Executive Summary
Two sophisticated AI-enhanced cyber campaigns targeted organizations across Latin America in 2026, demonstrating how threat actors are integrating artificial intelligence into their attack workflows. The first campaign (CL-CRI-1131) targeted Mexican transportation companies and government entities using living-off-the-land techniques and self-hosted NextChat instances for AI assistance. The second campaign (CL-CRI-1163) focused on Brazilian financial institutions, employing custom remote access trojans and Go-based SOCKS5 proxies with AI-generated naming conventions. Both campaigns utilized commercial large language models like ChatGPT and Claude to overcome technical obstacles, generate exploit scripts, and streamline post-exploitation activities. Despite enhanced technical capabilities through AI integration, the attackers exposed their operations through poor operational security, including unsecured staging directories and publicly accessible NextChat interfaces. This represents a significant evolution in regional threat landscapes where diverse threat groups are independently adopting AI to accelerate their attack capabilities while maintaining fundamental security weaknesses that defenders can exploit.
Why This Matters Now
The integration of AI tools by cybercriminals marks a critical inflection point in threat evolution, lowering barriers for sophisticated attacks while creating new detection opportunities through exposed AI infrastructure and operational patterns.
Attack Path Analysis
Attackers initiated compromise through resume-themed phishing emails targeting Latin American organizations, then escalated privileges using AI-generated scripts to extract credentials from SAM/NTDS databases. They moved laterally using SOCKS5 proxies while establishing command and control through self-hosted NextChat instances and tunneling infrastructure. Data exfiltration occurred via iterative batch scripts to attacker-controlled staging servers, with operations causing business disruption across Mexican transportation and Brazilian financial sectors through persistent access and credential harvesting.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers gained initial access through resume-themed phishing email attachments and exploitation of vulnerable JBoss servers, establishing foothold in target environments
MITRE ATT&CK® Techniques
Phishing: Spearphishing Attachment
Command and Scripting Interpreter: Windows Command Shell
OS Credential Dumping: Security Account Manager
OS Credential Dumping: NTDS
Proxy: External Proxy
Deobfuscate/Decode Files or Information
Exfiltration Over C2 Channel
Ingress Tool Transfer
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – External and Internal Penetration Testing
Control ID: Requirement 11.3
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: Section 500.15
DORA – Identification and Classification of ICT-related Incidents
Control ID: Article 8
CISA ZTMM 2.0 – Network/Environment
Control ID: Pillar 3
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001:2022 – Information Security in Project Management
Control ID: A.8.24
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Advanced Persistent Threat campaigns with AI-enhanced capabilities directly targeted Brazilian financial institutions using custom RATs, SOCKS5 proxies, and data exfiltration techniques.
Transportation
Mexican transportation organizations compromised through multi-stage intrusions with AI-assisted batch scripts, shadow copies, and encrypted traffic exfiltration via SOCKS5 infrastructure.
Government Administration
Federal ministries and municipal utilities targeted by LLM-enhanced attackers using living-off-the-land techniques, credential dumping, and lateral movement across government networks.
Utilities
Municipal water utilities in Mexico and Ecuador exposed to AI-augmented threat actors employing encrypted traffic analysis evasion and east-west network segmentation bypass techniques.
Sources
- Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin Americahttps://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/Verified
- Operation Escaneo - Mexican Government Financial Institutions Cyberattackhttps://www.cloudsek.com/blog/operation-escaneo-mexican-government-financial-institutions-cyberattackVerified
- Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin Americahttps://www.trendmicro.com/en_us/research/26/e/vibe-hacking-two-ai-augmented-campaigns-target-government-and-financial-sectors-in-latin-america.htmlVerified
- The AI-Assisted Breach of Mexico's Government Infrastructurehttps://cdn.prod.website-files.com/69944dd945f20ca4a27a7c47/69d8bb5aea59e31efb3b8a7f_Tech_Report_ai_breach_mex_gov.pdfVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained this multi-stage attack by limiting lateral movement between compromised systems and reducing the attackers' ability to establish persistent cross-network access across Mexican and Brazilian organizations.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial compromise through phishing and JBoss exploitation would likely still occur, but the fabric's visibility capabilities could have provided earlier detection of anomalous behavior patterns during the establishment phase
Control: Zero Trust Segmentation
Mitigation: Credential harvesting operations would likely face significant constraints as zero trust segmentation could have limited access to domain controllers and restricted the scope of systems where SAM and NTDS dumping could occur
Control: East-West Traffic Security
Mitigation: SOCKS5 proxy deployment and tunneling operations would likely encounter significant restrictions as east-west traffic controls could have blocked or constrained inter-system communications required for lateral movement infrastructure
Control: Multicloud Visibility & Control
Mitigation: Command and control establishment would likely face detection and potential disruption as multicloud visibility capabilities could have identified suspicious NextChat communications and abnormal certificate usage patterns across cloud environments
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration operations would likely be significantly constrained as egress security controls could have blocked or limited outbound data transfers to unauthorized staging servers and suspicious external endpoints
While some business disruption may still occur, the scope of impact would likely be substantially reduced with constrained lateral movement limiting the attackers' reach across transportation, government, and financial sector networks
Impact at a Glance
Affected Business Functions
- Transportation Logistics Operations
- Federal Government Services
- Financial Transaction Processing
- Critical Infrastructure Management
Estimated downtime: 7 days
Estimated loss: N/A
Security Account Manager (SAM) registry hives, Active Directory NTDS.dit files, sensitive government data from Mexican federal ministries and municipal utilities, Brazilian financial sector customer data, and operational infrastructure details including NextChat interfaces and staging scripts
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Cloud Native Security Fabric (CNSF) with inline enforcement to detect and block AI-generated attack scripts and agentic AI operations targeting shadow AI usage
- • Implement Zero Trust Segmentation with identity-based policies and microsegmentation to prevent lateral movement via SOCKS5 proxies and tunneling tools
- • Enable Egress Security & Policy Enforcement with FQDN filtering and data loss prevention to block exfiltration to unauthorized staging servers and dynamic DNS domains
- • Deploy Multicloud Visibility & Control with traffic observability and anomaly detection to identify suspicious automation patterns and repeated malformed requests indicative of AI-assisted operations
- • Implement Threat Detection & Anomaly Response capabilities to baseline normal behavior and alert on covert remote access tools like NextChat instances and iterative script execution patterns



