--[ Anomalía #18 - AI Didn't Arrive Alone ]--

October 2, 2026

By: ZoqueLabs

This writing is distributed under a Creative Commons CC BY-SA (Acknowledgment - Share Alike) license.

Spanish version

 

Until recently, it was easy to think of AI as something we use: we ask it something, we ask it to write code, to review a document, or to generate an image. But in this edition, several cases appear where it’s already doing something more.

There’s malware that consults models to decide what to do after gaining access to a computer. There are agents that can help us review files, perform reverse engineering, or look for patterns during an investigation. And there are tools that automate tasks that previously required considerably more time and human effort.

That doesn’t mean that everything is suddenly autonomous. There are still people making decisions, systems in testing, and processes that require human intervention. The interesting thing is that AI is starting to get inside those processes, doing part of the work instead of simply responding when someone asks it something.

And when we look at so-called nudify apps, we see something similar, but from a much darker perspective.

A report by the Institute for Strategic Dialogue (ISD) found 181 sites that allow users to upload photos of real people and generate sexualized images or videos. Between December 2025 and March 2026, they received, on average, more than 40 million unique visitors per month. The most visited site exceeded nine million in a single month.

Yes, nine million.

Interestingly, these tools don’t operate in isolation. They are found through search engines, promoted on social media, circulated via bots and Telegram channels, and have affiliate programs and payment mechanisms. Even app stores have become part of this process.

This connects to something we’d already seen in Anomalía. A few months ago, we discussed ads on Meta promoting these apps, apps on Google Play and the App Store, and tools accumulating millions of downloads. The ISD report helps put those pieces together: it wasn’t just apps appearing and disappearing. There’s a whole ecosystem surrounding them that allows you to find, use, pay for, and circulate them.

And that ecosystem is making it much easier to reproduce a form of digital violence we already know: creating and distributing sexualized content of real people without their consent. A completely ordinary photograph posted on social media can now become the raw material for fabricating something that never happened.

Privacy takes a different turn here. It’s no longer just about protecting an existing intimate image, but also about considering what other people can do with the images we voluntarily make public.

And this brings us back to the other side of the story: we are also incorporating AI into our processes.

An agent can help us review large amounts of files, reverse engineer them, find patterns, or accelerate tasks that would normally take hours. This can be incredibly useful for investigating threats, but it also forces us to consider what information we’re giving it, where it’s processed, what it has access to, and what results we need to review.

In other words, incorporating AI also means incorporating it into our threat models.

And those on the other side are conducting their own experiments. We already see malware consulting models during an infection and AI tools integrated into ecosystems of digital violence. We’ll likely see much more.

That’s why perhaps the interesting question is no longer just what can AI do, but what processes it’s interfering with and what changes when it enters them.

For those of us who work in threat intelligence and digital security for activism, it’s time to learn to navigate this space as well: to leverage these tools when they help us investigate or defend ourselves, but understanding what we’re giving them and maintaining human oversight of what they do.

And at the same time, to look at the other side: how are those who attack, monitor, manipulate, or perpetrate violence incorporating them?

Because AI didn’t arrive alone. It’s entering ecosystems, tools, and ways of doing things that already existed.

And that’s probably much more interesting than another chatbot.

Now, the long-awaited Anomalies. :)

--[ Surveillance ]--

Morocco - A surveillance network combining spyware, networks, and physical surveillance

Amnesty International documented a surveillance system used against journalists, activists, and human rights defenders in Morocco that combines several technical layers. The report identifies the use of Pegasus, zero-click attacks, network injection through the Maroc Telecom network, RCS physically installed on devices, geolocation systems, and even forensic extraction tools. It also documents the use of pre-infected phones and devices seized in internet cafes or during airport security checks. Nearly 13,000 Moroccan phone numbers were identified as potential targets in the analyzed records.

Amnesty International

Oxygen Forensics - The forensic software that ended up in Russian hands

Oxygen Forensics sells tools to extract and analyze information from phones and computers, a sort of neighbor of Cellebrite in the world of digital forensics. Its products ended up in the hands of law enforcement agencies in several European countries, and it also participated in projects funded by the European Union. Now, a US Department of Justice indictment alleges that the company was controlled by five Russian nationals and that the software continued to be developed in Russia. The same structure controlled a Russian company, MKO Systems, which sold technology related to the FSB, the Investigative Committee, and the Russian Ministry of Internal Affairs. The problem doesn’t end there: according to the indictment, after the expanded sanctions against Russia following the war with Ukraine, the owners and executives concealed the Russian ownership and origin of the technology in order to continue doing business with the US government. The response came in the form of a fraud indictment, with accounts, domains, and infrastructure seized, not as a sanctions case.

