Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
AI Cybersecurity Classified by Officially
We have analyzed two ongoing, multi-stage network intrusion and data-exfiltration campaigns targeting organizations in Latin America. Corroborating recent findings from the broader threat intelligence community, we observed attackers leveraging artificial intelligence (AI) to enhance their capabilities.
Our investigation categorizes this activity as follows:
We track them as two separate activity clusters with distinct geographic focuses. However, the technical and behavioral overlaps between CL-CRI-1131 and CL-CRI-1163 highlight shifting trends in Latin American targeting and threat actor tooling.
Both clusters have overlapping SOCKS5 relay infrastructure and they both rely on AI to orchestrate operations via commercial large language models (LLMs). This signals a broader evolution in the regional threat landscape. Rather than isolated incidents, these clusters demonstrate how diverse threat groups in Latin America are independently adopting advanced proxy networks and AI integration to streamline their execution.
This is an extract. The publication continues at the source.
Read the original at the source: https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/
Officially imported this from Palo Alto Networks Unit 42’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Palo Alto Networks Unit 42 — imported from official source
- Official source
- https://unit42.paloaltonetworks.com/feed/ RSS
- Imported
- September 18, 2026 11:34
- Versions
- 1 recorded
- Identity
https://unit42.paloaltonetworks.com/?p=186340