Ransomware Lurks in Brazil’s Classrooms

Article by Nacata Security, 04/08/2026

Did you know your university could be the easiest target to attack?

Researchers detect waves of ransomware attacks against educational institutions in Brazil since 2025.

University networks mix students, faculty, administrative staff, and external visitors, each group with different permissions and no uniform security policies to protect them.

That complexity turns every campus into a maze of poorly controlled access points where a single stolen credential can open the door to the entire internal system.

An attacker executes lateral movement and mass encryption in the early hours of the morning, with the clock showing 5:30 and servers going down one by one.
Documented overnight attack

The response team saw it firsthand.

Kaspersky’s GERT team documented cases from January 2025 to June 2026 in São Paulo, Rio de Janeiro, and Pernambuco. 40% of incidents were high severity, all linked to ransomware. The most active families were DragonForce and LockBit 3, the latter built with a builder leaked in 2022 that any attacker can use to generate variants capable of disabling defenses and wiping logs.

The entry vector was not a sophisticated exploit.

In most cases, attackers gained access using compromised valid accounts. Once inside, they escalated privileges with GodPotato or SweetPotato, moved laterally with PsExec, and used AnyDesk to maintain remote access. In one documented case, the attacker connected at 5:30 UTC and executed LockBit for the last time at 10:00 the same day: four and a half hours to encrypt entire servers.

Private institutions accounted for all ransomware attacks documented in the study.

Attackers assume that private universities have greater financial capacity to pay the ransom. Public institutions, on the other hand, primarily suffered privilege escalation attempts and suspicious endpoint activity. In both cases, the average technical response time was 9.6 hours, well above the actual duration of the attack.

The university campus as a circuit with dozens of different users connected to a central node with cables of varying thickness, some sparking.
Uncontrolled access

This pattern is not limited to Brazil.

Any educational institution with users at different access levels and unpatched systems shares the same vulnerabilities identified on these campuses.

The use of legitimate tools such as AnyDesk or PsExec makes it difficult for systems to block them.

40% of incidents were high severity and resulted in mass encryption with ransomware and complete operational paralysis.

And there is one detail that makes everything worse.

Several compromised systems were running Windows 10 past its end of support in October 2025, and some servers were running unpatched Windows Server 2016. This expands the attack surface and complicates subsequent forensic analysis.

The most silent risk comes from within.

One of the most striking cases was not external ransomware, but an insider. A user installed a Python keylogger on a machine shared by several employees. The script created log files with everything typed, hid those files in the file explorer, and detected when Caps Lock was pressed to correctly capture passwords. No persistence or automatic exfiltration.

The attacker collected the logs manually using a USB drive.

Forensic analysis identified USB device connections at the exact times the script was running, suggesting the insider was physically extracting files containing captured passwords. Without camera footage or additional evidence, it was not possible to attribute the activity to a specific individual or take definitive legal action.

An insider physically extracts password files via USB from a shared machine, with hidden logs visible on screen.
Insider with USB

Multi-factor authentication would have broken the entire attack chain.

Valid accounts were the most common entry vector in all analyzed cases. Enabling MFA on VPNs, remote portals, and email would have blocked the majority of these attacks, regardless of whether the credential had been stolen or reused.

Isolated backups are the last line of defense.

When ransomware encrypts servers, the only way out without paying is to have backup copies separated from the main environment and regularly tested. Researchers recommend centralizing logs, maintaining EDR telemetry with extended retention, and synchronizing clocks across all systems to reconstruct the attack timeline.

Patch, segment, and audit privileged accounts.

The recommendations are actionable today: review permissions, eliminate shared accounts, and apply all pending patches before someone else does it for you.

Act right now

  • Enable MFA on all remote access points and VPNs.
  • Review and eliminate shared accounts; assign one individual account per user.
  • Isolate your backups from the main environment and test them regularly.

Is your institution running unpatched systems that are already an active target?

Security is not improvised, it is audited. At Nacata Security we detect vulnerabilities and protect your company, because a single flaw can cost you everything you have built.

Related articles

Nacata Security, reach out to us anytime

How would you rate this news?

We are Nacata Security, get to know us

web: nacata.io

email: info@nacata.io

Phone: 919930793

LinkedIn: Nacata Security

Threats

Risks and attacks happening right now: vulnerabilities being actively exploited, official alerts from cybersecurity agencies, ongoing phishing or malware campaigns.

Information meant to help you act and protect yourself before the problem reaches you.



RATING


7.7



Who are we?


At Nacata Security we are an offensive cybersecurity company specialized in audits and penetration testing.


We detect, assess and help mitigate the vulnerabilities of your systems, networks and applications before a real attacker exploits them, offering 360º defense tailored to each client.


We’d be glad to get in touch with you for whatever you need.