A newly identified ransomware operation calling itself Moondancer has begun actively recruiting criminal affiliates with a specific focus on Latin America, according to threat intelligence monitoring cited by Brinztech. The group is structured as a ransomware-as-a-service (RaaS) syndicate, meaning it builds and maintains the malicious software while outsourcing the actual attacks to a network of paid partners. Notably, Moondancer has publicly stated it will not target healthcare organizations, a branding move increasingly common among ransomware operators trying to project an image of restraint even as they recruit criminals to break into other kinds of networks.
While Moondancer is still emerging and details remain limited, its recruitment drive fits a pattern that has defined ransomware's evolution for years: rather than a single group carrying out every attack, RaaS operators act more like criminal franchises, providing tools, infrastructure, and payment-splitting arrangements to independent affiliates who do the hands-on hacking.
How Ransomware-as-a-Service Recruitment Works
RaaS groups typically advertise on underground forums or invite-only channels, offering a cut of ransom payments to affiliates who successfully breach a target, deploy the encryption payload, and negotiate with victims. The core group behind the malware, in this case Moondancer, provides the technical backbone: the encryption tools, leak sites for pressuring victims, and sometimes even customer support for affiliates.
This division of labor is part of why ransomware has scaled so dramatically. It lowers the barrier to entry for less technically skilled criminals while letting the core developers focus on improving their tools and avoiding direct exposure during attacks. Recent reporting has tracked this same dynamic across the threat landscape, including Black Kite's 2026 report showing ransomware hit 7,551 victims worldwide last year, a scale only achievable through this kind of affiliate-driven model.
Why Latin America Is in the Crosshairs
Moondancer's decision to target its recruitment campaign specifically at Latin America is consistent with broader trends in how ransomware groups choose their expansion regions. Attackers often gravitate toward areas where cybersecurity defenses are still maturing, where local law enforcement cooperation on cybercrime cases can be slower, or where language and cultural familiarity give affiliates an advantage in crafting convincing phishing lures and negotiating with local victims.
This regional targeting mirrors patterns seen elsewhere. Ransomware activity has been climbing globally, with attacks surging 87% year-over-year and Spanish businesses alone facing an average of 2,068 attacks per week. Groups looking for fresh territory and less-saturated victim pools increasingly look beyond North America and Western Europe, and Latin America's growing digital economy makes it an attractive target for exactly this kind of expansion.
The public disclaimer about avoiding healthcare targets is also worth noting. Ransomware groups have faced significant reputational and law enforcement backlash after attacks on hospitals disrupted patient care in the past. By explicitly ruling out healthcare, Moondancer appears to be trying to reduce the intensity of international law enforcement attention while still building a criminal enterprise that can affect businesses, local governments, and other organizations across the region.
What This Means For You
If you run a business or manage IT infrastructure in Latin America, this development is a signal to revisit your ransomware defenses now rather than after an incident occurs. Affiliate-recruited attacks tend to ramp up quickly once a RaaS group has built out its network, since more affiliates simply means more attempted breaches happening in parallel.
For individual users, the risk is less direct but still relevant. Ransomware affiliates frequently gain initial access through phishing emails, compromised remote access credentials, or malicious downloads, the same techniques used in other malware campaigns, including recent ones like the fake CCleaner installer spreading GhostDesk spyware. Practicing caution with downloads and unsolicited links remains one of the most effective personal defenses against becoming an entry point for a larger organizational breach.
Actionable Takeaways
Organizations in Latin America, and anywhere else that may eventually see Moondancer activity, should prioritize a few concrete steps. Ensure remote access points, including VPNs and RDP connections, require multi-factor authentication, since compromised credentials remain one of the most common entry vectors for affiliate-driven ransomware. Keep offline, tested backups of critical data, since a working recovery plan removes much of the leverage a ransom demand relies on. Train staff to recognize phishing attempts, and monitor for unusual account activity that could indicate an affiliate has already gained a foothold.
The emergence of Moondancer ransomware is a reminder that the RaaS business model keeps producing new entrants, each looking for underserved regions and fresh victims. Staying informed about these shifts, and acting on basic security hygiene before an attack happens, remains the most reliable way to avoid becoming part of the next headline.




