Summary
Key Points:
- Ongoing multi-stage network intrusion campaigns targeting organizations in Latin America, utilizing AI for enhanced operational capabilities.
- The Mexican transportation campaign (CL-CRI-1131) affected transportation and government entities, while the Brazilian financial campaign (CL-CRI-1163) targeted the financial sector using phishing and custom RATs.
- Recommended actions include monitoring for indicators of compromise (IOCs) associated with these campaigns and enhancing defenses against AI-driven threats.
Technical Details: Attackers employed living-off-the-land techniques, iterative batch scripts, and custom malware like a Go-based SOCKS5 proxy. Notable IOCs include domains associated with data exfiltration and specific SHA-256 hashes of malicious files.
MITRE ATT&CK Techniques:
- T1566.001 - Phishing: Spearphishing Attachment (Initial Access)
- T1078 - Valid Accounts (Defense Evasion)
- T1003.001 - OS Credential Dumping: LSASS Memory (Credential Access)
- T1021.001 - Remote Services: Remote Desktop Protocol (Lateral Movement)
IOCs Mentioned:
- Domains: m-doxa-apodo.duckdns[.]org, m-doxa-geo.duckdns[.]org, m-doxa-intel.duckdns[.]org, hxxp[:]//167.148.195[.]53:8888/socktz_v9.exe
- SHA-256 hashes: 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c, 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5, 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8, a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996, 87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec
Join the discussion — sign up to comment, upvote, and save articles.