Attackers Leverage AI in Multi-Stage Cyber Campaigns Targeting Latin American Organizations

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

AI-Enhanced Cyber Campaigns Targeting Latin America: A Deep Dive

Recent investigations into multi-stage cyber campaigns targeting organizations in Latin America reveal a concerning trend: attackers are increasingly leveraging artificial intelligence (AI) to enhance their operational capabilities. This analysis focuses on two distinct campaigns—one targeting the transportation sector in Mexico and the other aimed at the financial sector in Brazil—both of which illustrate the evolving tactics of cybercriminals in the region. For a detailed overview, refer to the findings published by Palo Alto Networks’ Unit 42 team here.

Mexican Transportation Campaign: CL-CRI-1131

The first campaign, designated CL-CRI-1131, primarily affected a transportation organization along with various federal ministries and municipal water utilities in Mexico and Ecuador. Attackers employed living-off-the-land (LotL) techniques, utilizing existing system tools to execute their operations. Notably, they executed iterative batch scripts to manipulate and exfiltrate sensitive data, while also hosting instances of NextChat on their operational infrastructure.

Execution Challenges and Infrastructure Analysis

During an intrusion in April 2026, attackers faced significant challenges in gathering sensitive data. Their attempts to dump critical files from the Security Account Manager (SAM) registry hive and the domain controller’s NTDS.dit file were met with repeated failures. This led them to create shadow copies across multiple drives before successfully copying the necessary files. The attackers’ trial-and-error approach, characterized by the use of numbered batch scripts, suggests a reliance on AI-driven tools to troubleshoot and refine their methods.

Further analysis of the infrastructure revealed an active Let’s Encrypt TLS certificate linked to the domain m-doxa-apodo.duckdns[.]org. This domain was part of a multi-Subject Alternative Name (SAN) certificate that indicated the attackers’ operational focus on Mexican federal government targets. The evolution of their infrastructure, including the rotation of certificates and the establishment of new subdomains, underscores the attackers’ adaptability and sophistication.

AI Integration in Operations

Reports indicate that attackers utilized multiple large language models (LLMs), including Claude and GPT-4.1, to assist in troubleshooting and refining their operations. The use of NextChat, an open-source tool, allowed them to interact with various models and streamline their execution processes. This integration of AI not only facilitated the extraction of sensitive data but also highlighted a significant operational security oversight, as the attackers left their NextChat interface exposed to the public internet.

Brazilian Financial Campaign: CL-CRI-1163

The second campaign, tracked as CL-CRI-1163, targeted the Brazilian financial sector. Initial access was likely gained through a job-themed phishing email, which led to the deployment of custom remote access Trojans (RATs) and tunneling tools. The attackers’ use of a Go-based SOCKS5 proxy with filenames indicative of AI involvement further illustrates the trend of integrating advanced technologies into cyber operations.

Phishing and Automated Actions

In February 2026, attackers associated with CL-CRI-1163 executed a series of phishing attacks that resulted in the installation of multiple RATs. The iterative naming structure of the malware versions suggests a reliance on AI to generate and refine their toolset. As the attackers pivoted to retrieve updated versions of their malware from compromised infrastructure, they demonstrated a clear pattern of adapting their strategies in real-time.

Infrastructure Inspection and AI-Driven Development

Analysis of the infrastructure associated with CL-CRI-1163 revealed a wealth of campaign scripts hosted on an open directory. The naming conventions of these scripts, which included descriptive adjectives, suggest that the attackers employed LLMs to facilitate their development processes. This reliance on AI not only streamlined their operations but also exposed critical vulnerabilities in their operational security.

Conclusion: A New Era of Cyber Threats

The CL-CRI-1131 and CL-CRI-1163 campaigns exemplify a significant evolution in the cyber threat landscape of Latin America. By integrating AI into their operations, attackers are not only enhancing their capabilities but also lowering the barriers to entry for executing complex cyberattacks. However, the operational security failures exhibited by these groups—such as exposed infrastructure and unsecured tools—present opportunities for defenders to disrupt their activities. As the landscape continues to evolve, organizations must remain vigilant and proactive in their cybersecurity measures to counter these emerging threats.

Follow Cyber Warriors Middle East for further cybersecurity features, analysis and insights.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

DHS Subpoenas REI for Customer Data on Green Beanie Purchases Amid Protest Investigation

Did you buy a beanie from REI recently? The Department of Homeland Security (DHS) might be looking for you. According to reporting by Wired,...

Multiple-Cloud Adoption and Zero Trust Security Transform Networking in the Middle East

As organizations in the Middle East increasingly adopt multiple-cloud strategies, the convergence of automation and Zero Trust security is reshaping enterprise networking. Mohammed Al-Moneer,...

Citrix NetScaler ADC and Gateway Products Face Critical Vulnerabilities CVE-2026-19489 and CVE-2026-19490

Australian organisations using Citrix NetScaler ADC and Citrix NetScaler Gateway products should be aware of critical vulnerabilities identified by Citrix. These vulnerabilities, CVE-2026-19489 and...

Police Warn of Rising Cyber Extortion Scams Involving Intimate Images and Video Calls

SINGAPORE – The police have issued a warning regarding a surge in cyber extortion scams that involve intimate images and sexually explicit video calls....