Mexico, Brazil, Ecuador in CL-CRI-1131, 1163
Unit 42 tracked two AI-assisted intrusion clusters in Mexico, Ecuador and Brazil, using NextChat, Claude
Palo Alto Networks Unit 42 documented two AI-augmented intrusion clusters in Latin America, tracked as CL-CRI-1131 and CL-CRI-1163, with activity concentrated in Mexico, Ecuador and Brazil. The first compromised a Mexican transportation company, Mexican federal ministries and a municipal water company in Ecuador. The second targeted Brazil’s financial sector through job-themed phishing and résumé attachments. In both cases, operators folded commercial language models into the operational cycle, not as a standalone intrusion vector, but as support for faster troubleshooting, script generation and tactical problem-solving.
Executive summary
Palo Alto Networks Unit 42 documented two intrusion clusters in Latin America, CL-CRI-1131 and CL-CRI-1163, that combined commercial language models with attacker-owned infrastructure, conventional phishing, iterative scripts, custom RATs and SOCKS5 tunneling. The first cluster hit a Mexican transportation company, Mexican federal ministries and water entities in Ecuador. The second targeted Brazil’s financial sector through job-themed phishing and résumé attachments.
The novelty was not an autonomous AI attack vector, but the operational use of commercial LLMs inside familiar campaigns. Unit 42, and the summaries citing its analysis, describe a self-hosted NextChat instance on 178.128.87[.]160, exposed on TCP port 3000, used to query services such as Claude and GPT-4.1. That interface appears to have supported troubleshooting, script generation and assistance with exfiltration and exploitation tasks. The material also says initial access still depended on phishing and unpatched servers.
In CL-CRI-1163, the most distinctive component was SockTz, a reverse SOCKS5 proxy written in Go. Unit 42 observed at least nine successive versions, with file names such as socktz_v1 through socktz_v9, deployed with incremental changes over an approximate two-hour window. Several secondary sources, including Machine Speed, SecurityLab, daily.dev and CISOclub, read that pace as a sign of AI-assisted debugging and binary generation, although that conclusion is inferred and not a formal attribution in the original report.
The CL-CRI-1131 campaign relied on living-off-the-land techniques and iterative batch scripts to manipulate and exfiltrate sensitive data. CL-CRI-1163, by contrast, used job-themed phishing, custom RATs and SOCKS5 tunnels for internal pivoting. Unit 42 and the briefings citing its findings stress that initial access still came from phishing and unpatched systems, not from AI-specific vulnerabilities. AI strengthened existing TTPs instead of introducing a new autonomous entry point.
The regional footprint is clear and limited. Mexico accounts for most of the CL-CRI-1131 activity, with victims in transportation, federal government and water. Ecuador appears as an extension of that same campaign, with at least one municipal water company and other reports broadening the water-sector exposure. Brazil is the center of CL-CRI-1163, with financial-sector victims, including banks, and an intrusion chain that involved repeated staging from compromised attacker-controlled infrastructure. The available material does not attribute these clusters to any specific country, nation-state or region.
Background and context
The consolidated material makes it possible to reconstruct a fairly precise technical sequence, though not authorship attribution. Unit 42 published a Portuguese-language report on September 3, 2026, about continued AI use in attacks against Latin American organizations, and several secondary sources reused that analysis in briefings, technical notes and summaries in different languages. The common thread is always the same, two clusters, two primary attack geographies and a shared operating pattern that mixes automation, LLMs and custom tooling.
The CL-CRI-1131 cluster is linked to compromises in Mexico and Ecuador. Available summaries cite a Mexican transportation company, multiple federal ministries and at least one municipal water company in Ecuador. In a later expansion, a Russian outlet also mentioned municipal water companies in Mexico, which broadens the inventory of water-infrastructure victims, although it does not change the overall picture. The campaign is built around living-off-the-land activity, iterative batch scripts and self-hosted NextChat used to query commercial models.
The CL-CRI-1163 cluster is concentrated in Brazil and the financial sector. Here, initial access reportedly came through job-themed phishing and résumé attachments, followed by deployment of custom RATs and SockTz. SockTz appears repeatedly in the reports because it enables reverse SOCKS5 connections and pivoting into the victim network. The most important detail is the iteration speed, v1 to v9, which several summaries place at under two hours.
