AI-Assisted Multi-Stage Campaigns Targeting Latin American Organizations
Two distinct activity clusters (CL-CRI-1131 and CL-CRI-1163) are leveraging LLMs via hosted NextChat instances to troubleshoot and refine post-exploitation scripts and exfiltration infrastructure against entities in the Latin American transportation, government, and financial sectors.
Unit 42 researchers identified two significant activity clusters, CL-CRI-1131 and CL-CRI-1163, targeting Latin American organizations. CL-CRI-1131 focuses on transportation, government ministries, and municipal utilities in Mexico and Ecuador, utilizing living-off-the-land techniques and self-hosted NextChat instances for real-time AI-assisted troubleshooting. CL-CRI-1163 targets the Brazilian financial sector using custom Go-based RATs and SOCKS5 proxy tools (e.g., 'SockTz'). Both clusters demonstrate a sophisticated operational shift: attackers are integrating commercial Large Language Models (LLMs) into their post-exploitation workflow. This integration is evidenced by the iterative, trial-and-error generation of batch scripts used to overcome technical hurdles in credential dumping and data collection. Attackers host these AI-interaction interfaces on their own infrastructure, allowing for seamless prompting and debugging during live intrusions. The use of unique dynamic DNS naming conventions and rotated multi-SAN certificates highlights a mature and evolving approach to maintaining persistent, stealthy exfiltration channels.
Attack Chain
- Initial access is established via job-themed phishing (CL-CRI-1163) or exploitation of vulnerable web servers (CL-CRI-1131).
- Attackers perform host discovery and attempt to dump sensitive credentials including SAM and NTDS.dit.
- Failures in manual extraction lead to the creation of volume shadow copies (vssadmin) to facilitate file access.
- The operator initiates an LLM interface (NextChat on port 3000) to generate and debug iterative batch scripts for data collection.
- Scripts are executed to stage data in local collection directories, verified by internal permissions checks.
- Data is exfiltrated to attacker-controlled C2 infrastructure (e.g., 178.128.87.160) using TLS-encrypted channels.
- Persistent access is maintained via custom Go-based SOCKS5 proxies like 'SockTz' for ongoing network relay.
Impact
The campaigns have successfully compromised federal government ministries, municipal water utilities, and financial institutions. These intrusions facilitate the exfiltration of sensitive intelligence and administrative credentials, potentially leading to long-term espionage and financial disruption within the targeted sectors.
Recommendation
Prioritize the identification of unauthorized AI-interface tools and suspicious proxy activity within internal networks.
- Hunt for instances of 'NextChat' or similar web-based AI interfaces being hosted on internal or perimeter assets; investigate outbound TCP port 3000 activity.
- Monitor for the execution of iterative batch scripts that utilize 'vssadmin' for volume shadow copy manipulation, often followed by unauthorized file movement.
- Block the identified C2 infrastructure domains and IPs (e.g., m-doxa-*.duckdns.org) at the perimeter DNS and firewall level.
- Investigate any unknown Go-compiled binaries on endpoints, particularly those with filenames matching the 'SockTz' naming convention.
- Enable advanced URL filtering and DNS security to flag traffic to dynamic DNS services commonly utilized by these clusters.
Immediate actions
Block listed C2 domains and IPs at the network perimeter
Threat Hunt
Search for network traffic to port 3000 on internal assets
Data: Netflow or firewall logs
Detection coverage 1
Detect Suspicious NextChat Web Interface Hosting
highDetects the hosting of NextChat or similar LLM web interfaces on internal hosts, often used by attackers to troubleshoot post-exploitation activities.
Detection queries are available on the platform. Get full rules →
Indicators of compromise
1
domain
3
ip
| Type | Value |
|---|---|
| ip | 62.171.185.97 |
| domain | m-doxa-apodo.duckdns.org |
| ip | 178.128.87.160 |
| ip | 167.148.195.53 |