INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Attackers Expose Ongoing AI Tool Use Targeting Latin American Orgs
| 2026-09-03 11:56 MEDIUM MEDIUM AI-ENABLED ATTACK
Executive Summary
AI-generated
Two ongoing, multi-stage network intrusion and data-exfiltration campaigns targeting organizations in Latin America have been identified. The attackers are believed to be behind these operations, leveraging artificial intelligence (AI) tools to enhance their capabilities. Approximately 2 distinct campaigns are affecting around 4 transportation organizations and government entities in Mexico and Ecuador, as well as an unknown number of financial institutions in Brazil. The attacks work by utilizing living-off-the-land techniques and self-hosted NextChat instances for data exfiltration, with attackers using AI to generate scripts and troubleshoot execution failures. As of the current time, the status of these campaigns is ongoing, with continued use of shared SOCKS5 infrastructure and reliance on commercial large language models like Claude and GPT-4.1 for operational orchestration.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
7d7669••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
87bf8b••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
46ac28••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
a38b2c••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
m-•••••.org
m-•••••.duckdns
m-•••••.org
m-•••••.duckdns
so•••••.exe
rc•••••.py
ex•••••.py
so•••••.exe
29eee8••••••••••••••••••••••••••
4e58c2••••••••••••••••••••••••••••••••••
hxxp://••••••••••••••••••••
167.148.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign
UnlikeCampaign
UnlikeCampaign
DomainsCampaign
DomainsCampaign
SHACampaign
SHAOperation EscaneoOperation Escaneo
Target & Sectors
EUROPE
EUROPE
LATAM
LATAM
MIDDLE_EAST
MIDDLE_EAST
NORTH_AMERICA
NORTH_AMERICA
energyenergy
financefinance
governmentgovernment
transportationtransportation
Incident Timeline
2026/09/03
Attackers used NextChat instances and custom-built SOCKS5 proxies to target organizations in Latin America, including Mexico and Brazil.
Click on any entity below to view its context and source!
organisation
NextChat
The Mexican transportation campaign (CL-CRI-1131) impacted transportation organizations and government entities in Mexico and Ecuador, utilizing living-off-the-land techniques and self-hosted NextChat instances.
infrastructure
Windows
Despite trading built-in Windows utilities for custom-built implants, the underlying operational shift remains consistent in both campaigns.
Whether manipulating built-in Windows utilities or deploying custom-built proxy networks, these operators rely on commercial LLMs to overcome tactical hurdles and streamline their execution.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
Despite trading built-in Windows utilities for custom-built implants, the underlying operational shift remains consistent in both campaigns.
Whether manipulating built-in Windows utilities or deploying custom-built proxy networks, these operators rely on commercial LLMs to overcome tactical hurdles and streamline their execution.
Intelligence Sources
Palo Alto
2026-09-03
AlienVault OTX
2026-09-03
AlienVault OTX
2026-09-03
AlienVault OTX
2026-09-04
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T11:07
Comprehensive Tactical Telemetry
Highly Correlated Entities
34x
organisation
Identified Entity
NextChat
entity
23x
tactic
MITRE ATT&CK Technique
T1588.002 - Tool
technique
9x
target region
Target Country
Mexico
country
7x
timeline
Temporal Reference
April 2026
date
5x
campaign
Campaign
Campaign
During
operation
4x
target region
Target Region
LATAM
region
3x
industry
Targeted Sector
Transportation
sector
3x
attribution
Attributing Entity
AI Integration: Discovering the Backend Troubleshooting Interface
authority
2x
tactic
Cyber Operation Type
Phishing
tactic
2x
general metric
+1
866
+1
2x
general metric
Version
8
version
Contextual Telemetry
Context Block
5 METRICS
general metric
Incident
42
incident
general metric
+65.6983.8730
50
+65.6983.8730
general metric
178.128.87[.]160
5
178.128.87[.]160
infrastructure
Affected Product
Windows
software
general metric
Tcp Port
3,000
tcp port
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.