Secondary reporting adds useful pieces. Machine Speed notes that the operators queried ChatGPT and Claude as work tools during the intrusions. SecurityLab reports working files such as exploit_creative.py, exploit_careful.py and rce_focused.py, suggesting a rapid generation and tuning process for code. CISOclub and daily.dev describe SockTz progressing from a compromised WordPress site to attacker-controlled infrastructure. SocDefenders adds domains and a specific binary associated with SockTz v9.
That set of sources does not change one central conclusion. The attackers do not appear to have needed an AI exploit to get in. They used phishing, attached artifacts, unpatched servers and conventional post-exploitation techniques. AI appears later, as an operational multiplier, not as the entry door.
Key facts table
| Date | Fact | Source | Confidence |
|---|---|---|---|
| 2026-09-03 | Unit 42 published a report on continued AI use in attacks against Latin American organizations. | Palo Alto Networks Unit 42 | Confirmed |
| 2026-09-03 | CL-CRI-1131 affected transportation, federal government and water in Mexico and Ecuador. | Palo Alto Networks Unit 42, Cloud Security Alliance | Confirmed |
| 2026-09-03 | CL-CRI-1163 targeted Brazil’s financial sector with job-themed phishing. | Palo Alto Networks Unit 42, Cloud Security Alliance | Confirmed |
| 2026-09-03 | Operators self-hosted NextChat on 178.128.87[.]160 and used it with Claude and GPT-4.1. | Unit 42, Cloud Security Alliance, Machine Speed | Confirmed |
| 2026-09-03 | SockTz was observed in at least nine successive versions. | Unit 42, Cloud Security Alliance | Confirmed |
| 2026-09-03 | Unit 42 observed SockTz v1 through v9 deployed in less than two hours. | Machine Speed, daily.dev | Confirmed |
| 2026-09-04 | Risky Business summarized the Brazilian campaign with custom RATs and SOCKS5 tunnels. | Risky Business | Confirmed |
| 2026-09-05 | SecurityLab reported scripts such as exploit_creative.py and rce_focused.py. | SecurityLab | Confirmed |
| 2026-09-05 | Rambler expanded the water-sector victim set in Mexico and Ecuador. | Rambler/Technologies | Confirmed |
| 2026-09-06 | Zerotrust Consulting summarized the combined use of AI, LotL and SOCKS5 proxies. | Zerotrust Consulting | Confirmed |
Operation timeline
| Date | Event | Actor/vector | Verified source |
|---|---|---|---|
| February 2026 | Initial access to Brazilian financial entities through phishing with a résumé attachment. | CL-CRI-1163, spearphishing | Unit 42, SecurityLab |
| February 2026 | Reported start of minimum activity for both clusters. | CL-CRI-1131, CL-CRI-1163 | Cloud Security Alliance |
| April 2026 | Compromises in CL-CRI-1131 with NextChat activity on 178.128.87[.]160. | CL-CRI-1131, NextChat | Unit 42 |
| June 2026 | New compromises tied to CL-CRI-1131 using the same NextChat infrastructure. | CL-CRI-1131, NextChat | Unit 42 |
| February to June 2026 | Operational window documented by Machine Speed for both clusters. | CL-CRI-1131, CL-CRI-1163 | Machine Speed |
| September 3, 2026 | Publication of the main Unit 42 report. | Palo Alto Networks Unit 42 | Unit 42 |
| September 3, 2026 | Technical summaries from CSA, SocDefenders and Feedly consolidate the finding. | CSA, SocDefenders, Feedly | Secondary sources |
| September 4 to 6, 2026 | Additional analysis appears in Risky Business, Rambler, CISOclub, SecurityLab, daily.dev and Zerotrust. | CL-CRI-1131, CL-CRI-1163 | Secondary sources |
Attack chain and TTPs
The attack chain observed across both clusters follows a basic sequence, initial access through phishing or unpatched systems, execution of attached artifacts or scripts, use of commercial LLMs to speed up troubleshooting and tooling creation, and then persistence or pivoting through RATs and SOCKS5. The material shows no evidence of an AI exploit during the initial phase. AI appears as support for exploitation, code generation and rapid tool tuning.
