Security1 distinct publisher2 min readPublished
Two tracked clusters hit Mexican, Ecuadorian and Brazilian targets with living-off-the-land tradecraft, numbered batch scripts and shared SOCKS5 relays. The AI tooling they left running is the part defenders can query for.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Look at the April 2026 host activity in sequence. The operator tried repeatedly to dump the SAM registry hive and the domain controller NTDS.dit file, failed, then created shadow copies across multiple drives before copying the files out [5]. Alongside that ran a series of numbered batch scripts collecting data from the host, one of which had a permissions check inserted to make sure writes to the collection directory landed [6]. Then the operator went off to troubleshoot connectivity with 62.171.185[.]97, the address the cluster used for exfiltration [7]. Unit 42 reads that correction pattern as consistent with LLM usage [6]. That is an inference from behaviour on the box, not a captured prompt or a provider log.
The evidence is not equally thick across both clusters. CL-CRI-1131 has self-hosted NextChat instances sitting on operational infrastructure plus the script iteration [2]. CL-CRI-1163's basis is thinner: custom RATs and tunnelling tools, including a Go-based SOCKS5 proxy whose iterative filenames Unit 42 says suggest AI enablement [3]. Filenames are the weakest artifact in the set. A running service is the strongest.
The infrastructure work is where the pivot paid. From that exfiltration IP, Unit 42 found an active Let's Encrypt certificate for m-doxa-apodo.duckdns[.]org, following a distinctive dynamic DNS naming standard [8]. Searching the m-doxa prefix surfaced five active subdomains whose names indicate both operational function and intended Mexican federal government targets [9]. The certificates were regenerated in April 2026 and again in June 2026 [11], and the infrastructure persisted into June [12]. Three generations, February to April to June, is roughly two months per rotation across four months of observed life [13].
One wrinkle in the writeup matters for anyone repeating the pivot. In one passage Unit 42 describes the February 2026 setup as a single consolidated multi-SAN certificate carrying the five subdomains [9]; in another it describes the February deployment, following the initial activity window reported by CloudSEK, as a single-SAN certificate securing only m-doxa-apodo [10]. Those cannot both describe the same object. Which one is right determines whether the target list was visible in February or only from April.
The queryable version of this is dull, which is the point. A chat front end listening on a server nobody provisioned is an inventory question. Sustained egress from a file server to a commercial model API is a netflow question. Both are cheaper than trying to detect the prose an operator typed into a box you cannot see.
Ranked by verification strength, evidence, and original report placement.
Unit 42 tracks the Mexican transportation campaign as CL-CRI-1131; it impacted a transportation organisation alongside federal government ministries and municipal water utilities in Mexico and Ecuador, with operators relying on living-off-the-land techniques, iterative batch scripts to manipulate and exfiltrate sensitive data, and self-hosted NextChat instances on operational infrastructure.
Unit 42 analysed two ongoing, multi-stage network intrusion and data-exfiltration campaigns targeting organisations in Latin America, and observed attackers leveraging AI to enhance their capabilities, corroborating recent findings from the broader threat intelligence community.
Unit 42 tracks the Brazilian financial campaign as CL-CRI-1163; attackers targeted the Brazilian financial sector, expanded previously reported targeting of vulnerable web servers in a job-themed phishing campaign, and used custom remote access Trojans and tunnelling tools including a Go-based SOCKS5 proxy with iterative filenames that suggest AI-enablement.
During a CL-CRI-1131 intrusion in April 2026, after repeated attempts to dump the Security Account Manager registry hive and the domain controller NTDS.dit file, the attacker created shadow copies across multiple drives before copying files.
The attacker used a series of numbered batch scripts to collect sensitive data from the compromised host and inserted a permissions check to ensure successful file writing to the collection directory; Unit 42 says these trial-and-error actions and successive script fixes are consistent with LLM usage.
After struggling to collect the files, Unit 42 observed the attackers troubleshooting connectivity with infrastructure at 62.171.185[.]97, the IP address used in CL-CRI-1131 activity for data exfiltration.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
science
TeamPCP hid its infostealer inside the scanners that audit everyone else's code1 distinct publisher
security
Unit 42's Credential Brief: Hunt The Login That Succeeds Right After The Failures1 distinct publisher
science
Unit 42 counted 405 AI malware samples. Twelve reached a real endpoint.1 distinct publisher
security
Aeternum puts botnet C2 on Polygon, and leaves defenders no domain to seize1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Concrete artefacts, one pair of eyes
The specifics are unusually hard for this genre: named hive-dump failures, numbered batch files, an exfiltration address, a certificate pivot from an IP to a DuckDNS hostname, and a rotation table. All of it, though, is Unit 42's own telemetry, and two things pull the score down — the report contradicts itself on whether February's certificate covered five subdomains or one, and the AI conclusion is an inference from attacker clumsiness plus a chat interface, not from captured prompts.
Two live campaigns, no headcount
What is real is dated and located: a hands-on intrusion in April 2026, infrastructure still answering in June, victims in Mexican and Ecuadorian government and utilities and in Brazilian finance, and an attacker-run model interface serving both compromises. What is absent is any measure of spread — no number of victims, no volume of data taken, no indication whether the shared SOCKS5 relays serve two crews or twenty.
The AI label outruns the tradecraft
Unit 42's own hedging is honest — 'consistent with LLM usage', filenames that 'suggest' AI-enablement — and the NextChat box is a genuine find. But strip the label and the operation is shadow copies, registry hives and .bat files numbered 1 through n, executed by someone who kept failing and had to add a permissions check. The framing points at capability uplift; the evidence shows an intruder asking a chatbot why the copy didn't work. The leap from that to a region independently adopting AI is where the distance opens up.
House research with a contact form in the middle
This is a security vendor publishing on its own domain, and it breaks off mid-analysis to note that Palo Alto Networks customers are protected and to hand out the incident response number. None of that discredits the packet-level detail. It does explain the choice of headline — attackers using AI, rather than unpatched web servers and dumpable domain controllers — and it explains why the timeline has been checked by exactly one interested party.
Take the indicators, hold the thesis loosely
Split the story in two and the confidence splits with it. The host artefacts and the certificate trail are specific, internally coherent and immediately checkable by anyone with the logs — treat them as usable. The interpretive layer, that LLMs orchestrate these operations and that Latin American crews are converging on AI plus proxy networks, rests on one vendor's inference, an unresolved contradiction about February's certificate, and supporting reports we can only see referenced.