logo

APT Meets GPT: Targeted Operations with Untamed LLMs

ID: 28835391-735d-53f2-bbb0-1bec259a4130

STIX ID: report--28835391-735d-53f2-bbb0-1bec259a4130

Feed Name: Volexity Blog

Threat Score
90/100

Date Published: 2025-10-08

Date Updated: 2026-05-01

...
...

Volexity describes UTA0388, a China-aligned threat actor using tailored spear-phishing (including rapport-building phishing) to deliver a multi-variant backdoor family called GOVERSHELL via hosted ZIP/RAR archives that exploit search-order hijacking; the report details malware capabilities, diverse C2 mechanisms, infrastructure and IOCs, and assesses the actor likely leverages LLMs to generate and scale phishing content.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.