id=1636138425  data-opt-src=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-10.png\"  loading=\"lazy\" decoding=\"async\" width=\"869\" height=\"861\" src=\"data:image/svg+xml,%3Csvg%20viewBox%3D%220%200%20100%%20100%%22%20width%3D%22100%%22%20height%3D%22100%%22%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Crect%20width%3D%22100%%22%20height%3D%22100%%22%20fill%3D%22transparent%22%2F%3E%3C%2Fsvg%3E\" alt=\"\" class=\"wp-image-4335\" old-srcset=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:869\/h:861\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-10.png 869w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:300\/h:297\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-10.png 300w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:150\/h:150\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-10.png 150w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:768\/h:761\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-10.png 768w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:830\/h:822\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-10.png 830w\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-7.png\"><img data-opt-id=918802304  data-opt-src=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-7.png\"  loading=\"lazy\" decoding=\"async\" width=\"966\" height=\"772\" src=\"data:image/svg+xml,%3Csvg%20viewBox%3D%220%200%20100%%20100%%22%20width%3D%22100%%22%20height%3D%22100%%22%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Crect%20width%3D%22100%%22%20height%3D%22100%%22%20fill%3D%22transparent%22%2F%3E%3C%2Fsvg%3E\" alt=\"\" class=\"wp-image-4332\" old-srcset=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:966\/h:772\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-7.png 966w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:300\/h:240\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-7.png 300w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:768\/h:614\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-7.png 768w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:830\/h:663\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-7.png 830w\" \/><\/a><\/figure>\n\n\n\n<p><strong>asopagos.com<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-11.png\"><img data-opt-id=1096050859  data-opt-src=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1024\/h:229\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-11.png\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"229\" src=\"data:image/svg+xml,%3Csvg%20viewBox%3D%220%200%201024%20229%22%20width%3D%221024%22%20height%3D%22229%22%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Crect%20width%3D%221024%22%20height%3D%22229%22%20fill%3D%22transparent%22%2F%3E%3C%2Fsvg%3E\" alt=\"\" class=\"wp-image-4336\" old-srcset=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1024\/h:229\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-11.png 1024w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:300\/h:67\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-11.png 300w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:768\/h:171\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-11.png 768w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:830\/h:185\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-11.png 830w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1183\/h:264\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-11.png 1183w\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-12.png\"><img data-opt-id=1134930017  data-opt-src=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1024\/h:653\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-12.png\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"653\" src=\"data:image/svg+xml,%3Csvg%20viewBox%3D%220%200%201024%20653%22%20width%3D%221024%22%20height%3D%22653%22%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Crect%20width%3D%221024%22%20height%3D%22653%22%20fill%3D%22transparent%22%2F%3E%3C%2Fsvg%3E\" alt=\"\" class=\"wp-image-4337\" old-srcset=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1024\/h:653\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-12.png 1024w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:300\/h:191\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-12.png 300w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:768\/h:490\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-12.png 768w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:830\/h:530\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-12.png 830w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1166\/h:744\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-12.png 1166w\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-13.png\"><img data-opt-id=999890120  data-opt-src=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1024\/h:514\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-13.png\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"514\" src=\"data:image/svg+xml,%3Csvg%20viewBox%3D%220%200%201024%20514%22%20width%3D%221024%22%20height%3D%22514%22%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Crect%20width%3D%221024%22%20height%3D%22514%22%20fill%3D%22transparent%22%2F%3E%3C%2Fsvg%3E\" alt=\"\" class=\"wp-image-4338\" old-srcset=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1024\/h:514\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-13.png 