Executive Summary

Two sophisticated AI-enhanced cyber campaigns targeted organizations across Latin America in 2026, demonstrating how threat actors are integrating artificial intelligence into their attack workflows. The first campaign (CL-CRI-1131) targeted Mexican transportation companies and government entities using living-off-the-land techniques and self-hosted NextChat instances for AI assistance. The second campaign (CL-CRI-1163) focused on Brazilian financial institutions, employing custom remote access trojans and Go-based SOCKS5 proxies with AI-generated naming conventions. Both campaigns utilized commercial large language models like ChatGPT and Claude to overcome technical obstacles, generate exploit scripts, and streamline post-exploitation activities. Despite enhanced technical capabilities through AI integration, the attackers exposed their operations through poor operational security, including unsecured staging directories and publicly accessible NextChat interfaces. This represents a significant evolution in regional threat landscapes where diverse threat groups are independently adopting AI to accelerate their attack capabilities while maintaining fundamental security weaknesses that defenders can exploit.

Why This Matters Now

The integration of AI tools by cybercriminals marks a critical inflection point in threat evolution, lowering barriers for sophisticated attacks while creating new detection opportunities through exposed AI infrastructure and operational patterns.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers integrated commercial LLMs like ChatGPT and Claude through NextChat interfaces to generate exploit scripts, troubleshoot technical failures, and streamline post-exploitation workflows in real-time during their operations.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have significantly constrained this multi-stage attack by limiting lateral movement between compromised systems and reducing the attackers' ability to establish persistent cross-network access across Mexican and Brazilian organizations.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Initial compromise through phishing and JBoss exploitation would likely still occur, but the fabric's visibility capabilities could have provided earlier detection of anomalous behavior patterns during the establishment phase

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Credential harvesting operations would likely face significant constraints as zero trust segmentation could have limited access to domain controllers and restricted the scope of systems where SAM and NTDS dumping could occur

Lateral Movement

Control: East-West Traffic Security

Mitigation: SOCKS5 proxy deployment and tunneling operations would likely encounter significant restrictions as east-west traffic controls could have blocked or constrained inter-system communications required for lateral movement infrastructure

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Command and control establishment would likely face detection and potential disruption as multicloud visibility capabilities could have identified suspicious NextChat communications and abnormal certificate usage patterns across cloud environments

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration operations would likely be significantly constrained as egress security controls could have blocked or limited outbound data transfers to unauthorized staging servers and suspicious external endpoints

Impact (Mitigations)

While some business disruption may still occur, the scope of impact would likely be substantially reduced with constrained lateral movement limiting the attackers' reach across transportation, government, and financial sector networks

Impact at a Glance

Affected Business Functions

  • Transportation Logistics Operations
  • Federal Government Services
  • Financial Transaction Processing
  • Critical Infrastructure Management
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: N/A

Data Exposure

Security Account Manager (SAM) registry hives, Active Directory NTDS.dit files, sensitive government data from Mexican federal ministries and municipal utilities, Brazilian financial sector customer data, and operational infrastructure details including NextChat interfaces and staging scripts

Recommended Actions

  • Deploy Cloud Native Security Fabric (CNSF) with inline enforcement to detect and block AI-generated attack scripts and agentic AI operations targeting shadow AI usage
  • Implement Zero Trust Segmentation with identity-based policies and microsegmentation to prevent lateral movement via SOCKS5 proxies and tunneling tools
  • Enable Egress Security & Policy Enforcement with FQDN filtering and data loss prevention to block exfiltration to unauthorized staging servers and dynamic DNS domains
  • Deploy Multicloud Visibility & Control with traffic observability and anomaly detection to identify suspicious automation patterns and repeated malformed requests indicative of AI-assisted operations
  • Implement Threat Detection & Anomaly Response capabilities to baseline normal behavior and alert on covert remote access tools like NextChat instances and iterative script execution patterns

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image