Unit 42: Attackers Used Claude and GPT-4.1 via Exposed NextChat Interface to Automate Post-Exploitation in Latin America Campaigns
Palo Alto Networks Unit 42 identified two Latin American campaigns — CL-CRI-1131 against a transportation organization, Mexican federal ministries, and water utilities in Mexico and Ecuador, and CL-CRI-1163 against Brazilian financial firms — whose operators…
Both outlets (GBHackers and Cyber Security News, 2026-09-10) report on Unit 42's identification of two activity clusters, CL-CRI-1131 and CL-CRI-1163, tied by shared/overlapping SOCKS5 relay infrastructure and use of large language models during operations. CL-CRI-1131 targeted a transportation organization, Mexican federal ministries, and water utilities in Mexico and Ecuador, using living-off-the-land batch scripting, native Windows tools, and Volume Shadow Copies to dump the SAM registry hive and NTDS.dit. CL-CRI-1163 targeted Brazilian financial organizations with job/resume-themed phishing, custom remote-access Trojans, and SockTz, a Go-based reverse SOCKS5 tunneling utility, deploying nine versions (1-9) within roughly two hours — which Unit 42 suggests points to model-assisted development. An exposed self-hosted NextChat interface and open directories on attacker infrastructure led researchers to assess the operators used Claude and GPT-4.1 to generate workaround scripts and troubleshoot execution failures; Unit 42 noted AI reduced the time needed to troubleshoot intrusions after initial access rather than replacing the attacker. Trend Micro separately tracks related AI-augmented activity as SHADOW-AETHER-040 and SHADOW-AETHER-064. Defenders are advised to monitor shadow-copy activity, SAM/NTDS.dit access, numbered script creation, anomalous SOCKS5 tunnels, and dynamic-DNS connections.
- Unit 42 tracks two clusters: CL-CRI-1131 (Mexico/Ecuador: transportation organization, Mexican federal ministries, water utilities) and CL-CRI-1163 (Brazil financial sector), tied by overlapping/shared SOCKS5 relay infrastructure.
- An exposed self-hosted NextChat interface and open directories on attacker infrastructure led Unit 42 to assess operators used commercial LLMs Claude and GPT-4.1 to generate workaround scripts and troubleshoot execution failures.
- CL-CRI-1131 used living-off-the-land batch scripting, native Windows tools, and Volume Shadow Copies to dump the SAM registry hive and NTDS.dit.
- CL-CRI-1163 used job/resume-themed phishing, custom remote-access Trojans, and SockTz, a Go-based reverse SOCKS5 tunneling utility; versions 1-9 were deployed within roughly two hours, suggesting model-assisted development.
- Unit 42 assessed that AI reduced the time needed to troubleshoot intrusions after initial access rather than replacing the attacker.
- Trend Micro tracks related AI-augmented activity as SHADOW-AETHER-040 and SHADOW-AETHER-064.
- Defenders should watch for shadow-copy activity, SAM/NTDS.dit access, numbered script creation, anomalous SOCKS5 tunnels, and dynamic-DNS connections.
Coverage timelineoldest first · each row is one article
- · 6d agoHackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America
GBHackers· 58
Unit 42 says Latin American attackers used LLMs to automate post-exploitation in campaigns hitting Mexican government, water utilities, and Brazilian financial firms.
- · 6d agoHackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks
Cyber Security News· 74
Unit 42 links two Latin America campaigns where operators used Claude and GPT-4.1 during intrusions against government and financial targets.