1024w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:300\/h:151\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-13.png 300w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:768\/h:385\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-13.png 768w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:830\/h:416\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-13.png 830w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1156\/h:580\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-13.png 1156w\" \/><\/a><\/figure>\n\n\n\n<p><strong>solati.co<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-14.png\"><img data-opt-id=60699872  data-opt-src=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1024\/h:229\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-14.png\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"229\" src=\"data:image/svg+xml,%3Csvg%20viewBox%3D%220%200%201024%20229%22%20width%3D%221024%22%20height%3D%22229%22%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Crect%20width%3D%221024%22%20height%3D%22229%22%20fill%3D%22transparent%22%2F%3E%3C%2Fsvg%3E\" alt=\"\" class=\"wp-image-4339\" old-srcset=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1024\/h:229\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-14.png 1024w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:300\/h:67\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-14.png 300w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:768\/h:172\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-14.png 768w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:830\/h:186\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-14.png 830w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1170\/h:262\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-14.png 1170w\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-15.png\"><img data-opt-id=690314667  data-opt-src=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1024\/h:503\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-15.png\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"503\" src=\"data:image/svg+xml,%3Csvg%20viewBox%3D%220%200%201024%20503%22%20width%3D%221024%22%20height%3D%22503%22%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Crect%20width%3D%221024%22%20height%3D%22503%22%20fill%3D%22transparent%22%2F%3E%3C%2Fsvg%3E\" alt=\"\" class=\"wp-image-4340\" old-srcset=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1024\/h:503\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-15.png 1024w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:300\/h:147\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-15.png 300w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:768\/h:377\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-15.png 768w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:830\/h:407\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-15.png 830w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1157\/h:568\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-15.png 1157w\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-16.png\"><img data-opt-id=1563045731  data-opt-src=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-16.png\"  loading=\"lazy\" decoding=\"async\" width=\"985\" height=\"735\" src=\"data:image/svg+xml,%3Csvg%20viewBox%3D%220%200%20100%%20100%%22%20width%3D%22100%%22%20height%3D%22100%%22%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Crect%20width%3D%22100%%22%20height%3D%22100%%22%20fill%3D%22transparent%22%2F%3E%3C%2Fsvg%3E\" alt=\"\" class=\"wp-image-4341\" old-srcset=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:985\/h:735\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-16.png 985w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:300\/h:224\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-16.png 300w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:768\/h:573\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-16.png 768w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:830\/h:619\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-16.png 830w\" \/><\/a><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Estad\u00edsticas de v\u00edctimas de ataques por grupos y sectores a mayo de 2026<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-19.png\"><img data-opt-id=1630434068  data-opt-src=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1024\/h:659\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-19.png\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"659\" src=\"data:image/svg+xml,%3Csvg%20viewBox%3D%220%200%201024%20659%22%20width%3D%221024%22%20height%3D%22659%22%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Crect%20width%3D%221024%22%20height%3D%22659%22%20fill%3D%22transparent%22%2F%3E%3C%2Fsvg%3E\" alt=\"\" class=\"wp-image-4347\" old-srcset=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1024\/h:659\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-19.png 