Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
Two distinct multi-stage network intrusion campaigns are actively targeting Latin American organizations, with attackers leveraging artificial intelligence tools to enhance their capabilities. The Mexican transportation campaign (CL-CRI-1131) impacted transportation organizations and government entities in Mexico and Ecuador, utilizing living-off-the-land techniques and self-hosted NextChat instances. The Brazilian financial campaign (CL-CRI-1163) employed custom RATs and tunneling tools including a Go-based SOCKS5 proxy. Both operations demonstrate technical overlaps including shared SOCKS5 infrastructure and reliance on commercial large language models like Claude and GPT-4.1 for operational orchestration. Attackers used AI to generate scripts and troubleshoot execution failures, evidenced by iterative file naming patterns and exposed NextChat interfaces. However, fundamental operational security failures, including exposed staging directories and unsecured interfaces, provided defenders clear visibility...
Indicators of Compromise
- ip: 167.148.195.53
- domain: m-doxa-apodo.duckdns.org
- domain: m-doxa-geo.duckdns.org
- domain: m-doxa-intel.duckdns.org
- domain: m-doxa-vacunas.duckdns.org
- hash: 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8
- hash: 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5
- hash: 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c
- domain: m-doxa-repuve.duckdns.org
- domain: m-doxa-sre.duckdns.org
- hash: a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996
- hash: 87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec
- hash: 29eee8a0e2c63360e361a0d462d30ae6
- hash: 4e58c2617eeee39bb7492040f25d22d2eca263e1
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
Description
Two distinct multi-stage network intrusion campaigns are actively targeting Latin American organizations, with attackers leveraging artificial intelligence tools to enhance their capabilities. The Mexican transportation campaign (CL-CRI-1131) impacted transportation organizations and government entities in Mexico and Ecuador, utilizing living-off-the-land techniques and self-hosted NextChat instances. The Brazilian financial campaign (CL-CRI-1163) employed custom RATs and tunneling tools including a Go-based SOCKS5 proxy. Both operations demonstrate technical overlaps including shared SOCKS5 infrastructure and reliance on commercial large language models like Claude and GPT-4.1 for operational orchestration. Attackers used AI to generate scripts and troubleshoot execution failures, evidenced by iterative file naming patterns and exposed NextChat interfaces. However, fundamental operational security failures, including exposed staging directories and unsecured interfaces, provided defenders clear visibility...
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/"]
- Adversary
- null
- Pulse Id
- 6a996bdbc61a482545ffaa1c
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip167.148.195.53 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainm-doxa-apodo.duckdns.org | — | |
domainm-doxa-geo.duckdns.org | — | |
domainm-doxa-intel.duckdns.org | — | |
domainm-doxa-vacunas.duckdns.org | — | |
domainm-doxa-repuve.duckdns.org | — | |
domainm-doxa-sre.duckdns.org | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8 | — | |
hash4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5 | — | |
hash46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c | — | |
hasha38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996 | — | |
hash87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec | — | |
hash29eee8a0e2c63360e361a0d462d30ae6 | — | |
hash4e58c2617eeee39bb7492040f25d22d2eca263e1 | — |
Threat ID: 6a999eb6acd9273b492b004f
Added to database: 09/03/2026, 16:22:14 UTC
Last updated: 09/03/2026, 17:07:38 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.