This report details two AI-assisted intrusion campaigns in Latin America: CL-CRI-1131 against Mexican transportation and government-related targets, and CL-CRI-1163 against Brazil’s financial sector. Attackers used living-off-the-land techniques, custom RATs, SOCKS5 tunneling tools, and exposed NextChat/LLM infrastructure to troubleshoot failures, stage scripts, and exfiltrate data. #CL-CRI-1131 #CL-CRI-1163 #NextChat #SockTz #Claude #GPT-4.1
Keypoints
- The article analyzes two ongoing, multi-stage intrusion and data-exfiltration campaigns in Latin America.
- CL-CRI-1131 targeted a transportation organization in Mexico, plus federal ministries and municipal water utilities in Mexico and Ecuador.
- CL-CRI-1131 relied heavily on living-off-the-land techniques, batch scripts, shadow copies, and data theft from SAM and NTDS.dit.
- CL-CRI-1131 infrastructure included dynamic DNS domains, multi-SAN TLS certificates, and a public NextChat instance used for LLM-assisted troubleshooting.
- CL-CRI-1163 targeted Brazil’s financial sector and began with a resume-themed phishing compromise.
- CL-CRI-1163 involved custom RATs and a Go-based reverse SOCKS5 tool called SockTz, with iterative filenames suggesting AI-generated development.
- Both clusters shared proxy infrastructure and operational signs of commercial LLM use, exposing weak OpSec that defenders can leverage.
MITRE Techniques
- [T1059.003] Windows Command Shell – The attackers used batch scripts and command-line execution to collect and manipulate data, including iterative script runs (‘series of numbered batch scripts to collect sensitive data’).
- [T1113] Screen Capture / Data Collection from Information Repositories – The operators attempted to dump sensitive registry and directory data such as SAM and NTDS.dit (‘repeated attempts to dump the Security Account Manager (SAM) registry hive and the domain controller NTDS.dit file’).
- [T1003.002] Security Account Manager – The attackers targeted the SAM registry hive to obtain credential material (‘dump the Security Account Manager (SAM) registry hive’).
- [T1003.003] NTDS – The attackers attempted to extract the domain controller database for credentials and directory data (‘the domain controller NTDS.dit file’).
- [T1490] Inhibit System Recovery – They created shadow copies across multiple drives to facilitate file access and copying (‘the attacker created shadow copies across multiple drives before copying files’).
- [T1053.005] Scheduled Task/Job: Scheduled Task – The article describes iterative batch-script execution and repeated scripted actions consistent with automated tasking (‘series of numbered batch scripts’).
- [T1090.001] Proxy: Internal Proxy – The attackers deployed and retried SOCKS5 tunneling/proxy tools to reach infrastructure and relay traffic (‘Go-based reverse SOCKS5 tunneling tool named SockTz’).
- [T1105] Ingress Tool Transfer – Attackers retrieved tools from compromised and attacker-controlled infrastructure (‘attempts to install versions 1–8 … from a compromised WordPress site’ and ‘retrieve version 9’).
- [T1583.001] Acquire Infrastructure: Domains – They used dynamic DNS domains and multi-subdomain infrastructure for campaign operations (‘m-doxa-apodo.duckdns[.]org’ and related subdomains).
- [T1583.006] Acquire Infrastructure: Web Services – The campaign relied on hosted web services such as NextChat on attacker-controlled servers (‘hosted an instance of the open-source tool NextChat on TCP port 3000’).
Indicators of Compromise
- [IP address] infrastructure and exfiltration hosts – 62.171.185[.]97, 178.128.87[.]160
- [IP address] certificate- and staging-related host – 165.22.184[.]26, 167.148.195[.]53
- [Domains] Mexican campaign infrastructure – m-doxa-apodo.duckdns[.]org, m-doxa-geo.duckdns[.]org, and 4 more domains
- [SHA-256 certificate hashes] TLS certificate fingerprints tied to CL-CRI-1131 infrastructure – 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c, 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5, and 1 more hash
- [SHA-256 file hashes] Brazilian campaign artifacts – a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996, 87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec
- [URL] SockTz downloader/installer location – hxxp[:]//167.148.195[.]53:8888/socktz_v9.exe
- [File names] observed in staging and execution – socktz_v8.exe, socktz_v9.exe, exploit_creative.py, exploit_careful.py, rce_focused.py
Read more: https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/