Skip to main content
Emerging ThreatsMalware & Ransomware

AI-Powered Attacks Target Latin America With Advanced Proxy Networks

Cramped electrical room with industrial control systems and computers.

"During an April 2026 compromise, the attacker’s host-based operations reflected the trial and error of LLM usage," Palo Alto Networks' Unit 42 reports — a concise description that captures both the technique and the weakness exposed by two ongoing intrusion campaigns across Latin America.

CL-CRI-1131: Mexican transportation, federal ministries and municipal water utilities

Unit 42 tracks a multi-stage intrusion cluster as CL-CRI-1131. The cluster impacted a transportation organization and targeted federal government ministries and municipal water utilities in Mexico and Ecuador. Operators relied heavily on living-off-the-land techniques, running iterative, numbered batch scripts to collect and exfiltrate sensitive files. Unit 42 observed the attackers attempting to dump the SAM registry hive and the domain controller NTDS.dit file, then creating shadow copies across multiple drives before copying files — a sequence the analysts tie to iterative troubleshooting supported by large language models (LLMs).

Infrastructure pivoting in CL-CRI-1131 included connectivity to 62.171.185[.]97 for data exfiltration and an active Let’s Encrypt certificate covering m-doxa-apodo.duckdns[.]org and related subdomains. Unit 42 notes that the m-doxa prefix first appeared in February 2026 and that the operators rotated infrastructure and generated new multi-Subject Alternative Name (SAN) certificates in April and June 2026.

CL-CRI-1163: Brazilian financial sector, SockTz and custom RATs

Unit 42 tracks a separate activity cluster, CL-CRI-1163, focused on the Brazilian financial sector. That campaign began with a resume- or job-themed phishing initial access vector in February 2026, followed by the deployment of custom remote access Trojans and tunneling tools. Researchers observed attempts to install a Go-based reverse SOCKS5 tunneling tool named SockTz across versions 1–9 within a roughly two‑hour window, including the execution attempt of socktz_v8.exe and a retrieval of socktz_v9 from hxxp[:]//167.148.195[.]53:8888/socktz_v9.exe.

Unit 42 found an open directory on 167.148.195[.]53 hosting SockTz installers and hundreds of campaign scripts. Filenames and iterative numbering in the directory — such as exploit_creative.py, exploit_careful.py and rce_focused.py, and many files appended with an _output identifier — led Unit 42 to assess that LLMs were integrated into the attackers’ scripting and development workflow.

NextChat, commercial LLMs and the attackers’ operational model

Both clusters relied on AI orchestration via commercial LLMs. Unit 42 corroborates other reports that the operators used multiple LLMs — specifically naming Claude and GPT-4.1 in linked research — and deployed self-hosted tooling. An open instance of the open-source NextChat interface was observed at IP 178.128.87[.]160 on TCP port 3000, allowing the attackers to load and interact with multiple models on attacker-controlled infrastructure.

Unit 42 links the attackers’ trial-and-error scripts and iterative fixes to LLM-driven troubleshooting. In CL-CRI-1131, the presence of NextChat and visible prompt histories on a backend server provided the analysts with a window into the attackers’ playbook and the specific workarounds that enabled extraction of Active Directory data.

Exposed OpSec: certificates, open directories and public NextChat UIs

Despite using advanced proxy networks and AI, the operators left staging infrastructure exposed. Unit 42 highlights several concrete OpSec failures that yielded breadcrumbs for defenders: publicly accessible NextChat interfaces, open directories with hundreds of scripts, dynamic DNS domains using duckdns[.]org (including m-doxa-apodo.duckdns[.]org, m-doxa-geo.duckdns[.]org, m-doxa-intel.duckdns[.]org, m-doxa-repuve.duckdns[.]org, m-doxa-sre.duckdns[.]org and m-doxa-vacunas.duckdns[.]org), and structured multi-SAN Let’s Encrypt certificates used and rotated in February, April and June 2026.

Unit 42 published certificate SHA-256 fingerprints associated with hosts such as 178.128.87[.]160 and 165.22.184[.]26, and included file SHA-256 hashes tied to payloads and artifacts. Those exposed elements — the analysts argue — provide defenders with a clear roadmap to track and disrupt activity.

What this means for technologists, policymakers, and affected enterprises

  • Technologists and security teams: Public-facing staging infrastructure — open NextChat instances, exposed script directories and rotated multi-SAN certificates — are concrete forensic targets. Unit 42 demonstrates that pivoting on those artifacts can reveal prompt histories, toolchains and staging hosts used for exfiltration.
  • Policymakers and regulators: The campaigns underscore how attackers combine free services (dynamic DNS, Let’s Encrypt certificates) with commercial LLMs to scale operations. Observers may note the operational pattern of rapid certificate rotation and reused naming conventions that signal malicious infrastructure.
  • Affected enterprises and procurement leaders: The contrast between homegrown malware (CL-CRI-1163) and living-off-the-land scripts (CL-CRI-1131) shows that both custom implants and native utilities can be orchestrated by the same AI-enabled backend; defenders should treat exposed staging artifacts as high-value indicators for incident response.

Unit 42 concludes that AI has become a force multiplier for several Latin America–focused threat clusters: it accelerates exploit-script development, helps work around tactical failures and lowers the skill barrier for orchestration — but it also concentrates sensitive operational data on attacker-controlled infrastructure. Those exposures — from NextChat prompt histories to open directories and certificate timelines — remain the most reliable way for defenders to track and disrupt these campaigns.

Read the original Unit 42 report: https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/