CL-CRI-1131 relies more heavily on system techniques and scripts. The material says operators used living-off-the-land, ran iterative batch scripts and manipulated and exfiltrated sensitive data from compromised systems. That fits well with MITRE ATT&CK family T1059, and with evasion techniques associated with native tool abuse, although the original report does not label each step that way. The critical infrastructure layer was the self-hosted NextChat instance on 178.128.87[.]160.
CL-CRI-1163 has a clearer post-exploitation and pivoting component. Job-themed phishing and résumé attachments led to deployment of custom RATs and SockTz. SocDefenders, MITRE and other secondary sources make it possible to map T1566.001 to initial access, T1219 to RAT use, T1090.003 to multi-hop proxies and T1059 to scripts and commands. The fact that SockTz is a reverse SOCKS5 proxy in Go makes its technical function straightforward.
The most unusual piece is the tooling iteration. Unit 42 observed at least nine successive versions of SockTz, and several sources say socktz_v1 through socktz_v9 were deployed over a two-hour span. That pace does not prove AI assistance on its own, but it does suggest a rapid trial-and-error cycle, with minor changes and repeated redeployment. SecurityLab and daily.dev even describe exploit script names with varying adjectives, such as exploit_creative.py and exploit_careful.py, which strengthens the case for assisted generation.
In both clusters, the operation does not depend on an exotic technique but on the combination of several well-known pieces, phishing, LotL, scripts, RATs, proxies and LLMs. The value of the research is in showing that this combination is already active in the region and is being used with enough discipline to sustain complete intrusion chains.
| TTP | Description | Source |
|---|---|---|
| T1566.001 | Spearphishing attachment, used as the initial access vector in CL-CRI-1163. | MITRE ATT&CK, SocDefenders, Unit 42 |
| T1059 | Use of command interpreters and scripts, visible in iterative batch scripts and data manipulation. | MITRE ATT&CK, Unit 42, Risky Business |
| T1090.003 | Multi-hop proxy, functionally aligned with SockTz and reverse SOCKS5 tunneling. | MITRE ATT&CK, SocDefenders, Cloud Security Alliance |
| T1219 | Remote Access Tools, consistent with custom RAT use in CL-CRI-1163. | MITRE ATT&CK, Unit 42, SocDefenders |
| T1078 | Valid Accounts, reported by SocDefenders in the campaigns analyzed. | SocDefenders |
| T1003.001 | LSASS memory dumping, reported by SocDefenders in the campaigns analyzed. | SocDefenders |
Regional impact
Regional overview
The confirmed regional impact is concentrated in three countries, Mexico, Ecuador and Brazil, with clear differences between the transportation and government campaign in CL-CRI-1131 and the financial campaign in CL-CRI-1163. Mexico absorbs most of the public victims cited. Ecuador appears as an extension of the same operation, and Brazil as the focus of the second cluster, in a campaign aimed at banks and financial institutions.
The victim profile also changes by cluster. CL-CRI-1131 touches public infrastructure and critical services, transportation, federal government and water. CL-CRI-1163 targets a narrower financial vertical, but one that is technically more developed in post-exploitation, with custom RATs, tunneling and a SockTz version chain that suggests an accelerated refinement cycle. That distinction matters because it shows AI was not limited to generating text, but was used to sustain a multistage intrusion operation.
On the operational side, both clusters share infrastructure for interacting with commercial LLMs, especially self-hosted NextChat. That increases the value of that host as a critical asset in the attack chain. If that node is cut off, the operators lose access to Claude, GPT-4.1 and other services used for scripting and troubleshooting, although the material does not claim this is the only possible point of failure.
Mexico
Mexico accounts for most of the damage attributed to CL-CRI-1131. The Unit 42 report, and the summaries citing it, mention a Mexican transportation company, federal ministries and municipal water companies. That last layer matters because the Russian-language material expands the water exposure to Mexican entities in addition to Ecuadorian ones. The campaign relied on living-off-the-land activity, iterative batch scripts and a NextChat instance hosted by the attackers on 178.128.87[.]160.
