TA547 Uses an LLM-Generated Dropper to Infect German Orgs
ID: 8a85f603-2114-5494-895b-6ee658de2f86
STIX ID: report--8a85f603-2114-5494-895b-6ee658de2f86
Feed Name: Dark Reading
Threat Score
Proofpoint observed a TA547 phishing campaign targeting German organizations that used password-protected ZIP attachments containing LNK files which executed a PowerShell dropper to deploy the Rhadamanthys infostealer; researchers noted the dropper's code contained LLM-style, hyper-specific comments consistent with AI-generated code and discussed the operational implications of attackers leveraging AI for malware development.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
