LABScon25 Replay | LLM-Enabled Malware In the Wild
ID: db643f0d-d545-50de-9f10-0b484527ad4e
STIX ID: report--db643f0d-d545-50de-9f10-0b484527ad4e
Threat Score
SentinelLABS researchers present findings on LLM-enabled malware that generates malicious code at runtime—evading static signatures—while often leaving hardcoded artifacts like API keys and prompts; they propose hunting techniques (provider-specific API-key YARA rules and prompt detection coupled with lightweight LLM classifiers) and report a retrohunt uncovering over 7,000 samples (including an early “MalTerminal”), plus examples tied to PromptLock ransomware and APT28 activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
