CL-CRI-1163 is a Latin America-focused intrusion cluster that targeted financial-sector organizations in Brazil. It gained initial access using resume-themed phishing attachments and subsequently deployed custom remote-access Trojans. The cluster used SockTz, a Go-based reverse SOCKS5 tunneling tool, attempting multiple rapidly iterated versions to relay traffic through compromised systems and support post-compromise access. Operators initially distributed the tunneling tool through a compromised web resource before moving delivery to infrastructure under their control. CL-CRI-1163 shares overlapping SOCKS5 relay infrastructure with CL-CRI-1131, indicating an operational linkage between the clusters.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Targeted Brazilian financial organizations using job-themed phishing, custom remote-access Trojans, and SockTz reverse SOCKS5 tunneling. Operators used a compromised WordPress site to deliver multiple SockTz versions before moving to attacker-controlled infrastructure.
Targeted Brazilian financial organizations through job/resume-themed phishing, deploying custom remote-access Trojans and SockTz reverse SOCKS5 tunnels. The cluster was linked to CL-CRI-1131 through overlapping relay infrastructure and a shared pattern of using large language models during operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.