Alpha Cyber

Coordinated Cyber Strike: Five Families Syndicate Targets Alpha Automation in Brazil

A new wave of coordinated cyberattacks has emerged from a threat actor group known as the Five Families Collective, recently targeting Alpha Automation, a leading industrial automation firm in Brazil.

Alpha Cyber Research1 min readupdated 1 Apr 2026
Five Families Syndicate Graph

Uncovering the Hidden Infrastructure Behind a Sophisticated Threat Operation

A new wave of coordinated cyberattacks has emerged from a threat actor group known as the Five Families Collective, recently targeting Alpha Automation, a leading industrial automation firm in Brazil. This isn’t just another ransomware event, it’s a multi-layered attack campaign involving infrastructure obfuscation, lateral movement, and advanced data exfiltration methods.

At Alpha Cyber, our threat intel team has mapped out the infrastructure supporting this campaign, and the results are alarming.

Infrastructure Map Highlights:

Distributed Command & Control Servers across North America, Eastern Europe, and Southeast Asia
Multi-tiered proxy networks used to hide attacker origin
Weaponized phishing infrastructure mimicking government and industrial regulatory bodies
Custom malware loaders signed with stolen digital certificates
Dedicated data exfiltration channels over encrypted tunnels, undetectable by traditional firewalls

What It Means for Industrial and Critical Infrastructure Sectors:

The attack on Alpha Automation is a blueprint for future industrial espionage and disruption campaigns. Organizations across manufacturing, energy, and logistics should treat this as a warning: threat actors are shifting to supply chain infiltration and OT/ICS compromise.

How We Help:

At Alpha Cyber, we specialize in:

Threat Infrastructure Mapping – tracing attacker infrastructure across the globe
24/7 Threat Monitoring & Response – real-time alerting and remediation
Attack Surface Reduction – hardening systems against nation-state-level threats

Don’t wait for the breach to reach your systems.
Schedule a threat risk consultation or request a custom infrastructure analysis today.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]