Hackers using generative AI “ChatGPT” to evade anti-virus defenses
ID: a4fd8293-1461-5020-baa7-704fa3d9ccbf
STIX ID: report--a4fd8293-1461-5020-baa7-704fa3d9ccbf
Feed Name: GBHackers
**Executive Summary:** The Kimsuky APT conducted a targeted spear-phishing campaign impersonating a South Korean defense institution by using ChatGPT to generate deepfake military ID images and delivering obfuscated .lnk shortcuts, PowerShell commands, AutoIt and batch scripts that reconstruct and execute payloads, contact C2 servers, and schedule persistent tasks; the report details technical indicators, obfuscation techniques, and recommends EDR solutions to detect behavior-based anomalies and deobfuscate execution chains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
