Unit 42 analyzed two ongoing intrusion campaigns in Latin America (CL-CRI-1131 and CL-CRI-1163) where attackers leveraged commercial LLMs via self-hosted NextChat instances to generate scripts and troubleshoot execution failures. CL-CRI-1131 targeted Mexican transportation and government entities using living-off-the-land techniques, while CL-CRI-1163 targeted the Brazilian financial sector with custom RATs and a Go-based SOCKS5 proxy tool called SockTz. Both campaigns exhibited operational security failures, including exposed staging directories and multi-SAN certificates that revealed their infrastructure and intended targets.
NextChat
1 post
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America