1024w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:300\/h:193\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-19.png 300w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:768\/h:494\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-19.png 768w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:830\/h:534\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-19.png 830w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1319\/h:849\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-19.png 1319w\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-18.png\"><img data-opt-id=872932973  data-opt-src=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1024\/h:408\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-18.png\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"408\" src=\"data:image/svg+xml,%3Csvg%20viewBox%3D%220%200%201024%20408%22%20width%3D%221024%22%20height%3D%22408%22%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Crect%20width%3D%221024%22%20height%3D%22408%22%20fill%3D%22transparent%22%2F%3E%3C%2Fsvg%3E\" alt=\"\" class=\"wp-image-4346\" old-srcset=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1024\/h:408\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-18.png 1024w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:300\/h:119\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-18.png 300w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:768\/h:306\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-18.png 768w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:830\/h:331\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-18.png 830w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1308\/h:521\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-18.png 1308w\" \/><\/a><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">\u00bfQui\u00e9n es Everest?<\/h2>\n\n\n\n<p>Everest es un grupo criminal que opera desde al menos diciembre de 2020, con se\u00f1ales que apuntan a miembros de habla rusa o con base en pa\u00edses de la antigua Uni\u00f3n Sovi\u00e9tica. Con m\u00e1s de <strong>365 v\u00edctimas documentadas<\/strong> en 34 pa\u00edses, el grupo tuvo un incremento de actividad del <strong>25%<\/strong> respecto al mes anterior seg\u00fan los rastreadores especializados.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-6.png\"><img data-opt-id=1231223273  data-opt-src=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1024\/h:363\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-6.png\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"363\" src=\"data:image/svg+xml,%3Csvg%20viewBox%3D%220%200%201024%20363%22%20width%3D%221024%22%20height%3D%22363%22%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Crect%20width%3D%221024%22%20height%3D%22363%22%20fill%3D%22transparent%22%2F%3E%3C%2Fsvg%3E\" alt=\"\" class=\"wp-image-4331\" old-srcset=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1024\/h:363\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-6.png 1024w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:300\/h:106\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-6.png 300w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:768\/h:272\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-6.png 768w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:830\/h:294\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-6.png 830w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1236\/h:438\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-6.png 1236w\" \/><\/a><\/figure>\n\n\n\n<p>Su modelo de negocio combina <strong>doble extorsi\u00f3n<\/strong> \u2014cifrar datos y amenazar con publicarlos\u2014 con la venta de accesos iniciales a otras bandas criminales. Sus sectores preferidos son <strong>salud, servicios empresariales, tecnolog\u00eda y manufactura<\/strong>. Estados Unidos concentra el 29% de sus v\u00edctimas, pero Am\u00e9rica Latina ha comenzado a aparecer con mayor frecuencia en su historial.<\/p>\n\n\n\n<p><strong>Contexto global reciente<\/strong> En los \u00faltimos meses, Everest ha extorsionado a:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Iberia Airlines (596 GB de datos, 6 millones de d\u00f3lares exigidos)<\/li>\n\n\n\n<li>Liberty Mutual en EE.UU. (108 GB, m\u00e1s de 15.000 afectados)<\/li>\n\n\n\n<li>Entidades de salud en varios pa\u00edses. El grupo no discrimina sector ni regi\u00f3n geogr\u00e1fica.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Tecnolog\u00edas y herramientas asociadas con Everest<\/h3>\n\n\n\n<p>Everest suele apoyarse en herramientas leg\u00edtimas y malware auxiliar para movimiento lateral y persistencia, entre ellas:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Cobalt Strike<\/li>\n\n\n\n<li>AnyDesk<\/li>\n\n\n\n<li>Splashtop<\/li>\n\n\n\n<li>Atera<\/li>\n\n\n\n<li>WinRAR<\/li>\n\n\n\n<li>ProcDump<\/li>\n<\/ul>\n\n\n\n<p>Tambi\u00e9n se ha observado:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>explotaci\u00f3n de servicios RDP\/VPN expuestos,<\/li>\n\n\n\n<li>uso de credenciales robadas,<\/li>\n\n\n\n<li>compra y venta de accesos iniciales (Initial Access Broker).