Politico.eu

DraftKings uses AI to identify those most likely to lose

DraftKings is using its customers’ betting records to train a machine learning model that identifies people most likely to place losing bets and then targets them with promotions to encourage them to gamble again. According to the report, the model may end up targeting precisely those who already have problematic gambling patterns: instead of using that data to reduce risk, it’s used to increase the likelihood that they will continue gambling. The disturbing thing is that this doesn’t require purchasing third-party data: the very data a platform collects about our behavior can be enough to build a vulnerability profile and turn it into a business strategy. AI simply makes that processing much faster and at a larger scale.

EFF

--[ Digital Violence ]--

AI Accelerates the Production of Digital Violence Against Women

A recent UN Women report, based on responses from 641 women in 119 countries, found that one in four participants had experienced some form of AI-assisted violence, including deepfakes, sexualized images, and “undressing” tools. A single one of these applications had generated more than 3 million manipulated images by January 2026, reaching a peak of 6,700 per hour. The problem doesn’t end with the circulation of content: 41% of participants said they had limited what they post on social media as a result of digital violence, and among female writers and public communicators, the figure reached 50%. AI is reducing the time and cost of producing these attacks, while reporting, removing, and obtaining an institutional response remains much slower.

Wired

Nudify apps already form an ecosystem

As we mentioned in the editorial, the ISD report shows the scale that the generation of sexualized images without consent is reaching: 181 sites and more than 40 million unique visitors per month. The report also documents cases of promotion using images of minors and services that claim to prohibit such uses but lack real mechanisms to verify age.

ISD Global

--[ IA ]--

Malware reverse engineering in agent mode

A malware researcher recounts how he went from using AI for specific tasks—like generating YARA rules or explaining disassembled code—to building an agent system that distributes tasks among static analysis, reverse engineering, IOC extraction, enrichment, detection of evasion techniques, and report generation. In a demonstration, the system took an unknown sample and completed the analysis in about 30 minutes—a task that previously could take days or weeks. The author also clarifies where the interesting part lies: for this to be reliable, it needs visibility into what the agents are doing, what tools they call, what information they consult, and where human review is needed.

X

CLOSEDQUORUM - Malware that Leaves Some Decisions to AI

Cisco Talos discovered malware for Windows called CLOSEDQUORUM that can consult up to four AI models—DeepSeek, Qwen, Mistral, and Gemini—to decide what to do after gaining access to a computer. The program provides them with basic computer information, and the models choose from predefined actions, such as stealing credentials, maintaining access, or injecting code into other processes. Talos did not confirm that CLOSEDQUORUM was used in real attacks: the analyzed public file contained fake API keys and a fake webhook, although its development versions show that this logic was ready to operate. It is an early example of malware where some operational decisions no longer depend directly on someone behind the scenes giving instructions.

Tallos Intelligence

Ransomware Tests AI-Generated Malware During an Intrusion

In an operation attributed to Hive0163 – an actor identified in attacks against Mexico and Brazil – IBM X-Force researchers found Slopoly, a PowerShell backdoor they believe was possibly generated using a language model. The malware is not particularly sophisticated: it maintains access to the computer, gathers basic information, and receives commands from a remote server. What is unusual is that it didn’t appear as a lab test, but rather within a real intrusion that ended with Interlock ransomware. The case demonstrates a fairly concrete use of AI in the malware lifecycle: not to replace the attacker, but to quickly produce a functional piece of malicious code.

CYBLE

--[ Malware ]--

LATAM - A movie that ends up being something else

Kaspersky has discovered a campaign using movies as bait to distribute malware in Latin America. In Colombia, for example, they detected a case in August where someone downloaded a file that appeared to be Oak Street End (2026), but was actually a Windows program. Once opened, the malware can remain on the computer after a restart, gaining more permissions and allowing remote access. The files circulate on unofficial download sites and can easily spread from one country to another; The Odyssey also appeared among the baits. The campaign also uses the Solana blockchain network to locate the infrastructure from which it receives instructions, making it more difficult to block completely.

