AI-Enhanced Cyber Campaigns Targeting Latin America: A Deep Dive
Recent investigations into multi-stage cyber campaigns targeting organizations in Latin America reveal a concerning trend: attackers are increasingly leveraging artificial intelligence (AI) to enhance their operational capabilities. This analysis focuses on two distinct campaigns—one targeting the transportation sector in Mexico and the other aimed at the financial sector in Brazil—both of which illustrate the evolving tactics of cybercriminals in the region. For a detailed overview, refer to the findings published by Palo Alto Networks’ Unit 42 team here.
Mexican Transportation Campaign: CL-CRI-1131
The first campaign, designated CL-CRI-1131, primarily affected a transportation organization along with various federal ministries and municipal water utilities in Mexico and Ecuador. Attackers employed living-off-the-land (LotL) techniques, utilizing existing system tools to execute their operations. Notably, they executed iterative batch scripts to manipulate and exfiltrate sensitive data, while also hosting instances of NextChat on their operational infrastructure.
Execution Challenges and Infrastructure Analysis
During an intrusion in April 2026, attackers faced significant challenges in gathering sensitive data. Their attempts to dump critical files from the Security Account Manager (SAM) registry hive and the domain controller’s NTDS.dit file were met with repeated failures. This led them to create shadow copies across multiple drives before successfully copying the necessary files. The attackers’ trial-and-error approach, characterized by the use of numbered batch scripts, suggests a reliance on AI-driven tools to troubleshoot and refine their methods.
Further analysis of the infrastructure revealed an active Let’s Encrypt TLS certificate linked to the domain m-doxa-apodo.duckdns[.]org. This domain was part of a multi-Subject Alternative Name (SAN) certificate that indicated the attackers’ operational focus on Mexican federal government targets. The evolution of their infrastructure, including the rotation of certificates and the establishment of new subdomains, underscores the attackers’ adaptability and sophistication.
AI Integration in Operations
Reports indicate that attackers utilized multiple large language models (LLMs), including Claude and GPT-4.1, to assist in troubleshooting and refining their operations. The use of NextChat, an open-source tool, allowed them to interact with various models and streamline their execution processes. This integration of AI not only facilitated the extraction of sensitive data but also highlighted a significant operational security oversight, as the attackers left their NextChat interface exposed to the public internet.
Brazilian Financial Campaign: CL-CRI-1163
The second campaign, tracked as CL-CRI-1163, targeted the Brazilian financial sector. Initial access was likely gained through a job-themed phishing email, which led to the deployment of custom remote access Trojans (RATs) and tunneling tools. The attackers’ use of a Go-based SOCKS5 proxy with filenames indicative of AI involvement further illustrates the trend of integrating advanced technologies into cyber operations.
Phishing and Automated Actions
In February 2026, attackers associated with CL-CRI-1163 executed a series of phishing attacks that resulted in the installation of multiple RATs. The iterative naming structure of the malware versions suggests a reliance on AI to generate and refine their toolset. As the attackers pivoted to retrieve updated versions of their malware from compromised infrastructure, they demonstrated a clear pattern of adapting their strategies in real-time.
Infrastructure Inspection and AI-Driven Development
Analysis of the infrastructure associated with CL-CRI-1163 revealed a wealth of campaign scripts hosted on an open directory. The naming conventions of these scripts, which included descriptive adjectives, suggest that the attackers employed LLMs to facilitate their development processes. This reliance on AI not only streamlined their operations but also exposed critical vulnerabilities in their operational security.
Conclusion: A New Era of Cyber Threats
The CL-CRI-1131 and CL-CRI-1163 campaigns exemplify a significant evolution in the cyber threat landscape of Latin America. By integrating AI into their operations, attackers are not only enhancing their capabilities but also lowering the barriers to entry for executing complex cyberattacks. However, the operational security failures exhibited by these groups—such as exposed infrastructure and unsecured tools—present opportunities for defenders to disrupt their activities. As the landscape continues to evolve, organizations must remain vigilant and proactive in their cybersecurity measures to counter these emerging threats.
Follow Cyber Warriors Middle East for further cybersecurity features, analysis and insights.



