Kimera is a proprietary distributed reconnaissance framework associated with intrusion operations attributed to MexicanMafia, also known as PanchoVilla, and has also appeared in detections linked to TeamTNT activity. It is used to scan, enumerate, and triage targets at scale, feeding identified opportunities directly into downstream exploitation workflows. Reported deployments show Kimera functioning as part of a broader automated vulnerability-to-exploitation pipeline rather than as a standalone destructive or monetization payload.
Observed use places Kimera in campaigns targeting internet-facing infrastructure, especially perimeter devices and exposed enterprise services. It has been described as supporting parallelized enumeration and rapid target qualification in operations against organizations in Latin America, particularly critical infrastructure, government, financial, telecommunications, transport, and utility sectors. In those campaigns, Kimera operated alongside exploit tooling for widely targeted edge technologies and was integrated with post-compromise access mechanisms such as web shells, reverse tunnels, and persistent network-level tunneling.
Separately, detections bearing the Kimera name have been associated with TeamTNT cloud-focused operations involving misconfigured cloud services, vulnerable Kubernetes environments, and exposed Amazon Web Services instances. In that context, related activity included credential theft from cloud environments and deployment of cryptocurrency-mining payloads, including targeting of GPU-equipped systems. However, the strongest support for Kimera itself is as a reconnaissance component used to discover and prioritize targets for later exploitation.
Kimera is best characterized as offensive reconnaissance tooling used in multi-stage intrusion campaigns across cloud and enterprise-facing environments, with emphasis on automated discovery, scanning, and target selection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
All of it was fed by a custom reconnaissance engine the group calls Kimera, which CloudSEK said scanned and triaged targets at high speed, then handed them straight to the exploitation stage.
All of it was fed by a custom reconnaissance engine the group calls Kimera, which CloudSEK said scanned and triaged targets at high speed, then handed them straight to the exploitation stage.
All of it was fed by a custom reconnaissance engine the group calls Kimera, which CloudSEK said scanned and triaged targets at high speed, then handed them straight to the exploitation stage.
All of it was fed by a custom reconnaissance engine the group calls Kimera, which CloudSEK said scanned and triaged targets at high speed, then handed them straight to the exploitation stage.
All of it was fed by a custom reconnaissance engine the group calls Kimera, which CloudSEK said scanned and triaged targets at high speed, then handed them straight to the exploitation stage.
All of it was fed by a custom reconnaissance engine the group calls Kimera, which CloudSEK said scanned and triaged targets at high speed, then handed them straight to the exploitation stage.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Indicators of compromise SHA-256 Detection name ... TROJAN.SH.KIMERA.YXBJ3 ... TROJANSPY.SH.CHIMAERA.AA. TeamTNT’s attacks have become more modular ... crafted a hard-coded shell script that targeted credentials from vulnerable AWS instances ... payloads now identify GPU-based environments and deploy specific payloads to target instances running in CSPs and take advantage of the computational power and generate more cryptocurrency.
Tooling including proprietary reconnaissance engine Kimera; a "curated exploit armory" targeting popular perimeter devices such as those from Fortinet, Ivanti, and Cisco; portable lateral movement toolkits; and "layered command-and-control infrastructure using Neo-reGeorg webshells, Chisel reverse tunnels, and compromised Cisco routers with persistent GRE tunnels," researchers said.
Tooling including proprietary reconnaissance engine Kimera; a "curated exploit armory" targeting popular perimeter devices such as those from Fortinet, Ivanti, and Cisco; portable lateral movement toolkits; and "layered command-and-control infrastructure using Neo-reGeorg webshells, Chisel reverse tunnels, and compromised Cisco routers with persistent GRE tunnels," researchers said.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
All of it was fed by a custom reconnaissance engine the group calls Kimera, which CloudSEK said scanned and triaged targets at high speed, then handed them straight to the exploitation stage.
After using Kimera for reconnaissance, MexicanMafia exploits a range of popular vulnarabilities to gain initial access. These include FortiGate SSL-VPN vulnerabilities CVE-2022-42475, CVE-2023-27997, and CVE-2024-21762, as well as the CVE-2023-46805/CVE-2024-21887 Ivanti Connect Secure authentication bypass and command injection chain. The group also exploits Apache Tomcat AJP connectors via the GhostCat vulnerability, CVE-2020-1938.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom reconnaissance engine used to scan and triage targets rapidly before passing them to exploitation workflows.
A proprietary reconnaissance engine used by the MexicanMafia/PanchoVilla threat actor during Operation Escaneo for automated reconnaissance prior to exploitation and follow-on intrusion activity.
A custom distributed reconnaissance framework used to automate subdomain enumeration, port scanning, vulnerability scanning, XSS validation, screenshotting, JavaScript endpoint extraction, and triage from discovery to exploitation.
A TeamTNT-associated shell-script malware/toolset used in cloud intrusions, particularly against AWS and Kubernetes environments. The samples are modular, steal cloud credentials/metadata, adapt to Kubernetes targets, and deploy mining payloads optimized for GPU-equipped systems to increase Monero mining output.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.