Microsoft Threat Intelligence. (2024, February 14). Staying ahead of threat actors in the age of AI. Retrieved March 11, 2024.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1566 Phishing |
GroupKimsuky | Kimsuky has used spearphishing to gain initial access and intelligence. |
| T1591 Gather Victim Org Information |
GroupAPT28 | APT28 has used large language models (LLMs) to gather information about satellite capabilities. |
| T1591 Gather Victim Org Information |
GroupKimsuky | Kimsuky has collected victim organization information including but not limited to organization hierarchy, functions, press releases, and others. Kimsuky has also used large language models (LLMs) to gather information about potential targets of interest. |
| T1596 Search Open Technical Databases |
GroupKimsuky | Kimsuky has used LLMs to better understand publicly reported vulnerabilities. |
| T1596 Search Open Technical Databases |
GroupAPT28 | APT28 has used large language models (LLMs) to assist in script development and deployment. |
| T1682 Query Public AI Services |
GroupKimsuky | Kimsuky has used LLMs to identify think tanks, government organizations, and experts to inform targeting for spearphishing campaigns. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.