Paraguay’s MITIC Server Down for 24 Hours, TheGarudaEye in Spotlight
The online services of Paraguay’s Ministerio de Tecnologías de la Información y Comunicación (MITIC), the ministry overseeing the…
> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE
/actor/the-garuda-eye/ · 4 intel reports
The Garuda Eye is a 2025-era hacktivist desk that publishes numbered disruption reports against public-sector websites. The brand uses a stylized Garuda emblem. Operations are framed as protest signalling, not ransom. CyberAsia treats Telegram posts as claims until downtime is corroborated with independent probes.
Documented activity includes multi-hour outages against Paraguay Ministry of Foreign Affairs (mre.gov.py) in August 2026 under #OpParaguay / #OpBoP. Evidence packs showed Azure Front Door configuration errors escalating to nginx 502 and 504 gateway timeouts, plus check-host.net / check-host.cc maps. Stated duration for the foreign ministry incident was 86,400 seconds (24 hours). A related claim targeted Paraguay immigration infrastructure (migraciones.gov.py) with a reported 12-hour window.
The technical pattern is application-layer flooding rather than data theft. Origin servers lose thread and database capacity under legitimate-looking HTTP requests. Defenders should treat these as WAF, CDN, and rate-limit events, not as confirmed network intrusion, unless separate evidence of credential access appears.
Unlike RipperSec (MegaMedusa / Zeus Stresser panels) or NoName057(16) (DDoSia volunteer botnet), The Garuda Eye has not published a named custom toolkit in material reviewed by CyberAsia. Attribution stays at the collective brand level. Earlier 2025 reporting also tied the name to protest floods against regional administrative portals, including public citizen grievance sites, which matches a preference for highly visible government front doors over corporate payment systems.
Campaign packaging is consistent: a numbered report ID, a political justification graphic, a pair of third-party uptime maps, and a duration quoted in seconds. That packaging is useful for tracking but is not the same as a CERT confirmation. Paraguay authorities had not issued a public technical bulletin at the time CyberAsia filed the foreign ministry report.
Defensive notes for public portals: pre-position CDN and WAF challenges on .gov origin hosts, disable unused Azure Front Door routes, keep origin health checks off the public internet, and publish a maintenance status page so citizens are not forced through a dead origin during an active flood. If Azure Front Door returns a missing-route page, treat that as a configuration or origin-health failure first, then as a flood.
Status: active as of August 2026. Classification: hacktivist collective. No ransomware leak site, no affiliate panel, and no confirmed long-term persistence toolkit have been attached to this brand in the CyberAsia archive.
The online services of Paraguay’s Ministerio de Tecnologías de la Información y Comunicación (MITIC), the ministry overseeing the…
The hacktivist group TheGarudaEye has extended its reach into South America, taking down the official portal of the…
The official portal of Paraguay’s Dirección Nacional de Migraciones (DNM), migraciones.gov.py, suffered a major service disruption after hacktivist…
Paraguay’s Ministry of Foreign Affairs (Ministerio de Relaciones Exteriores) became the target of a cyberattack after its official…