Two distinct threat campaigns, SHADOW-AETHER-040 and SHADOW-AETHER-064, have been identified targeting government entities and financial organizations across Latin America using agentic artificial intelligence to conduct cyber intrusions. SHADOW-AETHER-040, a Spanish-speaking group, compromised six government entities in Mexico between December 2025 and January 2026, while SHADOW-AETHER-064, operating in Portuguese, targeted Brazilian financial institutions starting in April 2026. Both campaigns established SOCKS5 tunnels via ProxyChains and SSH, enabling AI agents to execute commands directly within victim networks. The AI agents dynamically generated hacking tools and scripts on-demand, reducing detection by signature-based security solutions. Despite tactical similarities including shared toolsets like Chisel, Neo-reGeorg, CrackMapExec, and Impacket, the campaigns appear to be separate entities distinguished primarily by language. These operations represent emerging cases of AI agents executing complete...
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Shadow-Aether-040 and Shadow-Aether-064 are two distinct Spanish and Portuguese-speaking threat groups targeting government and financial entities in Latin America. Both campaigns leverage AI-driven tools to establish persistent access, using similar tactics but differentiated by language and regional focus.
Goals & Targeting
The primary goal appears to be financial gain and data exfiltration from government and financial sectors in Latin America. The targeting of specific countries aligns with their linguistic focus, suggesting a regional operational model. Victims include government agencies, financial institutions, aerospace companies, and retail sectors.
Enhanced Description
The Shadow-Aether campaigns represent an emerging breed of cyber threats where artificial intelligence is used to execute and adapt attacks in real-time. Shadow-Aether-040 operates in Spanish, targeting Mexican government entities, while Shadow-Aether-064 operates in Portuguese, focusing on Brazilian financial institutions. Both groups employ ProxyChains and SSH tunnels to create SOCKS5 proxies, enabling AI agents to issue commands within victim networks. Their use of dynamically generated tools reduces signature-based detection, making them challenging for traditional security measures. Tools like Chisel, Neo-reGeorg, CrackMapExec, and Impacket have been linked to these campaigns.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Campaigns exhibit region-specific targeting patterns, with Shadow-Aether-040 focusing on Mexico and Shadow-Aether-064 on Brazil. Both campaigns show high operational continuity, with Shadow-Aether-040 active between December 2025 and January 2026, and Shadow-Aether-064 starting in April 2026. The use of AI agents suggests an advanced capability that may evolve into more sophisticated operations over time.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in the data, with clear evidence of campaign patterns and tool usage. Gaps include precise origins and specific motivations beyond financial gain or data theft. The AI aspect adds complexity but is not fully understood due to limited visibility into their development.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics