Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks
ID: 6995bc94-0cf4-5c49-8626-80ac8486634d
STIX ID: report--6995bc94-0cf4-5c49-8626-80ac8486634d
Feed Name: cybersecurityNews.com
## Executive summary: Unit 42 identified two linked AI-assisted intrusion clusters (CL-CRI-1131, CL-CRI-1163) that used job-themed phishing, custom remote-access Trojans, and SockTz SOCKS5 tunnels to reach targets in Latin America (government, transport, municipal water, and Brazilian finance); operators leveraged hosted NextChat and LLMs (Claude, GPT-4.1) to generate and troubleshoot scripts, and the report includes IoCs such as IP addresses, duckdns domains, certificate SHA-256 fingerprints and malware hashes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
