AI is now part of the attackers’ arsenal in Latin America

AI is now part of the attackers’ arsenal in Latin America

Artificial Intelligence is no longer just a tool for improving productivity, automating tasks, or assisting cybersecurity teams. Threat actors are also incorporating language models (LLMs) into their operations to solve technical problems, develop scripts, and accelerate different stages of their attacks.

A recent investigation by Unit 42, Palo Alto Networks’ threat intelligence team, provides particularly interesting evidence of this trend specifically in Latin America: two different campaigns targeting organizations in Mexico, Ecuador, and Brazil in which attackers used AI as part of their operations.

The most relevant aspect of the finding is not that attackers are using ChatGPT, Claude, or other language models, but rather how they are using them.

Two campaigns, one shared infrastructure

The first attack affected a transportation sector organization and was also associated with government targets and municipal water services in Mexico and Ecuador. The second was primarily directed at the Brazilian financial sector.

Although the campaigns present significant technical differences, the researchers identified a common element: the incorporation of commercial LLMs within the attackers’ workflow. In other words, AI does not appear only during attack preparation. It is beginning to be used as a support tool during the intrusion itself.

One of the most interesting aspects of the attack on the Mexican organization was precisely observing how the attackers reacted to technical problems. During a compromise that occurred in April 2026, the operators attempted to extract sensitive information from Windows systems, including the SAM hive and the NTDS.dit file from a domain controller. The initial attempts did not work.

Subsequently, different versions of scripts began to appear, along with modifications and alternative mechanisms until they managed to overcome the issues encountered during the operation.

The investigation also identified an instance of NextChat hosted on infrastructure controlled by the attackers themselves. NextChat allows interaction with different language models from a centralized interface. Related investigations had identified the use of models such as Claude and GPT-4.1 by the operators.

The combination of the initial errors, the successive modifications of the scripts, and the AI infrastructure led the researchers to assess that the attackers were using LLMs to generate solutions to the problems they encountered during the compromise.

The model thus begins to play a role similar to that of a technical assistant for the attacker. Faced with a command that doesn’t work, a permissions issue, or a tool that fails to execute correctly, the operator can turn to an LLM to quickly generate an alternative.

AI lowers the technical barrier for attackers

Traditionally, the ability to advance within a compromised infrastructure depended largely on the operator’s knowledge and experience.

An attacker could encounter an unexpected configuration, a different version of an operating system, permissions restrictions, or a tool that simply did not work as expected. Resolving those problems required technical knowledge, research, and time.

LLMs partially modify that equation. They do not automatically turn an inexperienced attacker into an advanced operator, but they can allow them to:

  • generate and modify scripts quickly;
  • interpret errors and look for alternatives;
  • adapt commands to different environments;
  • automate repetitive tasks;
  • develop simple tools;
  • generate configurations for proxies or tunnels;
  • accelerate reconnaissance and post-exploitation tasks.

The consequence is probably not the immediate emergence of completely autonomous attacks executed by AI, but rather the fact that attackers can iterate much faster.

Nine versions in two hours

The second campaign analyzed by Unit 42 offers a particularly illustrative example. The attack was aimed at Brazilian financial sector organizations and reportedly initially used phishing related to job offers.

Once access was obtained, the attackers deployed different RATs and attempted to install a SOCKS5 tunneling tool developed in Go called SockTz.

The researchers observed installation attempts of versions 1 through 9 of this tool over an approximate period of two hours. The infrastructure used by the attackers also contained hundreds of scripts with iterative naming patterns. Among them appeared names like exploit_creative.py, exploit_careful.py, and rce_focused.py. This type of naming convention, along with the speed of iteration and other evidence found in the infrastructure, is consistent with development processes assisted by language models.

Again, what’s interesting is not that AI has created a revolutionary tool, but rather the speed of the test, error, and correction cycle. If one version fails, another is generated in a matter of seconds and iteratively; that is, the cost of experimenting decreases considerably.

From “copy and paste” to the offensive co-pilot

For years, attackers used search engines, forums, public repositories, exploits available on the Internet, and tools developed by third parties. LLMs represent a natural evolution of that model.

Before, an attacker who encountered an error could search for the solution on the Internet, review documentation, adapt existing code, and try again.

Now they can maintain a dialogue with a model:

  • this command failed
  • analyze the error
  • generate another alternative
  • modify the script
  • try again.

Knowledge remains important, but the time needed to transform an idea into an executable action decreases. This makes AI a true capability multiplier.

And this phenomenon has particular relevance for Latin American organizations because these cases demonstrate that we are not talking only about hypothetical scenarios or attacks observed in other regions. The offensive use of AI is already appearing in campaigns that have concrete targets in Latin America.

The paradox: faster attackers, but not necessarily better

The investigation also leaves another interesting conclusion. The same attackers who used AI to solve technical problems made basic operational security (OpSec) mistakes.

Part of their infrastructure was left publicly exposed. NextChat instances, staging directories, scripts, and other components allowed researchers to reconstruct a significant portion of their operations.

AI had helped the operators solve technical problems within the compromised organizations, but did not correct their operational errors, which also leads us to conclude that AI does not automatically mean sophistication.

A relatively inexperienced actor can use an LLM to generate reasonably complex scripts and, at the same time, leave a critical server of their own infrastructure exposed.

For defensive teams, those errors continue to be valuable opportunities to identify infrastructure, correlate activity, and understand the adversary’s operations.

What does this mean for SOCs and incident response teams?

The adoption of AI by attackers also forces a review of some defensive assumptions. One of them is speed. If attackers can use AI to solve problems, modify tools, and quickly generate new variants, the time available to detect and contain an intrusion may be reduced.

Security teams should progressively assume that an attacker can adapt their procedures during the incident itself.

This increases the importance of capabilities such as behavior-based detection, event correlation, identity monitoring, Living-off-the-Land activity analysis, and effective incident response capabilities.

It also reinforces a principle that at BeaconLab we consider fundamental: it’s not enough to detect malware. In one of the attacks, for example, the attackers used legitimate operating system tools and Living-off-the-Land (LotL) techniques. In such scenarios, identifying anomalous behavior can be much more important than looking only for known malicious files.

There is, however, another side to this evolution. The same capabilities that allow an attacker to analyze errors, generate scripts, or process large amounts of information can also be used by defensive teams.

A SOC can use AI to accelerate investigations, interpret large volumes of events, contextualize alerts, generate hunting queries, or summarize information distributed across multiple sources.

An Incident Response team can use it to assist in log analysis, build timelines, generate investigation hypotheses, or accelerate certain repetitive tasks.

Therefore, the discussion should not be reduced to whether attackers use AI: If the attacker is using AI to operate faster, is our security team still responding at the same speed as five years ago?

Conclusion

The campaigns documented by Unit 42 show an evolution we will likely see more frequently. AI is not replacing the human attacker, but is beginning to accompany them. It allows them to experiment faster, generate tools, solve errors, and reduce some of the technical friction that traditionally limited certain operations.

This can increase the capabilities of less experienced actors and accelerate the operations of those who already possess advanced knowledge.

For Latin American organizations, the message is particularly relevant: this transformation is already occurring in campaigns targeting our region. The defensive response must evolve in the same direction.

Because in a scenario where attackers and defenders have access to similar tools, the advantage will probably not simply lie in who has AI, but in who manages to better integrate it into their operations, detect earlier, and respond faster.

References

Unit 42 – “Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America”. Palo Alto Networks, 2026.

Trend Micro – “Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America”.