<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/attackers-expose-ongoing-ai-tool-use-targeting-organizations-in-latin-america-qe4viyqpt" -->

---
title: Attackers Expose Ongoing AI Tool Use Targeting...
description: Unit 42 researchers detail two ongoing intrusion campaigns in Latin America, CL-CRI-1131 targeting Mexican transportation and government entities, and...
canonical: https://daily.dev/posts/attackers-expose-ongoing-ai-tool-use-targeting-organizations-in-latin-america-qe4viyqpt
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America | daily.dev
og:description: Unit 42 researchers detail two ongoing intrusion campaigns in Latin America, CL-CRI-1131 targeting Mexican transportation and government entities, and...
og:url: https://daily.dev/posts/attackers-expose-ongoing-ai-tool-use-targeting-organizations-in-latin-america-qe4viyqpt
og:image: https://api.daily.dev/og/posts/QE4viyqPt.png
og:image:alt: Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America

**[Unit 42](https://daily.dev/sources/unit42)** · 10 min read · 0 upvotes · 0 comments

## Summary

Unit 42 researchers detail two ongoing intrusion campaigns in Latin America, CL-CRI-1131 targeting Mexican transportation and government entities, and CL-CRI-1163 targeting Brazilian financial institutions. Both clusters show attackers integrating commercial LLMs (Claude, GPT-4.1) via self-hosted NextChat instances and iteratively-named scripts to troubleshoot exfiltration and proxy tooling, including a Go-based SOCKS5 tool called SockTz with version numbers 1-9. Despite the AI-enhanced tradecraft, attackers exposed open directories, unsecured NextChat interfaces, and multi-SAN TLS certificates, giving defenders a clear path to track and disrupt operations through basic OpSec failures.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs>

## Questions this post answers

### How are threat actors in Latin America using AI tools like NextChat during cyberattacks?

Attackers self-host NextChat, an open-source web interface for interacting with multiple LLMs, on their command-and-control infrastructure to compare model outputs and troubleshoot failed exfiltration scripts. In the CL-CRI-1131 campaign targeting Mexican organizations, attackers used NextChat alongside Claude and GPT-4.1 to iteratively generate batch scripts after repeated failures dumping SAM and NTDS.dit files.

_Security teams tracking AI-enabled attack tradecraft can follow evolving threat research on daily.dev._

### What is the SockTz tool used in the Brazilian financial sector attacks?

SockTz is a Go-based reverse SOCKS5 tunneling tool that attackers behind the CL-CRI-1163 campaign attempted to install on compromised systems, cycling through versions 1 through 9 within a two-hour window due to repeated installation failures. It was hosted on a compromised WordPress site and later retrieved from attacker-controlled infrastructure, and researchers previously linked it to attacks on vulnerable JBoss servers.

_Analysts comparing evolving proxy and tunneling malware can track these developments on daily.dev._

### How did operational security failures expose the AI-assisted Mexican government breach campaign?

Attackers left an open directory and an unsecured NextChat instance publicly accessible on IP 178.128.87.160, exposing their prompt history, staging scripts, and full playbook to researchers. Combined with a structured multi-SAN TLS certificate naming convention on duckdns.org subdomains revealing intended targets like vaccine registries and geolocation services, these OpSec lapses let defenders map and disrupt the campaign.

_Defenders hunting for exposed C2 infrastructure and cert-based indicators can follow this research on daily.dev._

## Similar posts on daily.dev

- [Chinese Cyber Threat Lurks In Critical Asian Sectors for Years](https://daily.dev/posts/chinese-cyber-threat-lurks-in-critical-asian-sectors-for-years-8fwvgxfsv) · Dark Reading · 0 upvotes · 0 comments
- [Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America](https://daily.dev/posts/vibe-hacking-two-ai-augmented-campaigns-target-government-and-financial-sectors-in-latin-america-djlzgrs4o) · Trend Micro · 0 upvotes · 0 comments
- [AI helps Chinese-speaking hackers speed up attacks on exposed servers](https://daily.dev/posts/ai-helps-chinese-speaking-hackers-speed-up-attacks-on-exposed-servers-os1x7amnl) · CSO Online · 1 upvotes · 0 comments
- [An Investigation Into Years of Undetected Operations Targeting High-Value Sectors](https://daily.dev/posts/an-investigation-into-years-of-undetected-operations-targeting-high-value-sectors-y5ptdykz6) · Unit 42 · 0 upvotes · 0 comments

