Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America

0
Medium
Published: 09/03/2026 (09/03/2026, 12:45:15 UTC)
Source: AlienVault OTX General

Description

Two distinct multi-stage network intrusion campaigns are actively targeting Latin American organizations, with attackers leveraging artificial intelligence tools to enhance their capabilities. The Mexican transportation campaign (CL-CRI-1131) impacted transportation organizations and government entities in Mexico and Ecuador, utilizing living-off-the-land techniques and self-hosted NextChat instances. The Brazilian financial campaign (CL-CRI-1163) employed custom RATs and tunneling tools including a Go-based SOCKS5 proxy. Both operations demonstrate technical overlaps including shared SOCKS5 infrastructure and reliance on commercial large language models like Claude and GPT-4.1 for operational orchestration. Attackers used AI to generate scripts and troubleshoot execution failures, evidenced by iterative file naming patterns and exposed NextChat interfaces. However, fundamental operational security failures, including exposed staging directories and unsecured interfaces, provided defenders clear visibility...

Technical Details

Author
AlienVault
Tlp
white
References
["https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/"]
Adversary
null
Pulse Id
6a996bdbc61a482545ffaa1c
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip167.148.195.53

Domain

ValueDescriptionCopy
domainm-doxa-apodo.duckdns.org
domainm-doxa-geo.duckdns.org
domainm-doxa-intel.duckdns.org
domainm-doxa-vacunas.duckdns.org
domainm-doxa-repuve.duckdns.org
domainm-doxa-sre.duckdns.org

Hash

ValueDescriptionCopy
hash7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8
hash4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5
hash46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c
hasha38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996
hash87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec
hash29eee8a0e2c63360e361a0d462d30ae6
hash4e58c2617eeee39bb7492040f25d22d2eca263e1

Threat ID: 6a999eb6acd9273b492b004f

Added to database: 09/03/2026, 16:22:14 UTC

Last updated: 09/03/2026, 17:07:38 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses