Affected Systems

Organizations in Latin America, specifically: Mexican transportation sector, federal government ministries, municipal water utilities in Mexico and Ecuador (CL-CRI-1131); Brazilian financial sector (CL-CRI-1163). Attackers use LLM tools (ChatGPT, Claude, NextChat) for operational orchestration, custom RATs, Go-based SOCKS5 proxies, and living-off-the-land techniques.

Exploitation Status

Active exploitation confirmed. Two distinct campaigns (CL-CRI-1131 and CL-CRI-1163) observed from February through June 2026. Attackers exposed due to operational security errors including exposed TLS certificates and infrastructure. Self-hosted NextChat instances and SOCKS5 relay infrastructure actively used for data exfiltration.

Business Impact

Multi-stage network intrusions with confirmed data exfiltration targeting critical infrastructure (government, utilities, transportation, financial services). Attackers demonstrated iterative trial-and-error behavior consistent with LLM-assisted operations, including SAM registry and NTDS.dit credential harvesting attempts. Infrastructure analysis revealed targeting profiles and operational timelines. Threat actors are evolving tactics by integrating commercial AI tools to streamline execution, indicating broader regional threat landscape shift.

Urgency

đźź  Within 24 hours

Recommended Actions

  • Monitor network traffic for connections to known C2 infrastructure: 62.171.185[.]97, 165.22.184[.]26, 178.128.87[.]160, and domains under m-doxa-*.duckdns[.]org
  • Hunt for numbered batch scripts executing volume shadow copy manipulation (vssadmin, wmic shadowcopy) and SAM/NTDS.dit extraction attempts in endpoint logs
  • Identify unauthorized NextChat instances or self-hosted LLM tools on corporate networks; block outbound connections to public AI services from sensitive systems
  • Review firewall and proxy logs for Go-based SOCKS5 proxy activity and unusual tunneling behavior, particularly to Latin American IP ranges
  • Engage Unit 42 Incident Response or equivalent for forensic analysis if transportation, government, utility, or financial sector operations in Latin America show indicators of compromise

---

# Geopolitical Context

Geopolitical Context

Two distinct but technically overlapping intrusion campaigns—CL-CRI-1131 and CL-CRI-1163—have targeted organizations across Latin America from February through June 2026, focusing on Mexican government entities, transportation infrastructure, and Brazilian financial institutions. The campaigns demonstrate an operational evolution in regional cyber threats, characterized by the integration of commercial large language models (LLMs) to streamline attack execution and the deployment of shared SOCKS5 proxy infrastructure for data exfiltration. The targeting of federal ministries, municipal utilities, and financial sector entities suggests actors with either economic motivations or intelligence collection objectives. Infrastructure naming conventions (including Spanish-language references to "vaccines" and "intelligence") and the geographic specificity of targeting indicate threat actors with regional familiarity and potentially localized operational priorities. The campaigns' reliance on living-off-the-land techniques and iterative scripting—consistent with AI-assisted code generation—reflects a democratization of advanced capabilities that may lower barriers to entry for regional threat actors.

State Actor Alignment

No state-level attribution is provided in the available reporting. The campaigns are tracked as distinct activity clusters (CL-CRI-1131 and CL-CRI-1163) without linkage to known advanced persistent threat (APT) groups or nation-state sponsors. The targeting profile—spanning government ministries, critical infrastructure (water utilities, transportation), and financial institutions—is consistent with both espionage and financially motivated cybercrime. The technical overlaps, including shared SOCKS5 infrastructure and parallel adoption of AI tooling, may indicate either coordinated operations by related actors or independent adoption of similar techniques within the Latin American threat ecosystem. The absence of clear state sponsorship markers suggests these may represent regional cybercriminal operations, though intelligence collection against government entities cannot be ruled out. No sanctions designations or formal government attributions appear to be associated with this activity at present.

Business Impacty pro region

The campaigns underscore growing cyber risk exposure across Latin America, particularly for government institutions and critical infrastructure operators with limited defensive maturity. Mexico and Brazil—the region's largest economies—face persistent targeting that threatens both national security equities and economic stability. The compromise of federal ministries and municipal utilities in Mexico, alongside financial sector intrusions in Brazil, highlights vulnerabilities in public-sector cybersecurity posture and the attractiveness of these targets for data theft and potential follow-on operations. For European and North American partners engaged in capacity-building and intelligence-sharing arrangements with Latin American governments, these incidents may complicate bilateral cooperation if sensitive information is compromised. The campaigns also reflect broader trends in the commoditization of offensive cyber capabilities: the use of commercial AI tools and readily available proxy infrastructure enables less sophisticated actors to conduct multi-stage intrusions previously associated with well-resourced APT groups. This capability diffusion may accelerate the frequency and impact of cyber incidents across the region, straining incident response resources and increasing systemic risk to interconnected financial and logistics networks.

Forecast

If threat actors continue to leverage operational security errors—such as exposed certificates and predictable infrastructure naming—defenders are likely to maintain visibility into campaign evolution and may achieve further disruption of ongoing operations. However, if attackers improve tradecraft and rotate infrastructure more frequently, detection and attribution will become more challenging. Should the technical overlaps between CL-CRI-1131 and CL-CRI-1163 indicate coordination rather than coincidence, a more organized threat ecosystem may be emerging in Latin America, potentially leading to increased targeting of regional critical infrastructure and cross-border operations. If commercial AI tools remain accessible and unregulated for offensive use, the barrier to entry for sophisticated intrusion campaigns will likely continue to decline, enabling a broader range of actors to conduct data exfiltration and espionage operations. Regional governments may face pressure to enhance public-sector cybersecurity investment and pursue multilateral frameworks for threat intelligence sharing. In the near term, organizations in Mexico, Brazil, and neighboring countries should anticipate continued targeting of government, financial, and transportation sectors, with particular risk to entities lacking robust endpoint detection and network segmentation capabilities.