INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Attackers Expose Ongoing AI Tool Use Targeting Latin American Orgs

| 2026-09-03 11:56 MEDIUM MEDIUM AI-ENABLED ATTACK
Executive Summary
AI-generated
Two ongoing, multi-stage network intrusion and data-exfiltration campaigns targeting organizations in Latin America have been identified. The attackers are believed to be behind these operations, leveraging artificial intelligence (AI) tools to enhance their capabilities. Approximately 2 distinct campaigns are affecting around 4 transportation organizations and government entities in Mexico and Ecuador, as well as an unknown number of financial institutions in Brazil. The attacks work by utilizing living-off-the-land techniques and self-hosted NextChat instances for data exfiltration, with attackers using AI to generate scripts and troubleshoot execution failures. As of the current time, the status of these campaigns is ongoing, with continued use of shared SOCKS5 infrastructure and reliance on commercial large language models like Claude and GPT-4.1 for operational orchestration.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

7d7669••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
87bf8b••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
46ac28••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
a38b2c••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
m-•••••.org
m-•••••.duckdns
m-•••••.org
m-•••••.duckdns
so•••••.exe
rc•••••.py
ex•••••.py
so•••••.exe
29eee8••••••••••••••••••••••••••
4e58c2••••••••••••••••••••••••••••••••••
hxxp://••••••••••••••••••••
167.148.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign UnlikeCampaign UnlikeCampaign DomainsCampaign DomainsCampaign SHACampaign SHAOperation EscaneoOperation Escaneo
Target & Sectors
EUROPE EUROPE LATAM LATAM MIDDLE_EAST MIDDLE_EAST NORTH_AMERICA NORTH_AMERICA energyenergy financefinance governmentgovernment transportationtransportation
Incident Timeline
‎2026/09/03
Attackers used NextChat instances and custom-built SOCKS5 proxies to target organizations in Latin America, including Mexico and Brazil.
organisation NextChat
infrastructure Windows
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product