logo

Hackers using generative AI “ChatGPT” to evade anti-virus defenses

ID: a4fd8293-1461-5020-baa7-704fa3d9ccbf

STIX ID: report--a4fd8293-1461-5020-baa7-704fa3d9ccbf

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2025-09-15

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Executive Summary:** The Kimsuky APT conducted a targeted spear-phishing campaign impersonating a South Korean defense institution by using ChatGPT to generate deepfake military ID images and delivering obfuscated .lnk shortcuts, PowerShell commands, AutoIt and batch scripts that reconstruct and execute payloads, contact C2 servers, and schedule persistent tasks; the report details technical indicators, obfuscation techniques, and recommends EDR solutions to detect behavior-based anomalies and deobfuscate execution chains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.