The most important technical signal for Mexico is that the chat infrastructure was used to query commercial language models during the intrusion. Unit 42 and Machine Speed place ChatGPT, Claude and GPT-4.1 inside the operation as working tools. That turns NextChat into a coordination node, not a minor accessory. The use of batch scripts to manipulate and exfiltrate sensitive data also shows the objective was not only access, but systematic extraction.
Ecuador
Ecuador appears as an extension of CL-CRI-1131, and according to the consolidated material, at least one municipal water company was compromised there. Secondary sources also describe ministries, water and transportation inside a single regional cluster, suggesting a broader campaign than a single isolated target. The technical pattern does not change, living-off-the-land activity, iterative scripts, self-hosted NextChat and exploitation supported by LLMs.
The available documentation does not provide a complete inventory of Ecuadorian victims. It does, however, establish a critical surface, municipal water, that is enough to understand the operational interest. From a defense perspective, that means the campaign should be treated as an intrusion with potential impact on essential services, not as a routine corporate phishing incident.
Brazil
Brazil is the center of CL-CRI-1163 and the clearest part of the study for post-exploitation analysis. Initial access came through résumé-based or job-themed phishing, with an attachment that served as the malicious artifact. Custom RATs and SockTz, the reverse SOCKS5 proxy in Go, followed. Unit 42 and secondary sources agree that the cluster affected financial-sector entities, including banks.
The critical piece here is SockTz. CISOclub, daily.dev and Deniz.in describe an attempt to deploy socktz_v1 through socktz_v8 from a compromised WordPress site using certutil, and then moving to socktz_v9 from attacker-controlled infrastructure when earlier versions failed. That kind of operational feedback shows a highly iterative campaign. It also shows the hosting network was not stable, but adaptive.
United States
The United States does not appear as a victim country in the consolidated research, but it does appear as the publication, support and contact point. Unit 42, part of Palo Alto Networks, published the main material, and the Portuguese-language report includes a toll-free contact number for North America. Palo Alto Networks also published corporate posts about using OpenAI and Anthropic models for defenders, a useful contrast to the offensive abuse of LLMs seen in these clusters.
That does not add a U.S. victim, but it does help place the response capability and vendor ecosystem. In the material, the United States functions as an editorial and support center, not as a target of CL-CRI-1131 or CL-CRI-1163.
Countries with no additional verifiable facts in the research for this section, Argentina, Chile, Paraguay, Bolivia, Peru, Colombia and Uruguay.
Technical indicators
| Type | Value | Source |
|---|---|---|
| IP | 178.128.87[.]160 | Unit 42, Machine Speed, Ciberseguridad LATAM |
| Port | TCP 3000 | Unit 42, Ciberseguridad LATAM |
| Domain | m-doxa-apodo.duckdns[.]org | SocDefenders |
| Domain | m-doxa-geo.duckdns[.]org | SocDefenders |
| Domain | m-doxa-intel.duckdns[.]org | SocDefenders |
| Binary | hxxp[:]//167.148.195[.]53:8888/socktz_v9.exe | SocDefenders |
| File name | socktz_v1 to socktz_v9 | Unit 42, Machine Speed, daily.dev, CISOclub, Deniz.in |
| Tool | NextChat | Unit 42, Cloud Security Alliance, Machine Speed |
| Tool | SockTz | Unit 42, Cloud Security Alliance, Risky Business |
Analysis for security teams
The first operational focus is detecting self-hosted chat infrastructure and unusual outbound traffic to commercial LLM APIs. The material indicates that attackers hosted NextChat on 178.128.87[.]160 and used it to query Claude and GPT-4.1. That suggests two practical controls. First, block or at least monitor unexpected connections to AI services from segments that should not use them. Second, watch internal hosts that show browsing patterns or exposed ports consistent with self-hosted chat interfaces.
The second focus is tunneling traffic. SockTz functions as a reverse SOCKS5 proxy, so detection should look for SOCKS patterns, multi-hop proxying and persistent outbound connections from endpoints that should not act as relays. Cloud Security Alliance specifically recommended looking for anomalous SOCKS5 traffic consistent with Chisel or SockTz. In telemetry terms, proxy, DNS, EDR and egress firewall logs should get priority.
