At a Glance
| Threat clusters | CL-CRI-1131 and CL-CRI-1163 |
| Activity type | Network intrusion and data exfiltration, AI-assisted |
| Targets | Transportation, government, water utilities, financial sector |
| Jurisdiction | Mexico, Ecuador, and Brazil |
| Status | Ongoing; tracked by researchers, no arrests reported |
| Source | Palo Alto Networks Unit 42 |
TL;DR
Palo Alto Networks Unit 42 tracked two campaigns where AI-powered cyberattacks struck organizations across Latin America. Attackers used commercial large language models to write scripts and fix broken tools. Their own exposed infrastructure then leaked their playbook to researchers.
What Happened
Unit 42 analyzed two multi-stage intrusion and data-exfiltration campaigns. Both targeted organizations in Latin America. In each case, operators turned to AI to sharpen their attacks.
The researchers describe the pattern plainly. They observed “attackers leveraging artificial intelligence (AI) to enhance their capabilities.” That trend links two otherwise separate groups.
The first cluster, CL-CRI-1131, hit a Mexican transportation firm. It also reached federal ministries and water utilities in Mexico and Ecuador. The second, CL-CRI-1163, went after the Brazilian financial sector.

The Mexican Transportation Campaign
During an April 2026 breach, the attacker struggled to steal data. After repeated tries to dump the SAM hive and NTDS.dit file, they created shadow copies across drives. These trial-and-error fixes point to LLM use.
Researchers then traced exfiltration traffic to a server hosting NextChat on port 3000. NextChat is an open-source interface for running multiple AI models. Unit 42 assessed that the attackers “relied on LLMs to generate the required workaround scripts.”
The Brazilian Financial Campaign
The second group used custom malware instead of built-in tools. Attackers gained access through a resume-themed phishing email. They then tried to install versions 1 through 9 of a Go-based SOCKS5 proxy called SockTz.
An exposed open directory revealed hundreds of scripts. Filenames like exploit_creative.py and rce_focused.py suggest AI-driven development. As the report notes, this points to “iterative, language model-driven development.”
Who Is Behind It
Unit 42 tracks the two clusters as separate operations with distinct geographic focus. However, they share overlapping SOCKS5 relay infrastructure. Both also rely on commercial LLMs to run operations.
Attribution stops at cluster level, so no named group or suspect is confirmed. Earlier reporting from CloudSEK and Gambit covered related February 2026 activity. Unit 42 corroborates and expands on those findings in its full technical analysis of AI tool use targeting LATAM organizations.
Impact and Scale
The campaigns reached sensitive infrastructure across three countries. Affected sectors include transport, government, water, and finance. Exact victim counts and any financial losses remain unreported.
These AI-powered cyberattacks also show a wider shift. Even lower-skilled actors now use AI as a force multiplier. It helps them populate directories with exploit scripts and manage complex post-exploitation steps.
The Attackers’ Weak Spot
The AI edge came with a cost. Exposing an open NextChat directory revealed poor operational security. As Unit 42 put it, the operators “failed to secure the staging server.”
That mistake left prompt history, scripts, and certificates in plain view. Multi-SAN TLS certificates further mapped their infrastructure. Consequently, defenders gained a clear roadmap to track the activity.
What Comes Next
Expect more groups to fold AI into their workflows. Yet basic OpSec failures still expose them. Defenders can pivot on those mistakes to disrupt campaigns.
Organizations in the region should watch for the published indicators. Monitor for certutil abuse, rogue SOCKS5 proxies, and unexpected NextChat instances. Strong logging and network segmentation remain the best defense against these AI-powered cyberattacks.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!