Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Palo Alto Networks’ Unit 42 published its analysis on September 3, 2026, detailing two ongoing multi-stage intrusion campaigns targeting organizations in Mexico, Ecuador, and Brazil. Both activity clusters—tracked as CL-CRI-1131 and CL-CRI-1163—use commercial large language models orchestrated through self-hosted interfaces to accelerate data exfiltration and C2 infrastructure management. The finding is significant because it forensically documents, for the first time, how LLMs have become an integrated operational component of regional cybercrime rather than a peripheral accessory.
- CL-CRI-1131 operators self-hosted NextChat instances at IP 178.128.87[.]160 on TCP port 3000 to interface with commercial LLMs during operations.
- Let’s Encrypt certificates issued on February 27, April 20, and June 19, 2026 show infrastructure evolution from 1 to 5 SANs, expanding the targeting footprint.
- Unit 42 detected trial-and-error patterns in batch scripts—repeated attempts to dump the SAM hive and NTDS.dit with subsequent fixes—indicating real-time LLM-assisted troubleshooting.
- The two clusters share overlapping SOCKS5 relay infrastructure, pointing to a proxy-service economy in Latin American cybercrime.
CL-CRI-1131: LLM and LotL Against Mexican Government Entities
Cluster CL-CRI-1131 targeted a transportation-sector organization, Mexican federal ministries, and municipal water utilities in Mexico and Ecuador. The documented intrusion dates to April 2026, with confirmed persistence through June 2026. Attackers employed living-off-the-land techniques and iteratively numbered batch scripts to manipulate and exfiltrate sensitive data.
The distinguishing element is the command-and-control infrastructure. Operators deployed NextChat—an open-source interface for interacting with multiple LLM models—on a server at 178.128.87[.]160, TCP port 3000. The instance was directly exposed without detectable access restrictions and functioned as an operational terminal for real-time queries.
DuckDNS domains registered for the cluster carry the "m-doxa" prefix: m-doxa-apodo, m-doxa-intel, m-doxa-vacunas. Subdomain names indicate operational functions and specific Mexican government targets. Associated Let’s Encrypt certificates show infrastructural progression: the first, issued February 27, 2026, covered a single host (165.22.184[.]26); the subsequent certificates from April 20 and June 19, 2026—both with five SANs—pointed to the NextChat server. This expansion documents the evolution of targeting over the course of the campaign.
CL-CRI-1163: AI-Enablement in the Brazilian Financial Sector
The second cluster, CL-CRI-1163, targeted the Brazilian financial sector, expanding from prior vulnerable-web-server targeting into a job-themed phishing campaign. Unlike the Mexican cluster, operators employed custom malware—a RAT—and proprietary tunneling tools.
Among these, Unit 42 identified a Go-based SOCKS5 proxy with iterative filenames suggesting AI-enablement. The report does not detail the exact structure of these names or the generation mechanism, but the characterization is explicit: the naming patterns do not match typical manual conventions.
The sharing of SOCKS5 relay infrastructure between CL-CRI-1131 and CL-CRI-1163 is the most strategically significant finding. Two geographically distinct clusters, with different sectoral targets and partially differentiated toolsets, converge on the same proxy network. This indicates a level of criminal infrastructure servitization that accelerates adoption of advanced capabilities even by independent operators.
"Both clusters have overlapping SOCKS5 relay infrastructure and they both rely on AI to orchestrate operations via commercial large language models (LLMs)" — Unit 42
The OpSec Failure: When AI Leaves Traces
The report’s strongest analytical angle is the demonstration that LLM usage, while accelerating operations, generated recognizable exposure patterns. Attackers left technical traces in three areas: the NextChat interface exposed on a standard port without evident hardening; multi-SAN certificates mapping infrastructural evolution with chronological precision; and sequentially numbered batch files with iterative corrections recording the "reasoning" process with the model.
Unit 42’s direct quote is definitive: "These trial-and-error actions and successive script fixes are consistent with LLM usage." The pattern is incompatible with a skilled operator writing manually: the speed of corrections, numeric sequentiality, and repetition of errors already fixed in prior instances indicate a query-response-interaction cycle with the model.
Prior reports from CloudSEK (June 2026, "Operation Escaneo") and Gambit (February 2026) had already documented the use of Claude and GPT-4.1 in Mexican campaigns. Unit 42 integrates this research into its own cluster framework, confirming operational continuity and intensifying AI adoption throughout 2026.
Why It Matters
The brief does not document specific mitigations or operational recommendations from the vendor. Unit 42 provides no hardening, detection, or incident-response guidance dedicated to this threat model. This gap is relevant: traditional defenses based on static IoCs—IPs, hashes, domains—are insufficient against operators who use LLMs to adapt scripts in real time and iterate tactics without recompiling malware.
The dossier does not specify the exact nature of exfiltrated data, nor the overall victim count beyond those confirmed. It is unclear whether the same operators manage both clusters or whether this represents independent adoption of similar tactics, though infrastructural overlap suggests at least proxy-service sharing. It is unconfirmed whether LLMs were also used for initial access or only for post-exploitation and troubleshooting.
The specific role of iterative filenames in the Go SOCKS5 proxy as an indicator of AI-enablement is not technically detailed in the available text. The dossier also does not specify whether unreported victims or related unidentified campaigns exist.
A Read on the Regional Trend
Adoption of commercial LLMs in Latin American cybercrime is not an isolated anomaly but a structural pattern. Unit 42 states it explicitly: "Rather than isolated incidents, these clusters demonstrate how diverse threat groups in Latin America are independently adopting advanced proxy networks and AI integration to streamline their execution." The key word is "independently": there is no single centralized actor, but a horizontal diffusion of skills and tools.
This has consequences for global threat modeling. Latin America has traditionally been considered a secondary market for sophisticated crimeware; Unit 42’s data indicates that the combination of accessible proxy services, low-cost LLM APIs, and open-source interfaces like NextChat has lowered the barrier to entry for multi-stage operations. The speed of tactical iteration—measured in days, not weeks—reduces defenders’ response time.
The next frontier is not automatic generation of malware from scratch, which the report does not document, but operational integration: the LLM as an embedded tactical consultant in the C2 workflow, enabling mid-tier operators to execute tasks that would otherwise require specialized expertise. The trail they leave differs from traditional malware, but it is a trail nonetheless. Unit 42’s work demonstrates it is detectable, provided detection models evolve in kind.
Frequently Asked Questions
Were the LLMs compromised or breached?
No. Attackers use legitimate commercial APIs—Claude and GPT-4.1 per CloudSEK and Gambit—via self-hosted interfaces. There is no indication of a breach at the LLM providers.
Are the two campaigns attributed to the same group?
Unit 42 treats CL-CRI-1131 and CL-CRI-1163 as separate clusters. Infrastructural overlap suggests proxy-service sharing, not necessarily common management. The source neither rules out nor confirms a single operating entity.
What is the current status of the campaigns?
The report describes them as "ongoing" with persistent infrastructure documented through June 2026. The dossier contains no indications of conclusion.
Sources
- https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/
- https://unit42.paloaltonetworks.com/tools/
- https://unit42.paloaltonetworks.com/atoms/
- https://unit42.paloaltonetworks.com/about-unit-42/
Information is based on the cited source and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.