{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/latam/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["CL-CRI-1131","CL-CRI-1163","ai-threat","exfiltration","latam","socks5"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eUnit 42 researchers identified two significant activity clusters, CL-CRI-1131 and CL-CRI-1163, targeting Latin American organizations. CL-CRI-1131 focuses on transportation, government ministries, and municipal utilities in Mexico and Ecuador, utilizing living-off-the-land techniques and self-hosted NextChat instances for real-time AI-assisted troubleshooting. CL-CRI-1163 targets the Brazilian financial sector using custom Go-based RATs and SOCKS5 proxy tools (e.g., 'SockTz'). Both clusters demonstrate a sophisticated operational shift: attackers are integrating commercial Large Language Models (LLMs) into their post-exploitation workflow. This integration is evidenced by the iterative, trial-and-error generation of batch scripts used to overcome technical hurdles in credential dumping and data collection. Attackers host these AI-interaction interfaces on their own infrastructure, allowing for seamless prompting and debugging during live intrusions. The use of unique dynamic DNS naming conventions and rotated multi-SAN certificates highlights a mature and evolving approach to maintaining persistent, stealthy exfiltration channels.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial access is established via job-themed phishing (CL-CRI-1163) or exploitation of vulnerable web servers (CL-CRI-1131).\u003c/li\u003e\n\u003cli\u003eAttackers perform host discovery and attempt to dump sensitive credentials including SAM and NTDS.dit.\u003c/li\u003e\n\u003cli\u003eFailures in manual extraction lead to the creation of volume shadow copies (vssadmin) to facilitate file access.\u003c/li\u003e\n\u003cli\u003eThe operator initiates an LLM interface (NextChat on port 3000) to generate and debug iterative batch scripts for data collection.\u003c/li\u003e\n\u003cli\u003eScripts are executed to stage data in local collection directories, verified by internal permissions checks.\u003c/li\u003e\n\u003cli\u003eData is exfiltrated to attacker-controlled C2 infrastructure (e.g., 178.128.87.160) using TLS-encrypted channels.\u003c/li\u003e\n\u003cli\u003ePersistent access is maintained via custom Go-based SOCKS5 proxies like 'SockTz' for ongoing network relay.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe campaigns have successfully compromised federal government ministries, municipal water utilities, and financial institutions. These intrusions facilitate the exfiltration of sensitive intelligence and administrative credentials, potentially leading to long-term espionage and financial disruption within the targeted sectors.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of unauthorized AI-interface tools and suspicious proxy activity within internal networks.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eHunt for instances of 'NextChat' or similar web-based AI interfaces being hosted on internal or perimeter assets; investigate outbound TCP port 3000 activity.\u003c/li\u003e\n\u003cli\u003eMonitor for the execution of iterative batch scripts that utilize 'vssadmin' for volume shadow copy manipulation, often followed by unauthorized file movement.\u003c/li\u003e\n\u003cli\u003eBlock the identified C2 infrastructure domains and IPs (e.g., m-doxa-*.duckdns.org) at the perimeter DNS and firewall level.\u003c/li\u003e\n\u003cli\u003eInvestigate any unknown Go-compiled binaries on endpoints, particularly those with filenames matching the 'SockTz' naming convention.\u003c/li\u003e\n\u003cli\u003eEnable advanced URL filtering and DNS security to flag traffic to dynamic DNS services commonly utilized by these clusters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T12:00:52Z","date_published":"2026-09-03T12:00:52Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ai-assisted-latam-campaigns/","summary":"Two distinct activity clusters (CL-CRI-1131 and CL-CRI-1163) are leveraging LLMs via hosted NextChat instances to troubleshoot and refine post-exploitation scripts and exfiltration infrastructure against entities in the Latin American transportation, government, and financial sectors.","title":"AI-Assisted Multi-Stage Campaigns Targeting Latin American Organizations","url":"https://feed.craftedsignal.io/briefs/2026-09-ai-assisted-latam-campaigns/"}],"language":"en","title":"CraftedSignal Threat Feed - Latam","version":"https://jsonfeed.org/version/1.1"}