The third focus is abuse of native utilities and batch scripts. CL-CRI-1131 used living-off-the-land techniques and iterative scripts to manipulate and exfiltrate data. In Windows environments, that means reviewing processes that mimic legitimate tools, batch commands launched in sequence and execution chains that end in unusual export or compression files. SocDefenders and MITRE help map that activity to T1059, T1078 and, for persistence, techniques associated with valid accounts.
The fourth focus is phishing response. CL-CRI-1163 began with résumé and job-offer emails. That makes mail controls, attachment sandboxing, sender reputation and targeted training for HR and recruiting especially important. The fact that the initial vector is traditional does not reduce the risk of the later operation. If anything, it ties directly into RAT deployment and tunneling.
The tactical priority should be twofold. First, close unnecessary exposure from self-hosted chat interfaces, tunneling binaries and compromised web repositories used for staging. Second, review egress and lateral movement within critical transportation, government, water and financial segments. If an organization in those verticals sees NextChat, SockTz or file patterns such as socktz_vN, the finding should not be treated as an isolated malware incident, but as part of a previously characterized intrusion chain.
Frequently asked questions
What connects CL-CRI-1131 and CL-CRI-1163 beyond both using AI?
The two clusters share more than LLM use. Both integrate self-hosted NextChat, access to Claude or GPT-4.1, and an operational support logic for solving exploits, generating scripts or speeding up intrusion tasks. The summaries also agree that they use conventional phishing, attacker-controlled infrastructure and techniques that map to MITRE ATT&CK.
What technical element makes AI use most visible in these campaigns?
The clearest indicator is the rapid iteration of tooling, especially SockTz in CL-CRI-1163, which was redeployed in at least nine versions. Add to that the NextChat instance exposed on 178.128.87[.]160 and the work scripts found by SecurityLab. Taken together, they suggest model assistance in the trial-and-error cycle.
Which countries and sectors are actually affected according to the consolidated material?
Mexico concentrates CL-CRI-1131, with victims in transportation, federal government and water. Ecuador appears within that same campaign, with at least one municipal water company. Brazil concentrates CL-CRI-1163, with a focus on banks and other financial entities. The material does not verify victims in Argentina, Chile, Paraguay, Bolivia, Peru, Colombia or Uruguay.
Which MITRE ATT&CK TTPs are most aligned with what was observed?
The best-aligned techniques are T1566.001 for spearphishing attachments, T1059 for scripts and command interpreters, T1090.003 for multi-hop proxying and T1219 for RATs. SocDefenders also mentions T1078 and T1003.001. That mapping covers initial access by phishing, post-exploitation and the use of SockTz as a reverse proxy.
What should a defense team prioritize if it suspects a similar intrusion?
First, review egress toward LLM APIs and traffic to self-hosted chat interfaces. Next, look for SOCKS5 patterns, multi-hop proxies and binaries with names like socktz_vN. In parallel, inspect résumé attachments, iterative batch scripts and processes that mimic legitimate utilities. If the organization sits in transportation, government, water or finance, the priority should be high.
Material limitations
The material makes it possible to reconstruct the technical chain, but not a firm geopolitical attribution. There is no verified identification of a state actor, criminal group or regional sponsor. Complete hashes, exhaustive victim lists, published detection rules from the original authors and an exact campaign start date are also unavailable. Several sources use formulas such as "at least since February 2026," which establish a floor but not a precise start.
The evidence for AI assistance in SockTz iteration is consistent, but partly inferred by third parties. Unit 42 describes the repeated versions and LLM use; other sources interpret that as proof of assisted automation. That inference is reasonable, but it remains an inference. Likewise, the mention of earlier campaigns against vulnerable JBoss systems for SockTz appears as secondary information, not as an independent confirmation within the main corpus.
No additional facts were verified for Argentina, Chile, Paraguay, Bolivia, Peru, Colombia or Uruguay. The United States appears only as the publication, support and editorial contact point, not as a victim.
