Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
AI supported rapid environmental analysis, identification of an OT-adjacent environment... and generation of a viable access path towards the IT-OT boundary
The campaign, OpenAI said, used its technologies to generate articles and shorter comments posted on websites and on social media. In some cases, the campaign used ChatGPT to rewrite comments posted by other social media users.
OpenAI ... banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments.
The influence operation ... relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Telegram, X, Facebook and LinkedIn.
This week, OpenAI identified several ChatGPT accounts that were using its chatbot to generate text and images for a covert Iranian campaign that the company called Storm-2035.
The posts later appeared across the Western web, on platforms including X, LinkedIn, Facebook, Substack, and Telegram... often using AI-generated personas, profile photos, and face-to-camera video reels.
The AI-tooling Dragos analyzed "leveraged known techniques and existing vulnerability knowledge to enumerate systems and services and attempt exploitation," | The generative AI tools helped the attacker with identifying a possible gateway to the utility's OT systems... The infrastructure was a vNode industrial gateway
Hackers deleted virtual machines and used backup software to wipe disks... The group also claimed responsibility for wiping data in SQL database in South Florida's Tri-Rail commuter transit system... deleting volumes at Saudi Arabian civil construction company UNIMAC and running a destruction script in SQL Server targets at vehicle tracking company Vyncs.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used by Black Basta operators to generate deceptive messages, rewrite malware code, debug tooling, and automate victim information collection. It is not malware itself but is a named tool heavily discussed in the content.
Illicit Microsoft Visual Studio Code extensions posing as AI coding assistants that exfiltrate developer data to China-based servers. They transmit files opened in VS Code in real time, can receive a server-controlled command to harvest and covertly transmit up to 50 files, and use a zero-pixel iframe to load multiple commercial analytics for user-activity monitoring—risking exposure of source code, cloud credentials, and configuration files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.