Description

Palo Alto Networks Unit 42 identified two ongoing cyber campaigns, tracked as CL-CRI-1131 and CL-CRI-1163, targeting organizations across Latin America. The campaigns affected transportation, government, water utilities, and financial sectors in Mexico, Ecuador, and Brazil. Both operations demonstrate growing use of commercial large language models (LLMs) by attackers to generate scripts, troubleshoot technical problems, and accelerate post-exploitation activities. The campaigns shared SOCKS5 relay infrastructure and similar AI-assisted techniques. In CL-CRI-1131, attackers compromised a Mexican transportation organization and targeted government ministries and water utilities in Mexico and Ecuador. During an April 2026 intrusion, operators repeatedly attempted to extract SAM and NTDS.dit data before creating Volume Shadow Copies and executing numbered batch scripts to collect sensitive files. Repeated script modifications and troubleshooting suggested LLM assistance. Exfiltration activity was connected to attacker infrastructure hosting NextChat, an open-source interface for interacting with multiple AI models. Exposed TLS certificates and domains also helped researchers map the campaign’s infrastructure. CL-CRI-1163 targeted Brazil’s financial sector through a suspected resume-themed phishing attachment. Attackers deployed custom RATs and repeatedly attempted to install versions of a Go-based SOCKS5 proxy called SockTz. Versions one through eight were retrieved from a compromised WordPress site, while later versions came from attacker-controlled infrastructure. An exposed directory contained hundreds of scripts with filenames such as exploit_creative.py, exploit_careful.py, and rce_focused.py, indicating possible iterative, LLM-driven development. The exposed infrastructure revealed significant details about the attackers’ tools and workflows. The campaigns show that AI can significantly enhance attackers’ capabilities by helping overcome technical obstacles and automate complex tasks. However, weak operational security exposed their infrastructure, scripts, certificates, and activity history. Organizations should monitor for unauthorized SOCKS5 proxies, certutil abuse, suspicious scripts, unexpected NextChat deployments, and related indicators. Effective mitigation includes strong endpoint detection, centralized logging, network segmentation, timely vulnerability patching, phishing awareness, secure internet-facing systems, and continuous threat hunting to identify and disrupt similar AI-assisted intrusions.