
Unit 42 Tracks Latin American Clusters Using Self-Hosted NextChat to Iterate AI-Assisted Tooling
Unit 42 tracks two Latin American clusters (CL-CRI-1131 and CL-CRI-1163) using self-hosted NextChat to query commercial LLMs, iterating batch scripts and SOCKS5 proxy variants (SockTz v1–v9) within hours of failures. Targets include Mexican/Ecuadorian government, transport and water, and Brazilian financial orgs.
Executive Takeaway — TL;DR
- Category:
- AI Cyber Attacks
- Severity:
- High
- Actor Type:
- Cybercriminal
- Geography:
- Latin America (Mexico, Ecuador, Brazil)
- Confidence:
- Confirmed
- MITRE ID:
- T1059, T1003, T1090, T1071, T1204
- Source:
- Unit 42 / Palo Alto Networks
- Read Time:
- 5 min
Executive Summary
Unit 42 has disclosed two tracked threat clusters operating in Latin America that used commercial large language models — accessed through self-hosted NextChat instances — to troubleshoot and iterate their tooling in real time. The clusters, designated CL-CRI-1131 (targeting Mexico and Ecuador transportation, government, and municipal water) and CL-CRI-1163 (targeting Brazilian financial organizations), generated successive batch scripts and SOCKS5 proxy variants within hours of each failure, demonstrating an iterative, AI-assisted development loop.
This is a defensive threat-intelligence analysis of publicly reported Unit 42 research. No exploit code or attack instructions are provided.
Key Findings
- Two tracked clusters: CL-CRI-1131 (Mexico/Ecuador transport, government, municipal water) and CL-CRI-1163 (Brazilian financial sector).
- Self-hosted NextChat: Operators deployed NextChat to query commercial LLMs, producing iterative tooling on demand.
- Rapid iteration: SOCKS5 proxy tooling (SockTz) cycled through versions v1–v9 within hours after failures, with LLM-style naming conventions on generated scripts.
- Living-off-the-land credential dumps: Operators combined AI-generated scripts with LotL credential extraction techniques.
- Overlapping infrastructure: Both clusters shared SOCKS5 proxy infrastructure, suggesting a common operator or toolkit supply chain.
- OpSec failures: Open NextChat instances and exposed directories leaked the playbooks, enabling the research.
Mechanism
The clusters did not use novel zero-days. Their differentiator was velocity: when a script or proxy variant failed, the operator queried the LLM through NextChat, received a corrected or adapted variant, and redeployed within hours. This compressed the traditional manual development cycle into a near-continuous improvement loop.
Defensive Implications
- Detect self-hosted LLM front-ends: NextChat and similar open-source chat UIs deployed on attacker infrastructure are a strong indicator of AI-assisted operations; monitor for their presence in egress and threat-actor infrastructure.
- Proxy variant churn: Rapid cycling of SOCKS5 proxy variants (SockTz v1–v9) within hours is an operational signature worth building detections around.
- Credential hygiene in LatAm government and finance: The targeting of federal ministries, municipal water, and financial orgs underscores the need for credential rotation, MFA, and LotL detection in these sectors.
- Shared infrastructure as attribution signal: Overlapping SOCKS5 infrastructure across clusters can link otherwise disparate activity to a common toolkit or operator.
Sources
- Unit 42 / Palo Alto Networks (3 Sep 2026)
Defensive research only. No exploit code or attack instructions.
Sources
- 1.Unit 42 — AI Tool Use Targeting LatAm OrgsPrimary research disclosure
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



