Date: 09/04/2026
Severity: High
Summary
We analyzed two ongoing, multi-stage network intrusion and data-exfiltration campaigns targeting organizations across Latin America. Attackers used AI to enhance their capabilities, alongside living-off-the-land techniques, custom RATs, and tunneling tools. The Mexican transportation campaign (CL-CRI-1131) targeted transportation organizations, government ministries, and municipal water utilities in Mexico and Ecuador. The Brazilian financial campaign (CL-CRI-1163) expanded job-themed phishing operations against vulnerable web servers, deploying custom RATs and a Go-based SOCKS5 proxy. Both campaigns involved iterative scripts, data exfiltration, and AI-enabled infrastructure, including self-hosted NextChat instances.
Indicators of Compromise (IOC) List
Domains/URLs | m-doxa-apodo.duckdns.org m-doxa-geo.duckdns.org m-doxa-intel.duckdns.org m-doxa-repuve.duckdns.org m-doxa-sre.duckdns.org m-doxa-vacunas.duckdns.org http://167.148.195.53:8888/socktz_v9.exe |
IP Address | 178.128.87.160 165.22.184.26 |
Hash | 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c
4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5
7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8
a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996
87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "m-doxa-repuve.duckdns.org" or url like "m-doxa-repuve.duckdns.org" or siteurl like "m-doxa-repuve.duckdns.org" or domainname like "m-doxa-intel.duckdns.org" or url like "m-doxa-intel.duckdns.org" or siteurl like "m-doxa-intel.duckdns.org" or domainname like "m-doxa-vacunas.duckdns.org" or url like "m-doxa-vacunas.duckdns.org" or siteurl like "m-doxa-vacunas.duckdns.org" or domainname like "m-doxa-apodo.duckdns.org" or url like "m-doxa-apodo.duckdns.org" or siteurl like "m-doxa-apodo.duckdns.org" or domainname like "http://167.148.195.53:8888/socktz_v9.exe" or url like "http://167.148.195.53:8888/socktz_v9.exe" or siteurl like "http://167.148.195.53:8888/socktz_v9.exe" or domainname like "m-doxa-sre.duckdns.org" or url like "m-doxa-sre.duckdns.org" or siteurl like "m-doxa-sre.duckdns.org" or domainname like "m-doxa-geo.duckdns.org" or url like "m-doxa-geo.duckdns.org" or siteurl like "m-doxa-geo.duckdns.org" |
Detection Query 2 : | dstipaddress IN ("178.128.87.160","165.22.184.26") or srcipaddress IN ("178.128.87.160","165.22.184.26") |
Detection Query 3 : | sha256hash IN ("a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996","46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c","4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5","7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8","87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec")
|
Reference:
https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/