<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">TTPs relevantes (MITRE ATT&amp;CK)<\/h3>\n\n\n\n<p>Algunas t\u00e9cnicas com\u00fanmente asociadas:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>T1133 \u2013 External Remote Services<\/li>\n\n\n\n<li>T1078 \u2013 Valid Accounts<\/li>\n\n\n\n<li>T1021 \u2013 Remote Services<\/li>\n\n\n\n<li>T1486 \u2013 Data Encrypted for Impact<\/li>\n\n\n\n<li>T1567 \u2013 Exfiltration to Cloud Services<\/li>\n\n\n\n<li>T1490 \u2013 Inhibit System Recovery<\/li>\n<\/ul>\n\n\n\n<p>A continuaci\u00f3n, se presenta un resumen de las CVEs que con mayor frecuencia han sido explotadas por grupos de ransomware y extorsi\u00f3n con TTPs compatibles con Everest:<\/p>\n\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table class=\"has-fixed-layout\"><thead><tr><th>CVE<\/th><th>Producto<\/th><th>Tipo<\/th><th>Severidad<\/th><th>Impacto Principal<\/th><\/tr><\/thead><tbody><tr><td><strong>CVE-2023-27997<\/strong><\/td><td>Fortinet FortiOS SSL-VPN<\/td><td>Buffer Overflow<\/td><td>Cr\u00edtica<\/td><td>RCE preautenticaci\u00f3n<\/td><\/tr><tr><td><strong>CVE-2022-42475<\/strong><\/td><td>Fortinet FortiOS<\/td><td>RCE<\/td><td>Cr\u00edtica<\/td><td>Ejecuci\u00f3n remota de c\u00f3digo<\/td><\/tr><tr><td><strong>CVE-2018-13379<\/strong><\/td><td>Fortinet FortiOS SSL-VPN<\/td><td>Path Traversal<\/td><td>Cr\u00edtica<\/td><td>Robo de credenciales VPN<\/td><\/tr><tr><td><strong>CVE-2023-4966<\/strong><\/td><td>Citrix NetScaler (Citrix Bleed)<\/td><td>Session Hijacking<\/td><td>Cr\u00edtica<\/td><td>Secuestro de sesiones autenticadas<\/td><\/tr><tr><td><strong>CVE-2019-19781<\/strong><\/td><td>Citrix ADC\/Gateway<\/td><td>RCE<\/td><td>Cr\u00edtica<\/td><td>Acceso remoto a sistemas<\/td><\/tr><tr><td><strong>CVE-2019-11510<\/strong><\/td><td>Pulse Secure VPN<\/td><td>Arbitrary File Read<\/td><td>Cr\u00edtica<\/td><td>Exposici\u00f3n de credenciales<\/td><\/tr><tr><td><strong>CVE-2023-46805<\/strong><\/td><td>Ivanti Connect Secure<\/td><td>Authentication Bypass<\/td><td>Cr\u00edtica<\/td><td>Acceso sin autenticaci\u00f3n<\/td><\/tr><tr><td><strong>CVE-2024-21887<\/strong><\/td><td>Ivanti Connect Secure<\/td><td>Command Injection<\/td><td>Cr\u00edtica<\/td><td>RCE post-bypass<\/td><\/tr><tr><td><strong>CVE-2021-26855<\/strong><\/td><td>Microsoft Exchange (ProxyLogon)<\/td><td>SSRF + RCE<\/td><td>Cr\u00edtica<\/td><td>Compromiso completo del servidor<\/td><\/tr><tr><td><strong>CVE-2021-34473<\/strong><\/td><td>Microsoft Exchange (ProxyShell)<\/td><td>RCE<\/td><td>Cr\u00edtica<\/td><td>Instalaci\u00f3n de webshells<\/td><\/tr><tr><td><strong>CVE-2021-34527<\/strong><\/td><td>Windows Print Spooler (PrintNightmare)<\/td><td>RCE \/ Privilege Escalation<\/td><td>Cr\u00edtica<\/td><td>Control de dominio<\/td><\/tr><tr><td><strong>CVE-2020-1472<\/strong><\/td><td>Netlogon (ZeroLogon)<\/td><td>Elevaci\u00f3n de privilegios<\/td><td>Cr\u00edtica<\/td><td>Compromiso de Domain Controller<\/td><\/tr><tr><td><strong>CVE-2021-21974<\/strong><\/td><td>VMware ESXi OpenSLP<\/td><td>RCE<\/td><td>Cr\u00edtica<\/td><td>Compromiso de hipervisores<\/td><\/tr><tr><td><strong>CVE-2023-20867<\/strong><\/td><td>VMware ESXi<\/td><td>RCE<\/td><td>Alta<\/td><td>Control de infraestructura virtual<\/td><\/tr><tr><td><strong>CVE-2021-20016<\/strong><\/td><td>SonicWall SMA<\/td><td>RCE<\/td><td>Cr\u00edtica<\/td><td>Acceso remoto persistente<\/td><\/tr><tr><td><strong>CVE-2023-28771<\/strong><\/td><td>Zyxel Firewall<\/td><td>Command Injection<\/td><td>Cr\u00edtica<\/td><td>Compromiso del firewall<\/td><\/tr><tr><td><strong>CVE-2023-22515<\/strong><\/td><td>Atlassian Confluence<\/td><td>Broken Access Control<\/td><td>Cr\u00edtica<\/td><td>Creaci\u00f3n de administradores<\/td><\/tr><tr><td><strong>CVE-2022-26134<\/strong><\/td><td>Atlassian Confluence<\/td><td>OGNL Injection \/ RCE<\/td><td>Cr\u00edtica<\/td><td>Ejecuci\u00f3n remota de c\u00f3digo<\/td><\/tr><tr><td><strong>CVE-2023-34362<\/strong><\/td><td>MOVEit Transfer<\/td><td>SQL Injection \u2192 RCE<\/td><td>Cr\u00edtica<\/td><td>Robo masivo de datos<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-20.png\"><img data-opt-id=911889894  data-opt-src=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1024\/h:676\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-20.png\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"676\" src=\"data:image/svg+xml,%3Csvg%20viewBox%3D%220%200%201024%20676%22%20width%3D%221024%22%20height%3D%22676%22%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Crect%20width%3D%221024%22%20height%3D%22676%22%20fill%3D%22transparent%22%2F%3E%3C%2Fsvg%3E\" alt=\"\" class=\"wp-image-4348\" old-srcset=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1024\/h:676\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-20.png 1024w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:300\/h:198\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-20.png 300w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:768\/h:507\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-20.png 768w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:830\/h:548\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-20.png 830w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:1040\/h:687\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2026\/05\/image-20.png 1040w\" \/><\/a><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Implicaciones para Colombia<\/h2>\n\n\n\n<p>El ataque registrado ocurre en un contexto de escalada sostenida. Seg\u00fan informes de ciberseguridad, Colombia acumul\u00f3 m\u00e1s de <strong>36.000 millones<\/strong> de intentos de ataque en 2024, y los primeros seis meses de 2025 ya registraban <strong>7.100 millones<\/strong>. Diversos estudios regionales reportan que las organizaciones en Colombia y Latinoam\u00e9rica enfrentan en promedio: entre <strong>2.800 y 3.000<\/strong> ciberataques semanales por organizaci\u00f3n.