logo

LABScon25 Replay | LLM-Enabled Malware In the Wild

Threat Score
70/100

Date Published: 2025-11-03

Date Updated: 2026-07-27

Author: LABScon

...
...

SentinelLABS researchers present findings on LLM-enabled malware that generates malicious code at runtime—evading static signatures—while often leaving hardcoded artifacts like API keys and prompts; they propose hunting techniques (provider-specific API-key YARA rules and prompt detection coupled with lightweight LLM classifiers) and report a retrohunt uncovering over 7,000 samples (including an early “MalTerminal”), plus examples tied to PromptLock ransomware and APT28 activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.