On 16 August a user posting as Straightonnumberone opened an affiliate programme on the darkforums[.]ru crime forum for a new Windows ransomware called Moondancer, and advertised it again on 20 August. Colombia's national CERT has now issued an alert about it, and the reason is the stated target list: critical infrastructure across Latin America.
Nothing has been encrypted yet, as far as colCERT's alert goes. What exists is a recruitment drive. That is the stage at which a ransomware-as-a-service operation is easiest to see and hardest to stop.
Hiring for three jobs
The group calls itself EXILIADOS on Telegram and uses the Straightonnumberone alias on dark web forums. colCERT says it is looking for three kinds of collaborator, and the split is a fair description of how a modern extortion crew is assembled. Initial access brokers to supply the way in, with a stated preference for legitimate compromised credentials. Pentesting operators with advanced Active Directory experience, plus hybrid cloud environments (Azure, AWS, Google Cloud) and the VMware ESXi and vCenter virtualisation platforms. Developers fluent in C, assembly or Rust, working on Windows internals, kernel-level development, cryptography and reverse engineering.
In exchange, affiliates are offered a variable share of ransom proceeds plus real-time technical advice during reconnaissance, lateral movement and deployment. colCERT rates the alert high risk.
Treat the sales pitch as a sales pitch
The encryptor is advertised as Windows only and built on XChaCha20 with ECDH key exchange. The group also claims proven capability to evade or disable market-leading EDR and XDR products, naming CrowdStrike, SentinelOne and Sophos. That claim is the group's own marketing, relayed by colCERT from forum posts, and no independent testing of it has been published. It is worth knowing what affiliates are being promised without treating it as an established capability.
The same caution applies to the carve-out. EXILIADOS says it will not attack healthcare, leaving energy, finance, government, telecommunications and transport in scope. Ransomware crews announce that rule often and break it often, so read it as a recruiting message rather than a guarantee to hospitals.
Why Colombia is raising its hand
colCERT's argument is direct. A campaign aimed explicitly at Latin American critical infrastructure is an imminent risk to Colombian organisations, and the affiliate model makes it move faster, because it bolts specialists onto a crew that would otherwise have to build every capability in-house. It has been a busy month for the country's defenders: weeks ago the same CERT warned about a crew that mined cryptocurrency on victim networks before encrypting them. Our Colombia country profile tracks the wider picture.
What to do before an affiliate shows up
The advert doubles as a requirements list, and it maps onto defences you can check this week. Credentials are the stated entry route, so put phishing-resistant multi-factor authentication on every remote access path and audit the accounts that still lack it. The pentesting brief names Active Directory, hybrid cloud identity, ESXi and vCenter, all of which reward tiered administrative accounts, management interfaces that are not reachable from user networks, and hypervisor credentials that are separate from the Windows domain. Given the evasion claim, do not treat endpoint detection as the last line: switch on agent tamper protection and make sure an agent going silent pages a human. Keep offline, tested backups of the systems you cannot operate without.
The alert, COLCERT AL 20260825 115, is published as TLP:CLEAR by colCERT.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.