Unit 42 Finds AI-Run Exfiltration Nodes in Latin America
Unit 42 says two ongoing intrusion campaigns in Latin America are using AI in the exfiltration phase, including a Mexican transportation and public-sector cluster and a separate campaign against Brazilian financial targets. In the Mexican case, the attackers ran self-hosted NextChat instances on operational infrastructure while using living-off-the-land batch scripts to move data out.
The point is not that they used a chatbot, but where they put it: the AI service sat on compromised infrastructure and helped coordinate the theft, while overlapping SOCKS5 proxy relays and other tooling carried the traffic. That makes the attacker-run chat node itself part of the control layer, so host activity and network paths around it can expose the operation even when the rest of the intrusion stays low-noise.
For defenders in those sectors, the lasting lesson is that self-hosted AI assistants with access to internal data can be turned into attacker command points if they land on compromised systems. If that node or its proxy layer is visible, it can become a disruption point the rest of the intrusion does not share.