ZeroHour
Story · 1 source · 3 articlesfirst updated ()

Unit 42 Ties Claude and GPT-4.1 Use to Latin American Intrusion Campaigns; SPIFFE/SPIRE Spoofing Research and 2026 Security Tool Buyer's Guides Round Out Coverage

highIndustryimportance 74
What's new: Sophos completed its acquisition of Secureworks for approximately $859 million in February 2025, consolidating competing vendors (Secureworks Taegis remains among compared managed XDR providers).
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Palo Alto Networks Unit 42 identified two LLM-assisted activity clusters — CL-CRI-1131 (Mexico/Ecuador government, transport and water utilities) and CL-CRI-1163 (Brazilian financial firms) — whose operators used Claude and GPT-4.1 via an exposed NextChat…

Palo Alto Networks Unit 42 identified two activity clusters in Latin America, CL-CRI-1131 and CL-CRI-1163, tied by shared SOCKS5 relay infrastructure and the use of commercial LLMs during operations. An exposed self-hosted NextChat interface on attacker infrastructure led researchers to assess that operators used Claude and GPT-4.1 to generate workaround scripts and troubleshoot execution failures; Unit 42 noted AI reduced post-initial-access troubleshooting time rather than replacing the attacker. CL-CRI-1131 compromised a transportation organization, Mexican federal ministries, and water utilities in Mexico and Ecuador, using living-off-the-land batch scripting and Volume Shadow Copies to dump the SAM registry hive and NTDS.dit. CL-CRI-1163 targeted Brazilian financial organizations with job-themed phishing (described as resume-themed in one report), custom remote-access Trojans, and SockTz, a Go-based reverse SOCKS5 tunneling utility deployed in nine versions within roughly two hours. Trend Micro tracks related AI-augmented activity as SHADOW-AETHER-040 and SHADOW-AETHER-064. Defenders are advised to watch for shadow-copy activity, SAM/NTDS.dit access, numbered script creation, anomalous SOCKS5 tunnels, and dynamic-DNS connections. In separate machine-identity research, Unit 42 showed that root access on a Kubernetes node enables spoofing of cgroup metadata used in SPIRE workload attestation, tricking it into issuing a co-located workload's SVIDs (X.509 and JWT) to an attacker-controlled process; the technique has not been observed in the wild, and the open-source Spooffe tool was released for assessing identity exposure. Six GBHackers buyer's guides published alongside this coverage compare twelve platforms each across XDR, MDR, MXDR, UEM, MDM and patch management, repeatedly flagging industry consolidation: Sophos completed its approximately $859 million acquisition of Secureworks in February 2025, and Arctic Wolf closed its purchase of BlackBerry's Cylance endpoint assets the same month.

  • Unit 42 tracks two LLM-assisted clusters: CL-CRI-1131 (Mexico/Ecuador: transportation organization, Mexican federal ministries, water utilities) and CL-CRI-1163 (Brazilian financial organizations), tied by overlapping SOCKS5 relay…
  • An exposed self-hosted NextChat interface on attacker infrastructure revealed use of Claude and GPT-4.1 for script generation and troubleshooting; Unit 42 assessed AI shortened troubleshooting time after initial access without replacing…
  • CL-CRI-1131 used living-off-the-land batch scripting and Volume Shadow Copies to dump the SAM registry hive and NTDS.dit, iterating numbered scripts.
  • CL-CRI-1163 used job-themed phishing (one source says resume-themed), custom RATs, and SockTz, a Go-based reverse SOCKS5 tunneling tool; versions 1-9 were deployed within roughly two hours, suggesting model-assisted development.
  • Trend Micro tracks related AI-augmented activity as SHADOW-AETHER-040 and SHADOW-AETHER-064.
  • Recommended detections: shadow-copy activity, SAM/NTDS.dit access, numbered script creation, anomalous SOCKS5 tunnels, and dynamic-DNS connections.
  • Unit 42 demonstrated that root on a Kubernetes node enables spoofing of Linux cgroup metadata used in SPIRE workload attestation, allowing an attacker-controlled process to obtain co-located workloads' SVIDs (X.509 and JWT).
  • The SPIFFE/SPIRE technique has not been observed exploited in the wild; Unit 42 released the open-source Spooffe tool and recommends hardening nodes, restricting root, prohibiting privileged containers, and minimizing weak selectors.

Coverage timeline

  1. · 7d ago
    GBHackers· 14
    The 12 Best Extended Detection & Response (XDR) Platforms, Compared and Priced

    Buyer's guide compares 12 XDR platforms, favoring Microsoft Defender XDR, Stellar Cyber and CrowdStrike, and warns ingestion pricing inflates costs.

  2. · 7d ago
    GBHackers· 15
    The 12 Best Managed Detection & Response (MDR) Services, Compared and Priced

    Buyer's guide compares 12 MDR services, naming Huntress best value, CrowdStrike Falcon Complete for response authority and Expel for transparency.

  3. · 7d ago
    GBHackers· 15
    The 12 Best Managed XDR Services, Compared and Priced

    A comparison of twelve managed XDR providers covering pricing models, telemetry breadth, and distinguishing genuine MXDR from rebranded MDR services.