Hacktivist group

Chronus Jr.

Chronus Jr. (also referred to as Chronus Juniors) is best assessed as a parallel and aligned sub-brand or affiliated operator grouping inside the broader Chronus ecosystem, rather than as a fully separate mature threat organization. Available evidence supports treating Chronus Jr. as related to Chronus Team through shared branding space, overlapping narrative posture, compatible victimology, and at least one observed Argentina-linked operation involving joint attribution with a core Chronus Team-linked actor.

Current confidence is medium-high for the existence of Chronus Jr. as a real named operational label and medium for the exact structural relationship between Chronus Jr. and the core Chronus Team brand. The healthiest analytical treatment remains conservative: Chronus Jr. appears close enough to the parent ecosystem to be operationally relevant, but distinct enough that it should not be automatically merged into the core roster without qualification.

The newly updated victimology materially improves the profile. Observed and reported activity links Chronus Jr.-associated operators to intrusion / data-leak activity affecting SEP Aguascalientes, the Secretariat of Health (DGDRH) in Aguascalientes, the Secretariat of Finance / Public Security in Oaxaca, and EDUCEM in Mexico. A further Argentina-linked case involves ReNPE (Relevamiento Nacional de Personal Educativo), where the observed attribution pattern placed h3 | Chronus Jr alongside Sh3llhunter | Chronus Team. ReNPE is an official national educational personnel survey platform that processes identity, employment, and education-related data on teachers and non-teaching staff, making this target socially and administratively sensitive.

From an intelligence standpoint, Chronus Jr. matters because it helps explain how the wider Chronus ecosystem may scale operations, segment branding, or distribute activity across related but distinct labels. The group’s apparent role is consistent with an operator-layer or junior / parallel unit model rather than an independently documented high-end intrusion set.

Source grading note used in this section only: source reliability and information credibility follow the classic A1–F6 format. Example: B2 means a usually reliable source and information probably true but not fully confirmed. OSINT and HUMINT are explicitly separated below whenever material value exists.

Created by iQBlack CTI Team
Contributors 1
Last updated 2026-08-21