LATAM Kaspersky

Mexico and Brazil - ShinyHunters Exploits SharePoint Again

ShinyHunters has once again exploited the CVE-2026-35273 vulnerability in Oracle PeopleSoft, this time in a broader campaign that now includes higher education, technology, healthcare, agriculture, transportation, and government organizations in Mexico and Brazil. The group modified its exploit to evade the WAF rules that blocked the SharePoint vulnerability, using a coded variation of the same path. Mandiant observed dozens of compromised systems and the deployment of web shells and backdoors to maintain access. It is the same actor we had previously identified in Anomaly, but now they are back with a campaign adapted to the defenses that organizations had put in place.

Google

LATAM - PDFs remain a fairly common entry point

. ESET recorded more than 107,000 PDF/phishing detections in Latin America during the first half of 2026. In Brazil, PDFs accounted for approximately 55% of the files associated with email threats. The format appears in campaigns ranging from a link or QR code within the document to longer malware download chains. In one case observed in Colombia, for example, the email led to a PDF that directed to a website, from which a RAR file was downloaded, ultimately installing a remote access Trojan. The PDF wasn’t necessarily the malware itself; it was the step that made the rest of the chain appear to be just another document.

ESET

LATAM - Residential proxies that can end up being used for malicious traffic

Residential proxy networks allow third parties to connect to the internet using a computer’s IP address or a home connection. Gen Threat Labs found 20.8 million blocked attacks associated with these networks between January and mid-September 2026, primarily phishing, malvertising, and various types of malware. The map also shows a significant presence in Latin America: Brazil ranks fourth, with approximately 131,000 observations of devices associated with these networks, and Mexico ninth, with around 57,000. And we’re not just talking about Windows computers: researchers have also found this type of infrastructure within Android applications, smart TVs, routers, and other connected devices. In practice, a home connection can end up being the point from which someone else launches a phishing campaign, distributes malware, or automates abusive traffic, while to the destination service, everything appears to originate from a common residential IP address. The study does not attribute these attacks to proxy providers; it shows how these networks can become an infrastructure layer for malicious traffic.

Gen Digital

--[ Leaks ]--

Argentina - Government investigates possible leak of Mi Argentina

The Argentine government is investigating a possible leak that could affect 6 million records from Mi Argentina, the state’s digital identity platform. The extent is not yet confirmed: it has also not been publicly reported what data would be involved or whether the exfiltration actually occurred. The platform stores sensitive documents and data of users, such as identity information, driver’s licenses, health credentials, and digitized official documentation.

Data Trends LATAM

--[ Cybercrime ]--

Chile - TeamFiltration finds accounts no one was looking at again.

Proofpoint detected a password spraying campaign between July and August against more than 5,700 accounts in 28 Microsoft 365 tenants in Latin America, concentrated especially in Chilean organizations. The most striking detail is the seven compromised accounts: all were functional or service accounts, with no prior legitimate usage logs and no MFA, apparently created with default passwords that were never changed. In one case, after gaining access, the attacker moved from the AWS infrastructure used for the spraying to a VPN in Germany and from there accessed Azure Portal, Office, SharePoint, and Microsoft Graph.

Proofpoint

--[ Exfiltradaz - Snapshot from 09/18/2026 to 10/02/2026 ]--

During this period, 17 references to leaks, compromised access, and ransomware-related posts were identified in five Latin American countries. Brazil had the highest number of observed records, with 12 references, followed by Ecuador, with two. The most frequent sectors were Credential Marketplace and Ransomware, with six records each.

Ransomware-related activity included posts about organizations in Ecuador, El Salvador, Brazil, and Venezuela. Among them are the Automobile Club of Ecuador (ANETA), the Catholic University of El Salvador, the Brazilian Federal Revenue Service, K3G Solutions Brazil, and Inter, one of Venezuela’s main internet providers. Posts related to Brazilian email access credentials were also identified, some advertised as “fresh” or “valid.”

During this period, references to recirculating databases also appeared, such as a post containing 3 million records from JavaTrading.com.br, in addition to new authors being monitored: lolcloud01 and lolcloud0123. The main sources observed were niflheim, ransomware, crdcrew, cracked, and hard-tm, which encompass various methods of publishing and selling data and access credentials.

More details on these leaks can be found at Exfiltradaz.

--[ ZOLIM --> Snapshot 02/10/2026 ]--

13 new and very interesting IPs for this ZOLIM snapshot. With these, we now have 285 servers detected since we started the observatory. :)

Some interesting signs:

If you want to delve deeper, take a look at ZOLIM. In the table at the bottom, you can search and cross-reference the data by country, ASN, IP address, threat level, city, and other fields. Every IP address is a good excuse to start investigating. :)