ZeroHour
Story · 1 source · 1 articlefirst updated ()

Unit 42: Operators Used Claude and GPT-4.1 During Latin American Intrusion Campaigns Against Mexican Government, Water Utilities, and Brazilian Finance

highThreat actorexploited in the wildimportance 74
What's new: No contradictions introduced by the third report (Cyber Security News, 2026-09-10T08:06:02Z); it corroborates the previously merged findings. It adds Unit 42's assessment that AI shortened troubleshooting time after initial access rather than replacing the attacker, and restates SockTz versions 1-9 within roughly two hours and the Brazilian phishing as resume-themed (equivalent to GBHackers'…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Palo Alto Networks Unit 42 tracks two related AI-assisted intrusion clusters in Latin America — CL-CRI-1131 (a transportation organization, Mexican federal ministries, and water utilities; later write-ups also place some utilities in Ecuador) and CL-CRI-1163…

Palo Alto Networks Unit 42 documented two ongoing AI-assisted intrusion campaigns against Latin American organizations, tracked as clusters CL-CRI-1131 and CL-CRI-1163 and tied together by shared SOCKS5 relay infrastructure. CL-CRI-1131 compromised a transportation organization, Mexican federal ministries, and municipal water utilities; Unit 42's original report frames this campaign as Mexico-focused, while the GBHackers and Cyber Security News write-ups of the same research specify water utilities in Mexico and Ecuador. CL-CRI-1163 targeted Brazilian financial organizations using job-themed (also described as resume-themed) phishing, custom RATs, and a Go-based reverse SOCKS5 tunneling utility called SockTz, with nine versions (1-9) deployed within roughly two hours. In CL-CRI-1131, attackers used living-off-the-land native Windows tools and Volume Shadow Copies to dump the SAM registry hive and NTDS.dit, and exfiltrated sensitive data via dynamic-DNS infrastructure using rotated multi-SAN TLS certificates between February and June 2026; the certificate SANs exposed target profiles including geolocation, intel, and vaccines subdomains. Evidence of LLM involvement includes iterative, sequentially numbered batch scripts consistent with LLM trial-and-error, AI-style naming of tunneling tools, and exposed self-hosted NextChat instances and open directories revealing the attackers' staging environment and iterative, LLM-assisted script development; the commercial LLMs identified are Claude and GPT-4.1. Unit 42 assessed that AI reduced the time needed to troubleshoot intrusions after initial access rather than replacing the attacker. Vendor naming differs across reports: Unit 42 uses CL-CRI-1131 and CL-CRI-1163, CloudSEK calls the Mexican campaign Operation Escaneo, and Trend Micro tracks related AI-augmented activity as SHADOW-AETHER-040 and SHADOW-AETHER-064. Detection guidance from the reports: monitor Volume Shadow Copy activity, SAM/NTDS.dit access, sequentially numbered script creation, anomalous SOCKS5 tunnels, and dynamic-DNS connections.

  • Unit 42 tracks two intrusion clusters, CL-CRI-1131 and CL-CRI-1163, linked by shared SOCKS5 relay infrastructure.
  • CL-CRI-1131 compromised a transportation organization, Mexican federal ministries, and municipal water utilities; Unit 42 frames the campaign as Mexico-focused, while GBHackers and Cyber Security News specify water utilities in Mexico and…
  • CL-CRI-1163 targeted Brazilian financial organizations with job-themed/resume-themed phishing, custom RATs, and the Go-based reverse SOCKS5 tunneling tool SockTz; versions 1-9 were deployed within roughly two hours.
  • CL-CRI-1131 used living-off-the-land batch scripting and Volume Shadow Copies to dump the SAM registry hive and NTDS.dit.
  • The Mexican campaign exfiltrated sensitive data via dynamic-DNS infrastructure with rotated multi-SAN TLS certificates between February and June 2026; the SANs exposed target profiles (geolocation, intel, and vaccines subdomains).
  • Evidence of LLM use includes an exposed self-hosted NextChat interface and open directories on attacker infrastructure, iterative numbered batch scripts, and AI-generated tunneling tool naming; the LLMs identified are Claude and GPT-4.1.
  • Unit 42 assessed that AI reduced post-initial-access troubleshooting time rather than replacing the attacker.
  • Vendor naming differs: Unit 42 (CL-CRI-1131, CL-CRI-1163), CloudSEK (Operation Escaneo for the Mexican campaign), Trend Micro (SHADOW-AETHER-040 and SHADOW-AETHER-064 for related AI-augmented activity).

Coverage timeline

  1. · 13d ago
    Palo Alto Unit 42· 72
    Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America

    Unit 42 documents two AI-assisted intrusion campaigns against Latin American government, utility, and financial organizations using LLM-orchestrated tooling.