<\/p>\n\n\n\n<p>Los ataques son adem\u00e1s cada vez m\u00e1s sofisticados: combinan ingenier\u00eda social, robo de credenciales e inteligencia artificial para hacerlos m\u00e1s dif\u00edciles de detectar.<\/p>\n\n\n\n<p>El caso de SOLATI pone sobre la mesa una pregunta inc\u00f3moda para todas las organizaciones colombianas: <strong>\u00bfcu\u00e1n seguros son sus proveedores?<\/strong> Las empresas que han fortalecido su per\u00edmetro interno a menudo descuidan auditar el nivel de seguridad de su ecosistema de contratistas, creando puertas traseras involuntarias hacia sus activos m\u00e1s sensibles.<\/p>\n\n\n\n<p><strong>Fuentes<\/strong>: <\/p>\n\n\n\n<p><a href=\"https:\/\/www.elcolombiano.com\/antioquia\/ciberataque-cartera-epm-hidroelectrica-de-caldas-seguridad-informatica-GH37126716?utm_source=chatgpt.com\">https:\/\/www.elcolombiano.com\/antioquia\/ciberataque-cartera-epm-hidroelectrica-de-caldas-seguridad-informatica-GH37126716<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/www.infobae.com\/colombia\/2026\/05\/30\/epm-investiga-posible-filtracion-de-datos-de-cartera-tras-ciberataque-a-contratista-empresa-activo-protocolos-de-seguridad\">https:\/\/www.infobae.com\/colombia\/2026\/05\/30\/epm-investiga-posible-filtracion-de-datos-de-cartera-tras-ciberataque-a-contratista-empresa-activo-protocolos-de-seguridad<\/a><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u00bfEst\u00e1 seguro que su aplicaci\u00f3n web es segura?<\/h2>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2024\/04\/image-8.png\"><img data-opt-id=937290856  data-opt-src=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:529\/h:145\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2024\/04\/image-8.png\"  loading=\"lazy\" decoding=\"async\" width=\"529\" height=\"145\" src=\"data:image/svg+xml,%3Csvg%20viewBox%3D%220%200%20529%20145%22%20width%3D%22529%22%20height%3D%22145%22%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Crect%20width%3D%22529%22%20height%3D%22145%22%20fill%3D%22transparent%22%2F%3E%3C%2Fsvg%3E\" alt=\"\" class=\"wp-image-3845\" old-srcset=\"https:\/\/ml4lvzevoq9y.i.optimole.com\/w:529\/h:145\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2024\/04\/image-8.png 529w, https:\/\/ml4lvzevoq9y.i.optimole.com\/w:300\/h:82\/q:mauto\/f:best\/https:\/\/www.itechsas.com\/blog\/wp-content\/uploads\/2024\/04\/image-8.png 300w\" \/><\/a><\/figure>\n\n\n\n<p>Recibe un\u00a0<strong>Diagn\u00f3stico Sin Costo\u00a0<\/strong>del estado de seguridad de tu aplicaci\u00f3n, sitio web o dominio dando clic en el siguiente enlace:<\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link has-vivid-red-background-color has-background wp-element-button\" href=\"https:\/\/forms.gle\/5yvxp32NRbNSGQ5W9\">Reciba Diagnostico sin Costo<\/a><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>El grupo de ransomware Everest public\u00f3 en su portal de la dark web un aviso de extorsi\u00f3n contra SOLATI S.A.S., empresa contratista de EPM y la Central Hidroel\u00e9ctrica de Caldas (CHEC). El ataque expuso informes especializados de cartera de ambas entidades y reaviva la alarma sobre la seguridad de la cadena de suministro tecnol\u00f3gico en&hellip;<\/p>\n","protected":false},"author":1,"featured_media":4343,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[23],"tags":[],"class_list":["post-4327","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ciberseguridad"],"_links":{"self":[{"href":"https:\/\/www.itechsas.com\/blog\/wp-json\/wp\/v2\/posts\/4327","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.itechsas.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.itechsas.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.itechsas.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.itechsas.com\/blog\/wp-json\/wp\/v2\/comments?post=4327"}],"version-history":[{"count":11,"href":"https:\/\/www.itechsas.com\/blog\/wp-json\/wp\/v2\/posts\/4327\/revisions"}],"predecessor-version":[{"id":4355,"href":"https:\/\/www.itechsas.com\/blog\/wp-json\/wp\/v2\/posts\/4327\/revisions\/4355"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.itechsas.com\/blog\/wp-json\/wp\/v2\/media\/4343"}],"wp:attachment":[{"href":"https:\/\/www.itechsas.com\/blog\/wp-json\/wp\/v2\/media?parent=4327"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.itechsas.com\/blog\/wp-json\/wp\/v2\/categories?post=4327"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.itechsas.com\/blog\/wp-json\/wp\/v2\/tags?post=4327"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}