Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America

Published September 10, 2026

Attackers in Latin America are using AI tools to write custom attack code and automate stealing data from businesses after breaking in. This speeds up their theft and makes it harder to stop.

Report priority
Medium

How it works

  • Attackers use AI chatbots to write custom scripts that steal data from hacked computers.
  • The AI helps them bypass security checks and move faster through a company's systems.
  • These scripts let attackers grab files, passwords, and other sensitive info without being noticed.
  • The AI also helps them fix mistakes in their code and keep their attacks running smoothly.

What to do

If you run a business in Latin America and store sensitive data like customer records or financial info, check if your security tools have recently detected unusual activity or data transfers. Look for signs of unauthorized access, such as unexpected logins or missing files.

Update your security software and firewalls to block new attack methods. Use multi-factor authentication (MFA) for all accounts that access sensitive data. Monitor your network for unusual traffic, and consider hiring cybersecurity experts to review your defenses.

Technical details

Attackers break into a company's network, then use AI to write scripts that copy customer databases and employee records. The AI helps them avoid security software and move the stolen data to hidden servers in other countries.

Researchers observed threat actors in Latin America embedding commercial large language models (LLMs) directly into their intrusion workflows. These attackers use AI to automate script generation, troubleshoot issues in real time, and deploy proxies for post-exploitation tasks, significantly speeding up data theft and lateral movement within compromised networks. The trend demonstrates how AI is expanding beyond initial access vectors like phishing or reconnaissance into deeper, more efficient post-breach operations.