CYBER DELTA FORCESearch

Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America

Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations.

CDF News DeskPalo Alto Unit 423 Sept 2026, 3:30 pm
Image courtesy of Palo Alto Unit 42. Original report
CDF REPORT

Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations. We have analyzed two ongoing, multi-stage network intrusion and data-exfiltration campaigns targeting organizations in Latin America. We track them as two separate activity clusters with distinct geographic focuses. However, the technical and behavioral overlaps between CL-CRI-1131 and CL-CRI-1163 highlight shifting trends in Latin American targeting and threat actor tooling.

Exposed staging infrastructure revealed operational scripts with filenames that suggest an LLM dynamically generated them rather than a human developer. Exposed staging directories, unsecured NextChat interfaces and structured multi-SAN certificates provide defenders with a clear roadmap of the attacker's infrastructure.

This suggests that the attackers employed iterative, language model-driven development: exploit_creative.py, exploit_careful.py and rce_focused.py .

This occurred while the attacker used a series of numbered batch scripts to collect sensitive data from the compromised host, as shown in Figure 2. Table 2 shows, by date, the certificates and hosts used for CL-CRI-1131 activity, demonstrating a timeline for the associated infrastructure. The IP address 178.128.87[.]160 was used in CL-CRI-1131 activity during the associated April and June 2026 compromises. This address hosted an instance of the open-source tool NextChat on TCP port 3000.

What changed

Pivoting on 62.171.185[.]97 , the IP address used in CL-CRI-1131 activity for data exfiltration, we discovered an active Let's Encrypt TLS certificate using the domain m-doxa-apodo.duckdns[.]org and following a unique dynamic DNS naming standard.

These reports describe attackers using multiple LLMs, including Claude and GPT-4.1 to troubleshoot issues faced by the attackers across their campaigns.

We observe an identical technical setup when pivoting to a secondary campaign targeting the Brazilian financial sector.

Where previous reports identified different versions of this tool across campaigns, we observed installation attempts of versions 1–9 in a two-hour window.

Similar to the SockTz version numbers and the CL-CRI-1131 operations, the open directory associated with this CL-CRI-1163 activity exposed iterative scripts with appended identifier _output , indicating the attackers employed LLMs throughout the campaign.

Who is affected

Figure 3 shows an example of the associated NextChat user interface, as it would look from a web browser window.

NextChat is an open-source web interface where users can load and interact with multiple models.

Researchers previously identified this SockTz proxy tool and 167.148.195[.]53 tied to persistent targeting of vulnerable JBoss servers.

CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors.

Why this matters

Exposed staging infrastructure revealed operational scripts with filenames that suggest an LLM dynamically generated them rather than a human developer.

Exposed staging directories, unsecured NextChat interfaces and structured multi-SAN certificates provide defenders with a clear roadmap of the attacker's infrastructure.

The technical picture

This suggests that the attackers employed iterative, language model-driven development: exploit_creative.py, exploit_careful.py and rce_focused.py .

How organizations are responding

This occurred while the attacker used a series of numbered batch scripts to collect sensitive data from the compromised host, as shown in Figure 2.

Table 2 shows, by date, the certificates and hosts used for CL-CRI-1131 activity, demonstrating a timeline for the associated infrastructure.

The IP address 178.128.87[.]160 was used in CL-CRI-1131 activity during the associated April and June 2026 compromises.

This address hosted an instance of the open-source tool NextChat on TCP port 3000.

After attackers dropped multiple RATs, we observed a similar iterative naming structure, likely due to the attackers' failure to install their tool set.

We observed attempts to install versions 1–8 of a Go-based reverse SOCKS5 tunneling tool named SockTz from a compromised WordPress site.

What to watch next

Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.

MORE IN DATA BREACHES

More cybersecurity reporting

240,000 Hit by Data Breach at Japan’s Digital AgencySecurityWeek · 15 Sept 2026, 5:15 pmTelegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML ExportsThe Hacker News · 14 Sept 2026, 11:28 pmPro-Ukraine Hacking Cat group deploying new malware against Russian targetsThe Record · 14 Sept 2026, 9:45 pmPersonal, Financial Info Exposed in Revolut Data BreachSecurityWeek · 14 Sept 2026, 6:33 pm