Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America

    Date: 09/04/2026

    Severity: High

    Summary

    We analyzed two ongoing, multi-stage network intrusion and data-exfiltration campaigns targeting organizations across Latin America. Attackers used AI to enhance their capabilities, alongside living-off-the-land techniques, custom RATs, and tunneling tools. The Mexican transportation campaign (CL-CRI-1131) targeted transportation organizations, government ministries, and municipal water utilities in Mexico and Ecuador. The Brazilian financial campaign (CL-CRI-1163) expanded job-themed phishing operations against vulnerable web servers, deploying custom RATs and a Go-based SOCKS5 proxy. Both campaigns involved iterative scripts, data exfiltration, and AI-enabled infrastructure, including self-hosted NextChat instances.

    Indicators of Compromise (IOC) List 

    Domains/URLs

    m-doxa-apodo.duckdns.org

    m-doxa-geo.duckdns.org

    m-doxa-intel.duckdns.org

    m-doxa-repuve.duckdns.org

    m-doxa-sre.duckdns.org

    m-doxa-vacunas.duckdns.org

    http://167.148.195.53:8888/socktz_v9.exe

    IP Address 

    178.128.87.160

    165.22.184.26

    Hash 

    46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c

    4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5

    7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8

    a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996

    87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "m-doxa-repuve.duckdns.org" or url like "m-doxa-repuve.duckdns.org" or siteurl like "m-doxa-repuve.duckdns.org" or domainname like "m-doxa-intel.duckdns.org" or url like "m-doxa-intel.duckdns.org" or siteurl like "m-doxa-intel.duckdns.org" or domainname like "m-doxa-vacunas.duckdns.org" or url like "m-doxa-vacunas.duckdns.org" or siteurl like "m-doxa-vacunas.duckdns.org" or domainname like "m-doxa-apodo.duckdns.org" or url like "m-doxa-apodo.duckdns.org" or siteurl like "m-doxa-apodo.duckdns.org" or domainname like "http://167.148.195.53:8888/socktz_v9.exe" or url like "http://167.148.195.53:8888/socktz_v9.exe" or siteurl like "http://167.148.195.53:8888/socktz_v9.exe" or domainname like "m-doxa-sre.duckdns.org" or url like "m-doxa-sre.duckdns.org" or siteurl like "m-doxa-sre.duckdns.org" or domainname like "m-doxa-geo.duckdns.org" or url like "m-doxa-geo.duckdns.org" or siteurl like "m-doxa-geo.duckdns.org"

    Detection Query 2 :

    dstipaddress IN ("178.128.87.160","165.22.184.26") or srcipaddress IN ("178.128.87.160","165.22.184.26")

    Detection Query 3 :

    sha256hash IN ("a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996","46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c","4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5","7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8","87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec")

    Reference:    

    https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/                                      


    Tags

    MalwareLatin AmericaAIExfiltrationliving off the land (LOTL)RATMexicoTransportation SystemsGovernment Services and FacilitiesWater and Wastewater SectorBrazilFinancial Services

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags