MSFT-AI

Microsoft Threat Intelligence. (2024, February 14). Staying ahead of threat actors in the age of AI. Retrieved March 11, 2024.

Open the source

Techniques2

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1566
Phishing
GroupKimsuky

Kimsuky has used spearphishing to gain initial access and intelligence.

T1591
Gather Victim Org Information
GroupAPT28

APT28 has used large language models (LLMs) to gather information about satellite capabilities.

T1591
Gather Victim Org Information
GroupKimsuky

Kimsuky has collected victim organization information including but not limited to organization hierarchy, functions, press releases, and others. Kimsuky has also used large language models (LLMs) to gather information about potential targets of interest.

T1596
Search Open Technical Databases
GroupKimsuky

Kimsuky has used LLMs to better understand publicly reported vulnerabilities.

T1596
Search Open Technical Databases
GroupAPT28

APT28 has used large language models (LLMs) to assist in script development and deployment.

T1682
Query Public AI Services
GroupKimsuky

Kimsuky has used LLMs to identify think tanks, government organizations, and experts to inform targeting for spearphishing campaigns.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.