securityonline.info 9 Sept 2026, 00:04 UTC

AI-Assisted Attacks Target Latin American Transport and Banks

AI-Assisted Attacks Target Latin American Transport and Banks
CyberSIXT Evidence Panel Source marked as original reporting

PALO Alto Networks Unit 42 reports two AI-assisted intrusion campaigns targeting Latin American organisations, with activity spanning Mexico, Ecuador and Brazil. In both cases, attackers leveraged commercial large language models to script or enhance toolchains and post-exploitation steps, and exposed infrastructure that researchers used to trace the operations.

The two clusters are CL-CRI-1131, which struck a Mexican transportation firm and reached federal ministries and water utilities in Mexico and Ecuador, and CL-CRI-1163, which targeted the Brazilian financial sector. The campaigns are described as multi-stage intrusions culminating in data exfiltration, with AI used to generate workaround scripts and refine the attacks.

In the Mexican transportation campaign, the attackers attempted repeated data dumps of SAM hive and NTDS[.]dit files, then created shadow copies across drives, with exfiltration traffic traced to a server hosting NextChat on port 3000. NextChat—an open-source interface for running multiple AI models—was used to generate the required workaround scripts according to Unit 42.

The Brazilian campaign relied on custom malware rather than built‑in tools; the attackers gained access via a resume-themed phishing email and attempted to install multiple versions of a Go-based SOCKS5 proxy named SockTz. An exposed directory revealed hundreds of scripts with names such as exploit_creative.py and rce_focused.py, described as indicative of iterative, language model–driven development.

The operators share overlapping SOCKS5 relay infrastructure and rely on commercial LLMs, though attribution remains at the cluster level rather than to named groups. Defenders are urged to monitor for certutil abuse, rogue SOCKS5 proxies and unexpected NextChat instances, with strong logging and network segmentation as key mitigations.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline