Hacktivist group

EsqueleSquad

EsqueleSquad, also observed as EsqueleSquad Team and referenced in English-language supply-chain reporting as “Skeleton Squad,” is assessed as a Latin-linked cybercrime / hacktivist-adjacent cluster with a mixed activity record spanning public defacement claims, malicious open-source package abuse, malware distribution, and recent large-scale data-leak claims affecting Argentine governmental, academic and media infrastructure.

The strongest recent reporting concerns a May 2026 claim in which the actor Skull1172, representing EsqueleSquad TEAM, allegedly announced a consolidated leak affecting more than 900 Argentine government, education and media domains, with more than 80 million records and over 50 GB threatened for release. Public reporting states that the incident remains under investigation and should be treated as alleged until confirmed by victim-side evidence.

Older reporting indicates that EsqueleSquad or Esquele Squad was linked to a 2018 defacement of the Observatorio de Violencia contra las Mujeres in Salta, Argentina. Separate software supply-chain reporting from 2023 links “Skeleton Squad” / EsqueleSquad to malicious package campaigns across PyPI and npm, including payload download and Windows-focused execution chains.

Confidence is medium that EsqueleSquad represents a persistent brand or cluster name reused across Latin-language cybercrime and defacement contexts. Confidence is low–medium that all activity attributed to EsqueleSquad across 2018 defacement, 2023 package malware, and 2026 Argentina data-leak claims reflects the same operator set.

Created by iQBlack CTI Team
Contributors 1
Last updated 2026-08-21