CL-CRI-1131 is an intrusion cluster active against public-sector and critical-infrastructure organizations in Mexico and Ecuador, including Mexican federal ministries, a transportation organization, and municipal water utilities. The cluster attempted to collect Windows account and directory information and, after encountering collection failures, created volume shadow copies and used iteratively revised batch scripts to copy targeted data. Operators abused legitimate Windows utilities and used commercial large language models through a self-hosted NextChat deployment to troubleshoot execution failures and generate workaround code during post-compromise activity. CL-CRI-1131 was linked to CL-CRI-1163 through overlapping SOCKS5 relay infrastructure and a shared pattern of large-language-model-assisted operational troubleshooting. Its attribution, organizational identity, and country of origin are not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted intrusions against Mexican and Ecuadorian public-sector and utility targets. Following initial access, the operators used legitimate Windows utilities, volume shadow copies, iterative batch scripts, and AI-assisted troubleshooting to collect and exfiltrate data.
Conducted intrusions against Mexican and Ecuadorian public-sector and transportation targets, using legitimate Windows utilities, iterative batch scripts, data collection and exfiltration troubleshooting. Researchers assessed the operators used Claude and GPT-4.1 through a self-hosted NextChat instance to develop workaround code and troubleshoot execution failures.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.