News Room
16
Share
Unit 42 Tracks Latin American Clusters Using Self-Hosted NextChat to Iterate AI-Assisted Tooling
highAI Cyber Attacks

Unit 42 Tracks Latin American Clusters Using Self-Hosted NextChat to Iterate AI-Assisted Tooling

Unit 42 tracks two Latin American clusters (CL-CRI-1131 and CL-CRI-1163) using self-hosted NextChat to query commercial LLMs, iterating batch scripts and SOCKS5 proxy variants (SockTz v1–v9) within hours of failures. Targets include Mexican/Ecuadorian government, transport and water, and Brazilian financial orgs.

04 September 2026Last updated 04 September 20265 min readUnit 42 / Palo Alto Networks
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
AI Cyber Attacks
Severity:
High
Actor Type:
Cybercriminal
Geography:
Latin America (Mexico, Ecuador, Brazil)
Confidence:
Confirmed
MITRE ID:
T1059, T1003, T1090, T1071, T1204
Source:
Unit 42 / Palo Alto Networks
Read Time:
5 min

Executive Summary

Unit 42 has disclosed two tracked threat clusters operating in Latin America that used commercial large language models — accessed through self-hosted NextChat instances — to troubleshoot and iterate their tooling in real time. The clusters, designated CL-CRI-1131 (targeting Mexico and Ecuador transportation, government, and municipal water) and CL-CRI-1163 (targeting Brazilian financial organizations), generated successive batch scripts and SOCKS5 proxy variants within hours of each failure, demonstrating an iterative, AI-assisted development loop.

This is a defensive threat-intelligence analysis of publicly reported Unit 42 research. No exploit code or attack instructions are provided.

Key Findings

  • Two tracked clusters: CL-CRI-1131 (Mexico/Ecuador transport, government, municipal water) and CL-CRI-1163 (Brazilian financial sector).
  • Self-hosted NextChat: Operators deployed NextChat to query commercial LLMs, producing iterative tooling on demand.
  • Rapid iteration: SOCKS5 proxy tooling (SockTz) cycled through versions v1–v9 within hours after failures, with LLM-style naming conventions on generated scripts.
  • Living-off-the-land credential dumps: Operators combined AI-generated scripts with LotL credential extraction techniques.
  • Overlapping infrastructure: Both clusters shared SOCKS5 proxy infrastructure, suggesting a common operator or toolkit supply chain.
  • OpSec failures: Open NextChat instances and exposed directories leaked the playbooks, enabling the research.

Mechanism

The clusters did not use novel zero-days. Their differentiator was velocity: when a script or proxy variant failed, the operator queried the LLM through NextChat, received a corrected or adapted variant, and redeployed within hours. This compressed the traditional manual development cycle into a near-continuous improvement loop.

Defensive Implications

  • Detect self-hosted LLM front-ends: NextChat and similar open-source chat UIs deployed on attacker infrastructure are a strong indicator of AI-assisted operations; monitor for their presence in egress and threat-actor infrastructure.
  • Proxy variant churn: Rapid cycling of SOCKS5 proxy variants (SockTz v1–v9) within hours is an operational signature worth building detections around.
  • Credential hygiene in LatAm government and finance: The targeting of federal ministries, municipal water, and financial orgs underscores the need for credential rotation, MFA, and LotL detection in these sectors.
  • Shared infrastructure as attribution signal: Overlapping SOCKS5 infrastructure across clusters can link otherwise disparate activity to a common toolkit or operator.

Sources

  • Unit 42 / Palo Alto Networks (3 Sep 2026)

Defensive research only. No exploit code or attack instructions.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.

Sources

  1. 1.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo