Two active intrusion and data-exfiltration clusters, CL-CRI-1131 and CL-CRI-1163, targeted Latin American organizations in 2026. CL-CRI-1131 compromised a Mexican transportation organization and pursued Mexican and Ecuadorian government and water-utility targets, collecting data with living-off-the-land techniques. CL-CRI-1163 targeted Brazil’s financial sector through resume-themed phishing, deploying custom remote-access trojans and evolving versions of the Go-based reverse SOCKS5 proxy SockTz.
Researchers identified overlapping SOCKS5 relay infrastructure across the campaigns, alongside exposed staging systems and AI-interface infrastructure, including a NextChat deployment. The infrastructure, certificates, script directories, and predictable naming patterns suggest the operators used commercial LLM tools to troubleshoot execution failures and develop or refine operational scripts. Defenders can use those exposed artifacts and relay-infrastructure overlaps to hunt, track, and disrupt the activity.

See the actors and campaigns active against you right now.
6 events from the most recent confirmed update back to the earliest known activity.
CL-CRI-1131-associated infrastructure obtained an additional multi-SAN TLS certificate, further linking its exposed infrastructure to the campaign's tracked DuckDNS-hosted services.
Infrastructure associated with CL-CRI-1131 remained active through June. The cluster also targeted Mexican federal ministries and municipal water utilities in Mexico and Ecuador, using DuckDNS subdomains and data-exfiltration-related infrastructure.
CL-CRI-1131-associated infrastructure obtained a multi-SAN TLS certificate, one of the certificates later associated with host 178.128.87[.]160, which exposed a NextChat LLM web interface.
CL-CRI-1131 intrusion activity was observed against a transportation organization in Mexico. Operators repeatedly attempted to collect the SAM registry hive and Active Directory NTDS.dit database, including by creating volume shadow copies and using numbered batch scripts to stage collected data.
Infrastructure associated with CL-CRI-1131 used a single-subject-alternative-name TLS certificate, later linked to host 165.22.184[.]26 through its certificate fingerprint.
CL-CRI-1163 likely obtained initial access to Brazilian financial-sector targets through a resume-themed phishing email attachment. The operators subsequently deployed custom remote-access Trojans and attempted to install successive SockTz reverse-SOCKS5 proxy versions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
unit42.paloaltonetworks.com
Open sourcetrendmicro.com
Open sourcecdn.prod.website-files.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.