ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

Unit 42: Attackers Used Claude and GPT-4.1 via Exposed NextChat Interface to Automate Post-Exploitation in Latin America Campaigns

highThreat actorexploited in the wildimportance 74
What's new: Initial merged coverage (both reports dated 2026-09-10): first reporting of Unit 42's disclosure of LLM-assisted post-exploitation in Latin America, introducing cluster identifiers CL-CRI-1131 and CL-CRI-1163, the SockTz tunneling tool (nine versions in ~two hours), the exposed NextChat interface evidencing Claude/GPT-4.1 use, and Trend Micro's SHADOW-AETHER-040/064 tracking.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Palo Alto Networks Unit 42 identified two Latin American campaigns — CL-CRI-1131 against a transportation organization, Mexican federal ministries, and water utilities in Mexico and Ecuador, and CL-CRI-1163 against Brazilian financial firms — whose operators…

Both outlets (GBHackers and Cyber Security News, 2026-09-10) report on Unit 42's identification of two activity clusters, CL-CRI-1131 and CL-CRI-1163, tied by shared/overlapping SOCKS5 relay infrastructure and use of large language models during operations. CL-CRI-1131 targeted a transportation organization, Mexican federal ministries, and water utilities in Mexico and Ecuador, using living-off-the-land batch scripting, native Windows tools, and Volume Shadow Copies to dump the SAM registry hive and NTDS.dit. CL-CRI-1163 targeted Brazilian financial organizations with job/resume-themed phishing, custom remote-access Trojans, and SockTz, a Go-based reverse SOCKS5 tunneling utility, deploying nine versions (1-9) within roughly two hours — which Unit 42 suggests points to model-assisted development. An exposed self-hosted NextChat interface and open directories on attacker infrastructure led researchers to assess the operators used Claude and GPT-4.1 to generate workaround scripts and troubleshoot execution failures; Unit 42 noted AI reduced the time needed to troubleshoot intrusions after initial access rather than replacing the attacker. Trend Micro separately tracks related AI-augmented activity as SHADOW-AETHER-040 and SHADOW-AETHER-064. Defenders are advised to monitor shadow-copy activity, SAM/NTDS.dit access, numbered script creation, anomalous SOCKS5 tunnels, and dynamic-DNS connections.

  • Unit 42 tracks two clusters: CL-CRI-1131 (Mexico/Ecuador: transportation organization, Mexican federal ministries, water utilities) and CL-CRI-1163 (Brazil financial sector), tied by overlapping/shared SOCKS5 relay infrastructure.
  • An exposed self-hosted NextChat interface and open directories on attacker infrastructure led Unit 42 to assess operators used commercial LLMs Claude and GPT-4.1 to generate workaround scripts and troubleshoot execution failures.
  • CL-CRI-1131 used living-off-the-land batch scripting, native Windows tools, and Volume Shadow Copies to dump the SAM registry hive and NTDS.dit.
  • CL-CRI-1163 used job/resume-themed phishing, custom remote-access Trojans, and SockTz, a Go-based reverse SOCKS5 tunneling utility; versions 1-9 were deployed within roughly two hours, suggesting model-assisted development.
  • Unit 42 assessed that AI reduced the time needed to troubleshoot intrusions after initial access rather than replacing the attacker.
  • Trend Micro tracks related AI-augmented activity as SHADOW-AETHER-040 and SHADOW-AETHER-064.
  • Defenders should watch for shadow-copy activity, SAM/NTDS.dit access, numbered script creation, anomalous SOCKS5 tunnels, and dynamic-DNS connections.

Coverage timeline

  1. · 6d ago
    GBHackers· 58
    Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America

    Unit 42 says Latin American attackers used LLMs to automate post-exploitation in campaigns hitting Mexican government, water utilities, and Brazilian financial firms.

  2. · 6d ago
    Cyber Security News· 74
    Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks

    Unit 42 links two Latin America campaigns where operators used Claude and GPT-4.1 during intrusions against government and financial targets.