Two real, ongoing intrusion campaigns targeted organizations in Latin America, including a Mexican transportation organization and Brazil’s financial sector. In the Brazil campaign, attackers reportedly got in via a resume-themed phishing attachment, then attempted to download and run tunneling tools and remote-access malware. Investigators also found the attackers used an AI chat tool (NextChat) hosted on their own infrastructure to troubleshoot and generate scripts, though they exposed parts of that infrastructure publicly.
Key findings
- Researchers analyzed “two ongoing, multi-stage network intrusion and data-exfiltration campaigns targeting organizations in Latin America.”
- The Mexico-focused cluster (CL-CRI-1131) used living-off-the-land scripts and data exfiltration infrastructure, and exposed AI tooling (NextChat) on attacker-controlled servers.
- The Brazil-focused cluster (CL-CRI-1163) “likely gained initial access through a job-themed phishing compromise,” specifically via a “resume-themed phishing email attachment.”
- Attackers repeatedly attempted tool installs (versions 1–9) and used infrastructure that suggested AI-assisted, iterative script generation (e.g., descriptive filenames like “exploit_creative.py”).
- Open directories / exposed infrastructure allowed researchers to observe tooling and operational details.
Who’s being targeted
- Commonly targeted roles: HR, Recruiting, Hiring Managers, Finance, IT Operations, Security Operations.
- Affected industries: Transportation, Government, Utilities (Water), Finance and Insurance.
- Attack channels: email, website.
- Impersonated: Job applicant / recruiter (job-related sender), Legitimate-looking download location hosted on a compromised site.
Awareness takeaways
- Treat unsolicited job-related attachments as high risk; route candidates through official hiring portals and scan attachments before opening.
- Be suspicious of requests or instructions to download and run tools from random websites, even if they look like legitimate blog/WordPress pages.
- Repeated “versioned” tool downloads and rapid retries can be a sign of an active attacker troubleshooting in real time, escalate quickly to security.
- Assume attackers may use AI to iterate faster on scripts and troubleshooting; focus training on verification steps and reporting, not just “spotting typos.”
Red flags to watch for
- Unexpected resume/attachment from an unknown sender
- Pressure to open an attachment rather than using an official hiring portal
- Attachment-based workflow with no prior contact or verification
- Use of built-in tools to fetch executables from the internet
- Executable name/versioning that changes repeatedly (v1–v9)
- Files hosted on a compromised or unfamiliar website
Read the video transcript
In Brazil, banks got breached because someone opened one thing: a fake resume email. The email said, 'Resume for Finance Role – attachment included.' When it opened, it quietly pulled down a tunneling tool called socktz_v8.exe from a random WordPress site to dig into the network. Investigators saw versions 1 through 9 of this tool tried in two hours, with filenames like exploit_creative.py. That’s not a glitch, that’s someone, likely with AI help, rapidly troubleshooting live inside a network. If you get an unexpected resume attachment outside our hiring portal, don’t open it, forward it to Security and let us check it first.