Forensic Summary
Unit 42 has identified two active intrusion campaigns targeting Latin American organisations in the transportation and financial sectors, with threat actors demonstrably leveraging commercial LLMs — including self-hosted NextChat instances — to orchestrate and refine attack execution. The campaigns share overlapping SOCKS5 relay infrastructure and exhibit iterative, AI-assisted scripting behaviour, suggesting independent but parallel adoption of LLM tooling by distinct threat groups. This represents a concrete operational example of adversaries using AI to lower the skill floor for multi-stage network intrusion and data exfiltration.
Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/llm-assisted-intrusions-hit-latin-american-orgs-via-nextchat/
Top comments (0)