logo

Now You See Me, Now You Don’t: Using LLMs to Obfuscate Malicious JavaScript

ID: a80c56cd-3623-5aea-9d39-7206bc4b0cc7

STIX ID: report--a80c56cd-3623-5aea-9d39-7206bc4b0cc7

Feed Name: Palo Alto Networks Unit 42

Threat Score
70/100

Date Published: 2024-12-20

Date Updated: 2026-04-28

Author: Lucas Hu, Shaown Sarker, Billy Melicher, Alex Starov, Wei Wang, Nabeel Mohamed and Tony Li

...
...

Unit 42 demonstrates an adversarial ML technique that leverages large language models to iteratively rewrite malicious JavaScript (variable renaming, string splitting, dead code insertion, minification, etc.) so that static/machine-learning detectors mark it as benign while preserving behavior; their algorithm flipped a detector verdict 88% of the time and produced variants that evaded multiple vendors on VirusTotal. The report includes real-world phishing examples and IOCs (URLs and SHA256 hashes), compares LLM-based rewrites to off-the-shelf obfuscators, and shows defenders can mitigate the threat by augmenting training data with LLM-rewritten samples—yielding an approximate 10% improvement in detection when retrained.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.