<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>CL-CRI-1131 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cl-cri-1131/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 03 Sep 2026 12:00:52 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cl-cri-1131/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>AI-Assisted Multi-Stage Campaigns Targeting Latin American Organizations</title><link>https://feed.craftedsignal.io/briefs/2026-09-ai-assisted-latam-campaigns/</link><pubDate>Thu, 03 Sep 2026 12:00:52 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-ai-assisted-latam-campaigns/</guid><description>Two distinct activity clusters (CL-CRI-1131 and CL-CRI-1163) are leveraging LLMs via hosted NextChat instances to troubleshoot and refine post-exploitation scripts and exfiltration infrastructure against entities in the Latin American transportation, government, and financial sectors.</description><content:encoded><![CDATA[<p>Unit 42 researchers identified two significant activity clusters, CL-CRI-1131 and CL-CRI-1163, targeting Latin American organizations. CL-CRI-1131 focuses on transportation, government ministries, and municipal utilities in Mexico and Ecuador, utilizing living-off-the-land techniques and self-hosted NextChat instances for real-time AI-assisted troubleshooting. CL-CRI-1163 targets the Brazilian financial sector using custom Go-based RATs and SOCKS5 proxy tools (e.g., 'SockTz'). Both clusters demonstrate a sophisticated operational shift: attackers are integrating commercial Large Language Models (LLMs) into their post-exploitation workflow. This integration is evidenced by the iterative, trial-and-error generation of batch scripts used to overcome technical hurdles in credential dumping and data collection. Attackers host these AI-interaction interfaces on their own infrastructure, allowing for seamless prompting and debugging during live intrusions. The use of unique dynamic DNS naming conventions and rotated multi-SAN certificates highlights a mature and evolving approach to maintaining persistent, stealthy exfiltration channels.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Initial access is established via job-themed phishing (CL-CRI-1163) or exploitation of vulnerable web servers (CL-CRI-1131).</li>
<li>Attackers perform host discovery and attempt to dump sensitive credentials including SAM and NTDS.dit.</li>
<li>Failures in manual extraction lead to the creation of volume shadow copies (vssadmin) to facilitate file access.</li>
<li>The operator initiates an LLM interface (NextChat on port 3000) to generate and debug iterative batch scripts for data collection.</li>
<li>Scripts are executed to stage data in local collection directories, verified by internal permissions checks.</li>
<li>Data is exfiltrated to attacker-controlled C2 infrastructure (e.g., 178.128.87.160) using TLS-encrypted channels.</li>
<li>Persistent access is maintained via custom Go-based SOCKS5 proxies like 'SockTz' for ongoing network relay.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The campaigns have successfully compromised federal government ministries, municipal water utilities, and financial institutions. These intrusions facilitate the exfiltration of sensitive intelligence and administrative credentials, potentially leading to long-term espionage and financial disruption within the targeted sectors.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification of unauthorized AI-interface tools and suspicious proxy activity within internal networks.</p>
<ul>
<li>Hunt for instances of 'NextChat' or similar web-based AI interfaces being hosted on internal or perimeter assets; investigate outbound TCP port 3000 activity.</li>
<li>Monitor for the execution of iterative batch scripts that utilize 'vssadmin' for volume shadow copy manipulation, often followed by unauthorized file movement.</li>
<li>Block the identified C2 infrastructure domains and IPs (e.g., m-doxa-*.duckdns.org) at the perimeter DNS and firewall level.</li>
<li>Investigate any unknown Go-compiled binaries on endpoints, particularly those with filenames matching the 'SockTz' naming convention.</li>
<li>Enable advanced URL filtering and DNS security to flag traffic to dynamic DNS services commonly utilized by these clusters.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>CL-CRI-1131</category><category>CL-CRI-1163</category><category>ai-threat</category><category>exfiltration</category><category>latam</category><category>socks5</category></item></channel></rss>