Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors shadow-aether-040, shadow-aether-064

shadow-aether-040, shadow-aether-064

TLP:CLEAR
Active

Description

Two distinct threat campaigns, SHADOW-AETHER-040 and SHADOW-AETHER-064, have been identified targeting government entities and financial organizations across Latin America using agentic artificial intelligence to conduct cyber intrusions. SHADOW-AETHER-040, a Spanish-speaking group, compromised six government entities in Mexico between December 2025 and January 2026, while SHADOW-AETHER-064, operating in Portuguese, targeted Brazilian financial institutions starting in April 2026. Both campaigns established SOCKS5 tunnels via ProxyChains and SSH, enabling AI agents to execute commands directly within victim networks. The AI agents dynamically generated hacking tools and scripts on-demand, reducing detection by signature-based security solutions. Despite tactical similarities including shared toolsets like Chisel, Neo-reGeorg, CrackMapExec, and Impacket, the campaigns appear to be separate entities distinguished primarily by language. These operations represent emerging cases of AI agents executing complete...

Goals & Targeting

Targeted Sectors

Government
Financial services
Aerospace
Retail

Targeted Countries / Regions

Brazil
Mexico

AI Analysis

· 2 weeks ago

Executive Summary

Shadow-Aether-040 and Shadow-Aether-064 are two distinct Spanish and Portuguese-speaking threat groups targeting government and financial entities in Latin America. Both campaigns leverage AI-driven tools to establish persistent access, using similar tactics but differentiated by language and regional focus.

Goals & Targeting

The primary goal appears to be financial gain and data exfiltration from government and financial sectors in Latin America. The targeting of specific countries aligns with their linguistic focus, suggesting a regional operational model. Victims include government agencies, financial institutions, aerospace companies, and retail sectors.

Enhanced Description

The Shadow-Aether campaigns represent an emerging breed of cyber threats where artificial intelligence is used to execute and adapt attacks in real-time. Shadow-Aether-040 operates in Spanish, targeting Mexican government entities, while Shadow-Aether-064 operates in Portuguese, focusing on Brazilian financial institutions. Both groups employ ProxyChains and SSH tunnels to create SOCKS5 proxies, enabling AI agents to issue commands within victim networks. Their use of dynamically generated tools reduces signature-based detection, making them challenging for traditional security measures. Tools like Chisel, Neo-reGeorg, CrackMapExec, and Impacket have been linked to these campaigns.

Key Capabilities

  • AI-driven dynamic tool generation
  • SOCKS5 tunnel establishment via ProxyChains and SSH
  • Lateral movement within networks using CrackMapExec and Impacket
  • Data exfiltration and persistence techniques

MITRE ATT&CK Tactics

Initial Access
Lateral Movement
Defense Evasion

ATT&CK Techniques

T1043.004
T1566.001
T1078.001
T1569

Software / Tooling

ProxyChains
Chisel
Neo-reGeorg
CrackMapExec
Impacket
PowerGrid

Campaigns & Victims

Campaigns exhibit region-specific targeting patterns, with Shadow-Aether-040 focusing on Mexico and Shadow-Aether-064 on Brazil. Both campaigns show high operational continuity, with Shadow-Aether-040 active between December 2025 and January 2026, and Shadow-Aether-064 starting in April 2026. The use of AI agents suggests an advanced capability that may evolve into more sophisticated operations over time.

IOC Patterns

  • SOCKS5 tunnel creation via ProxyChains
  • AI-generated tool usage patterns
  • Language-specific phishing attempts in Spanish/Portuguese
  • Dynamic domain generation for C2 communication

Recommended Actions

  • Monitor for SOCKS5 and SSH traffic anomalies.
  • Implement AI-based detection solutions to counter AI-driven threats.
  • Enforce multi-factor authentication (MFA) for critical systems.
  • Conduct regular patching of network protocols and tools like ProxyChains.
  • Train employees on region-specific phishing tactics in Spanish/Portuguese.

Suggested Tags

APT
cyber espionage
government
financial-services
Latin America

Confidence Assessment

Moderate confidence in the data, with clear evidence of campaign patterns and tool usage. Gaps include precise origins and specific motivations beyond financial gain or data theft. The AI aspect adds complexity but is not fully understood due to limited visibility into their development.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Financial Targeting
Government Targeting
APT
cyber espionage
government
financial-services
Latin America

Details

Type
Unknown
Confidence
55%
Added
May 14, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.