logo

Analyste CTI et LLM: exemple d’une collaboration fructueuse

ID: 31254d5d-a783-5972-be9e-7ea029799f29

STIX ID: report--31254d5d-a783-5972-be9e-7ea029799f29

Feed Name: Intrinsec Blog

Threat Score
75/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: Gilbert KALLENBORN

...
...

A CTI investigation uncovered a targeted campaign against blockchain developers using a credible fake-recruitment repository that embedded multiple compromise vectors: an auto-executing malicious VSCode task, a trojanized npm dependency, and obfuscated JavaScript with a multi-stage staging chain, ephemeral JWTs, and C2 filtering. The analysis recovered IOCs (files: tasks.json, settings.json, package.json, config.env.example), decoded an encoded C2 URL, partially deobfuscated parser.js, and produced a structured report mapping MITRE ATT&CK techniques; the report also highlights the effective use of a large language model to accelerate static analysis while stressing the critical role of human analysts in guiding and validating findings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.