Sources and internal consistency
The findings in the consolidated material are consistent across Palo Alto Networks Unit 42, Cloud Security Alliance, Machine Speed, Risky Business, SocDefenders, Feedly, SecurityLab, daily.dev, CISOclub, Deniz.in, Rambler and Zerotrust Consulting. The documentary consensus is that CL-CRI-1131 and CL-CRI-1163 are active campaigns in Latin America that combine commercial LLMs, self-hosted NextChat and SOCKS5 tunneling tooling, with a focus on Mexico, Ecuador and Brazil.
Palo Alto Networks’ defensive report on the use of GPT-5.6-Cyber and Claude Mythos 5 for testing and risk exposure appears as parallel commercial context. That material does not change the intrusion facts, but it does frame the contrast between offensive and defensive LLM use within the same security ecosystem.
Sources
- CVE-2026-76658 - Exploits & Severityfeedly.com· Feedly
- AI-Augmented Intrusions Hit Latin American Government and Financelabs.cloudsecurityalliance.org· Cloud Security Alliance
- Alternative CISO Daily Briefing – 2026-09-03labs.cloudsecurityalliance.org· Cloud Security Alliance
- CISO Daily Briefing – September 3, 2026labs.cloudsecurityalliance.org· Cloud Security Alliance
- Attacks — Machine Speed - AI-Cyber Intelligencemachinespeed.techpointe.org· Machine Speed
- Risky Bulletin: Russia tells data centers to deploy drone defensesrisky.biz· Risky Business
- Attackers Expose Ongoing AI Tool Use Targeting ...socdefenders.ai· SocDefenders
- IA como copiloto de ciberdelincuentes — el patrón que detectó Unit 42ciberseguridadlatam.com· Ciberseguridad LATAM
- Jewelbug Linked to Government Espionage and Crypto Fraud ...mallory.ai· Mallory
- ИИ научил хакеров взламывать быстрее. Прятаться пока не научилnews.rambler.ru· Rambler/Technologies
- Два кластера атак в Латинской Америке использовали LLM и SOCKS5cisoclub.ru· CISOclub.ru
- Unit 42 (search result with CL-CRI-1163 February 2026 phishing detail)unit42.paloaltonetworks.com· Palo Alto Networks Unit 42
- Unit 42 (search result with "more than 50 MITRE ATT&CK techniques" observation)unit42.paloaltonetworks.com· Palo Alto Networks Unit 42
- Atacantes expõem uso contínuo de ferramentas de IA em ataques contra organizações na América Latinaunit42.paloaltonetworks.com· Palo Alto Networks Unit 42
- ИИ научил хакеров взламывать быстрее. Прятаться пока не ...securitylab.ru· SecurityLab
- T1566.001 Spearphishing Attachmentattack.mitre.org· MITRE ATT&CK
- T1059 Command and Scripting Interpreterattack.mitre.org· MITRE ATT&CK
- T1219 Remote Access Toolsattack.mitre.org· MITRE ATT&CK
- Risky Bulletin: Russia tells data centers to deploy drone defensesnews.risky.biz· Risky Business
- Proxy (T1090)attack.mitre.org· MITRE ATT&CK
- Phishing (T1566)attack.mitre.org· MITRE ATT&CK
- Unit 42 traces LLM-assisted intrusion attempts against Mexican and Brazilian targetsdeniz.in· Deniz.in
- Putting OpenAI Cyber Models to Work for Defenderspaloaltonetworks.com· Palo Alto Networks
- Unit 42 Defends Organizations Against Next-Gen Frontier AI Risks with Anthropic’s Mythos 5paloaltonetworks.com· Palo Alto Networks
- Corporate tweet on GPT-5.6-Cyber and multi-model harnessx.com· Palo Alto Networks
- MITRE ATT&CK Enterprise Matrixattack.mitre.org· MITRE
- ZTC Cyber Intelligence 003 | 7 de septiembre de 2026zerotrust.consulting· Zerotrust Consulting
- Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin Americadaily.dev· daily.dev
- T1090.003 Multi-hop Proxyattack.mitre.org· MITRE ATT&CK
- Risky Bulletin: Russia tells data centers to deploy drone defensesrisky.biz· Risky.Biz



