logo

TA547 Uses an LLM-Generated Dropper to Infect German Orgs

ID: 8a85f603-2114-5494-895b-6ee658de2f86

STIX ID: report--8a85f603-2114-5494-895b-6ee658de2f86

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2024-04-10

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Proofpoint observed a TA547 phishing campaign targeting German organizations that used password-protected ZIP attachments containing LNK files which executed a PowerShell dropper to deploy the Rhadamanthys infostealer; researchers noted the dropper's code contained LLM-style, hyper-specific comments consistent with AI-generated code and discussed the operational implications of attackers leveraging AI for malware development.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.