Analyste CTI et LLM: exemple d’une collaboration fructueuse
ID: 31254d5d-a783-5972-be9e-7ea029799f29
STIX ID: report--31254d5d-a783-5972-be9e-7ea029799f29
Feed Name: Intrinsec Blog
A CTI investigation uncovered a targeted campaign against blockchain developers using a credible fake-recruitment repository that embedded multiple compromise vectors: an auto-executing malicious VSCode task, a trojanized npm dependency, and obfuscated JavaScript with a multi-stage staging chain, ephemeral JWTs, and C2 filtering. The analysis recovered IOCs (files: tasks.json, settings.json, package.json, config.env.example), decoded an encoded C2 URL, partially deobfuscated parser.js, and produced a structured report mapping MITRE ATT&CK techniques; the report also highlights the effective use of a large language model to accelerate static analysis while stressing the critical role of human analysts in guiding and validating findings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
