Analyzing the Current State of AI Use in Malware
ID: 919c224c-c219-5537-a96a-50675953a4b1
STIX ID: report--919c224c-c219-5537-a96a-50675953a4b1
Feed Name: Palo Alto Networks Unit 42
Unit 42 analyzed two malware samples demonstrating current AI integration trends in malware: a ConfuserEx-obfuscated .NET infostealer that calls OpenAI GPT-3.5-Turbo for logging/naïve evasion and obfuscation suggestions (largely unimplemented ‘‘AI theater’’), and a dropper that sends host telemetry to GPT-4 to gate execution of a Sliver payload. The report details four LLM-invoking functions, sample behaviors (data collection, exfiltration, opsec logging), provides SHA256 IOCs, and assesses implications of AI-assisted decision-making for future malware evolution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
