Unit 42: Operators Used Claude and GPT-4.1 During Latin American Intrusion Campaigns Against Mexican Government, Water Utilities, and Brazilian Finance
Palo Alto Networks Unit 42 tracks two related AI-assisted intrusion clusters in Latin America — CL-CRI-1131 (a transportation organization, Mexican federal ministries, and water utilities; later write-ups also place some utilities in Ecuador) and CL-CRI-1163…
Palo Alto Networks Unit 42 documented two ongoing AI-assisted intrusion campaigns against Latin American organizations, tracked as clusters CL-CRI-1131 and CL-CRI-1163 and tied together by shared SOCKS5 relay infrastructure. CL-CRI-1131 compromised a transportation organization, Mexican federal ministries, and municipal water utilities; Unit 42's original report frames this campaign as Mexico-focused, while the GBHackers and Cyber Security News write-ups of the same research specify water utilities in Mexico and Ecuador. CL-CRI-1163 targeted Brazilian financial organizations using job-themed (also described as resume-themed) phishing, custom RATs, and a Go-based reverse SOCKS5 tunneling utility called SockTz, with nine versions (1-9) deployed within roughly two hours. In CL-CRI-1131, attackers used living-off-the-land native Windows tools and Volume Shadow Copies to dump the SAM registry hive and NTDS.dit, and exfiltrated sensitive data via dynamic-DNS infrastructure using rotated multi-SAN TLS certificates between February and June 2026; the certificate SANs exposed target profiles including geolocation, intel, and vaccines subdomains. Evidence of LLM involvement includes iterative, sequentially numbered batch scripts consistent with LLM trial-and-error, AI-style naming of tunneling tools, and exposed self-hosted NextChat instances and open directories revealing the attackers' staging environment and iterative, LLM-assisted script development; the commercial LLMs identified are Claude and GPT-4.1. Unit 42 assessed that AI reduced the time needed to troubleshoot intrusions after initial access rather than replacing the attacker. Vendor naming differs across reports: Unit 42 uses CL-CRI-1131 and CL-CRI-1163, CloudSEK calls the Mexican campaign Operation Escaneo, and Trend Micro tracks related AI-augmented activity as SHADOW-AETHER-040 and SHADOW-AETHER-064. Detection guidance from the reports: monitor Volume Shadow Copy activity, SAM/NTDS.dit access, sequentially numbered script creation, anomalous SOCKS5 tunnels, and dynamic-DNS connections.
- Unit 42 tracks two intrusion clusters, CL-CRI-1131 and CL-CRI-1163, linked by shared SOCKS5 relay infrastructure.
- CL-CRI-1131 compromised a transportation organization, Mexican federal ministries, and municipal water utilities; Unit 42 frames the campaign as Mexico-focused, while GBHackers and Cyber Security News specify water utilities in Mexico and…
- CL-CRI-1163 targeted Brazilian financial organizations with job-themed/resume-themed phishing, custom RATs, and the Go-based reverse SOCKS5 tunneling tool SockTz; versions 1-9 were deployed within roughly two hours.
- CL-CRI-1131 used living-off-the-land batch scripting and Volume Shadow Copies to dump the SAM registry hive and NTDS.dit.
- The Mexican campaign exfiltrated sensitive data via dynamic-DNS infrastructure with rotated multi-SAN TLS certificates between February and June 2026; the SANs exposed target profiles (geolocation, intel, and vaccines subdomains).
- Evidence of LLM use includes an exposed self-hosted NextChat interface and open directories on attacker infrastructure, iterative numbered batch scripts, and AI-generated tunneling tool naming; the LLMs identified are Claude and GPT-4.1.
- Unit 42 assessed that AI reduced post-initial-access troubleshooting time rather than replacing the attacker.
- Vendor naming differs: Unit 42 (CL-CRI-1131, CL-CRI-1163), CloudSEK (Operation Escaneo for the Mexican campaign), Trend Micro (SHADOW-AETHER-040 and SHADOW-AETHER-064 for related AI-augmented activity).
Coverage timelineoldest first · each row is one article
- · 13d agoAttackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
Palo Alto Unit 42· 72
Unit 42 documents two AI-assisted intrusion campaigns against Latin American government, utility, and financial organizations using LLM-orchestrated tooling.