---

Tags: [#malware](https://daily.dev/tags/malware), [#data-exfiltration](https://daily.dev/tags/data-exfiltration)

[View this post on daily.dev](https://daily.dev/posts/attackers-expose-ongoing-ai-tool-use-targeting-organizations-in-latin-america-qe4viyqpt)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America","url":"https://daily.dev/posts/attackers-expose-ongoing-ai-tool-use-targeting-organizations-in-latin-america-qe4viyqpt","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/attackers-expose-ongoing-ai-tool-use-targeting-organizations-in-latin-america-qe4viyqpt"},"datePublished":"2026-09-03T10:06:40.002Z","dateModified":"2026-09-03T11:21:56.983Z","description":"Unit 42 researchers detail two ongoing intrusion campaigns in Latin America, CL-CRI-1131 targeting Mexican transportation and government entities, and...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/0c98c3c5805b2733713030bbf5ed1a06?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/0c98c3c5805b2733713030bbf5ed1a06?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Unit 42","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Unit 42","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/5b55ca8d2ae04181939041fbc9d78160","url":"https://daily.dev/sources/unit42"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/attackers-expose-ongoing-ai-tool-use-targeting-organizations-in-latin-america-qe4viyqpt","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"malware,data-exfiltration","timeRequired":"PT10M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Unit 42","item":"https://daily.dev/sources/unit42"},{"@type":"ListItem","position":3,"name":"Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/attackers-expose-ongoing-ai-tool-use-targeting-organizations-in-latin-america-qe4viyqpt#faq","mainEntity":[{"@type":"Question","name":"How are threat actors in Latin America using AI tools like NextChat during cyberattacks?","acceptedAnswer":{"@type":"Answer","text":"Attackers self-host NextChat, an open-source web interface for interacting with multiple LLMs, on their command-and-control infrastructure to compare model outputs and troubleshoot failed exfiltration scripts. In the CL-CRI-1131 campaign targeting Mexican organizations, attackers used NextChat alongside Claude and GPT-4.1 to iteratively generate batch scripts after repeated failures dumping SAM and NTDS.dit files. Security teams tracking AI-enabled attack tradecraft can follow evolving threat research on daily.dev."}},{"@type":"Question","name":"What is the SockTz tool used in the Brazilian financial sector attacks?","acceptedAnswer":{"@type":"Answer","text":"SockTz is a Go-based reverse SOCKS5 tunneling tool that attackers behind the CL-CRI-1163 campaign attempted to install on compromised systems, cycling through versions 1 through 9 within a two-hour window due to repeated installation failures. It was hosted on a compromised WordPress site and later retrieved from attacker-controlled infrastructure, and researchers previously linked it to attacks on vulnerable JBoss servers. Analysts comparing evolving proxy and tunneling malware can track these developments on daily.dev."}},{"@type":"Question","name":"How did operational security failures expose the AI-assisted Mexican government breach campaign?","acceptedAnswer":{"@type":"Answer","text":"Attackers left an open directory and an unsecured NextChat instance publicly accessible on IP 178.128.87.160, exposing their prompt history, staging scripts, and full playbook to researchers. Combined with a structured multi-SAN TLS certificate naming convention on duckdns.org subdomains revealing intended targets like vaccine registries and geolocation services, these OpSec lapses let defenders map and disrupt the campaign. Defenders hunting for exposed C2 infrastructure and cert-based indicators can follow this research on daily.dev."}}]}
```

