Mexico. A new cyberattack has set off alarms in Mexico. According to an analysis by the SILIKN Research Unit, North Korean-sponsored cybercriminals compromised the cloud environment of the company Commvault, hosted on Microsoft Azure, by exploiting a zero-day vulnerability.
The attack has been attributed to the Lazarus group, an advanced persistent threat (APT) known for its sophistication and links to espionage operations, financial theft, and global destabilization.
The attack exploited the CVE-2025-3928 vulnerability, a critical flaw with a CVSS score of 8.7 that affects Commvault's web server. This flaw allows an authenticated remote attacker to create and run webshells, thereby gaining unauthorized access to compromised infrastructure. Although its exploitation requires valid credentials within the Commvault environment, it is presumed that the attackers combined this vulnerability with techniques such as credential theft to achieve the intrusion.
The incident was first detected in March 2025, and while Commvault released corrective patches in February, these were released before the CVE identifier was assigned, confirming that it was a zero-day attack. The fixed versions include updates 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms.
To support the detection of malicious activity, several indicators of compromise (IoCs) were shared and the following IP addresses have been recommended to be blocked:
- 108.69.148.100
- 128.92.80.210
- 184.153.42.129
- 108.6.189.53
- 159.242.42.20
It is also important to monitor login attempts from IP addresses outside of the usual geographical ranges and times.
SILIKN's research unit has identified several Mexican government agencies as potentially exposed to this vulnerability. Among the affected entities are:
- Tax Administration Service (SAT)
- Government of the State of Sonora
- Ministry of Finance of the State of Sonora
- CorreosClic (Mexican Postal Service)
- Higher Institute of Auditing and Supervision
- Mexico's National Customs Agency
- Secretariat of Education and Culture of Colima
- Integral Information Platform of the Ministry of Education and Culture of Colima
The exposure of these entities is compounded by a lack of updates, the use of outdated systems, and the persistence of vulnerabilities in platforms such as Zimbra, which continue to be widely exploited attack vectors.
The Lazarus group has maintained a constant presence in Mexico over the past decade. In 2018, it attempted to steal $100 million from the Mexican financial system through spear-phishing and exploiting vulnerabilities in the SWIFT network, replicating techniques used in the theft of $81 million from the Central Bank of Bangladesh in 2016.
In 2022, it exploited vulnerabilities in Zimbra servers (CVE-2022–27925 and CVE-2022–37042) to extract 120 GB of data from Mexican government institutions, coinciding with the massive leak of 6 TB of confidential documents from the Ministry of National Defense (Sedena).
Between 2015 and 2016, it also launched attacks on commercial banks in Mexico as part of a global campaign. Its history includes the WannaCry ransomware (2017) and, more recently, the theft of $1.5 billion from the cryptocurrency platform Bybit (2025).
This new incident highlights the challenges of protecting cloud environments from highly sophisticated cyberattackers. Although no official data loss has been reported in this case, the exposure from government entities highlights the urgent need to adopt more robust security practices, including:
- Multi-factor authentication
- Continuous infrastructure monitoring
- Immediate application of security patches
- Network segmentation
- Continuous training of staff
Collaboration between technology providers, government agencies, and the cybersecurity community will be key to addressing emerging threats and mitigating risks before they materialize into national security crises.
*By Víctor Ruiz, founder of SILIKN, Certified Cybersecurity Instructor (CSCT),™ (ISC)² Certified in Cybersecurity℠ (CC), EC-Council Ethical Hacking Essentials (EHE) Certified, EC-Council Certified Cybersecurity Technician (CCT), Ethical Hacking Certified Associate (EHCA), Cisco Ethical Hacker & Cisco Cybersecurity Analyst and leader of the Querétaro Chapter of the OWASP Foundation.


