Unit 42 Links Latin America Intrusions to LLM-Assisted Attacks and SOCKS5 Relay Tool
Palo Alto Networks' Unit 42 has documented separate intrusion campaigns targeting organizations in Mexico and Brazil, attributed to threat clusters CL-CRI-1131 and CL-CRI-1163. Attackers gained initial access through phishing emails carrying resume-disguised attachments, after which multiple remote access trojans were deployed on compromised Windows endpoints. The threat actors repeatedly attempted to deploy SockTz, a reverse SOCKS5 relay tool, cycling through nine versions over roughly two hours, suggesting iterative troubleshooting possibly aided by large language models. On compromised systems, attackers made multiple attempts to extract sensitive credential files, including SAM and NTDS.dit, using Volume Shadow Copies and batch scripts with destination write-permission checks. Unit 42 also observed activity coordinating data exfiltration toward a specific IP address, though successful file transmission and SockTz connection establishment were not explicitly confirmed.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in