Unit 42 analyzed two ongoing intrusion campaigns in Latin America (CL-CRI-1131 and CL-CRI-1163) where attackers leveraged commercial LLMs via self-hosted NextChat instances to generate scripts and troubleshoot execution failures. CL-CRI-1131 targeted Mexican transportation and government entities using living-off-the-land techniques, while CL-CRI-1163 targeted the Brazilian financial sector with custom RATs and a Go-based SOCKS5 proxy tool called SockTz. Both campaigns exhibited operational security failures, including exposed staging directories and multi-SAN certificates that revealed their infrastructure and intended targets.
AI-enabled attacks
2 posts
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America Describing attacks with crime script analysis The article introduces crime script analysis (CSA) as a narrative-driven technique for describing cyber attacks alongside or as an alternative to TTP-based frameworks like MITRE ATT&CK. Using a business email compromise (BEC) case study, the author demonstrates how AI can industrialize BEC attacks by automating reconnaissance and social engineering message generation. The article identifies specific intervention points across the seven-step BEC crime script where defenders can disrupt attacker workflows.