Cookies Policy
We use strictly necessary cookies whilst you are here. These are to enable the website to work and cannot be disabled. To read more about what this means, please see our Privacy Policy.

Large Language Models (LLMs) in the Arsenal of Sophisticated Adversaries

Thread (Free) allows users to upload articles covering cyber threat actors. Thread then extracts the text on that page and - using machine learning - maps the tactics, techniques and procedures (TTPs) in the text to MITRE ATT&CK®.

Introduction

Insights 
reveal 
threat 
actors' 
evolution, 
not 
revolution. 
Adaptation 
is 
key 
for 
defence.

In the dynamic landscape of cybersecurity, the emergence of Large Language Models (LLMs) has elicited both anticipation and concern.

While some predict that LLMs will unleash a deluge of new malware, others believe these tools hold the key to solving all security challenges. However, amidst the hype, it is crucial to ground our understanding in tangible evidence.

Recent insights from Microsoft and OpenAI offer a sobering perspective, revealing that sophisticated adversaries are leveraging LLMs not to revolutionise their tactics, but to refine and augment their existing methods. Rather than heralding a seismic shift in attacker behaviour, the utilisation of LLMs by threat actors largely serves to enhance their operational effectiveness while also offering valuable insights for threat intelligence.

The Real Use Cases of LLMs
The Status Quo, but Better
LLMs as a Source of Threat Intelligence

Furthermore, the specific ways in which threat actors utilise LLMs offer valuable intelligence for defenders. Looking at the Microsoft report:

 

  • APT28 has been using LLMs to study satellite and radar technologies. In December 2022 it was reported that APT28 was hacking satellite communications providers. This interest has clearly persisted since 2022 and should be noted by defenders that look after satellite communications providers.
  • APT37’s use of LLMs involved research into think tanks and experts on North Korea, and to understand CVE-2022–30190 (Follina). Think tanks and experts on North Korea should be aware that APT37 is in their threat model, and that they use unpatched vulnerabilities for remote code execution.
  • TortoiseShell and Charcoal Typhoon are both looking to improve their social engineering. Defenders that know these groups are in their threat model should be prepared for social engineering.
  • TortoiseShell was also seen trying to lure a prominent feminist to an attacker-built website, so people advocating for women’s rights, likely within Iran, should note that TortoiseShell is in their threat model.
  • APT4 has been using LLMs to research U.S. and internal Chinese affairs, so this hints at possible targets.
Conclusion

While the integration of LLMs into the arsenal of sophisticated adversaries presents new challenges for defenders, it also offers opportunities for the security community to learn from and adapt to these adversaries. Ultimately, while LLMs may not herald a paradigm shift in cybersecurity, they undoubtedly represent a significant evolution in the tactics and capabilities of threat actors.

Benefits

Why 
select 
Arachne?

Do you want to maximise your security within your budget? Arachne Digital is the logical choice.

Our platform searches the internet for information on threat actors, gathers reports, and categorises the findings by region, industry, and threat actor. Our process automatically maps TTPs to MITRE ATT&CK®, slashing research time and saving you money.

Threat Mitigation Experts

Connect with a way to see and neutralise potential attacks before they impact your organisation. Arachne Digital empowers organisations to anticipate and avoid cyber threats by delivering actionable intelligence.

Optimised Security Posture

By integrating the precise threat intelligence provided by our reports, you can evolve, prioritise and implement effective and continually updated security controls relevant to your organisation.

Streamlined Compliance

Comprehensive, insightful threat intelligence reports support audit preparations. Demonstrate a proactive approach to cybersecurity and achieve and maintain compliance more easily.

Testimonials 
& 
Partnerships

“As a premier cyber security provider, Fortian is dedicated to delivering industry-leading security solutions to our clients. Arachne Digital’s cyber threat intelligence (CTI) plays a critical role in our 24×7 Managed Security Services, empowering us to stay ahead of evolving threats and safeguard our clients’ digital assets.

Arachne Digital’s timely and actionable CTI provides us with relevant indicators that are seamlessly integrated into our security tools and processes. This integration enhances our ability to monitor, detect, and respond to threats in real-time and improves the efficiency of our threat hunting and incident response processes.

Fortian is proud to partner with Arachne Digital, and we look forward to continuing our collaboration to protect our clients against the ever-evolving cyber threat landscape.”

Partnership

We 
are 
partnered 
with 
DISARM 
Foundation.

Arachne Digital is proud to partner with the DISARM Foundation as the inaugural member of their Partner Programme, launched at the beginning of 2024.

This partnership is crucial in supporting the DISARM Foundation’s mission to maintain and enhance the DISARM Framework, ensuring it remains a free and continuously updated resource in the fight against disinformation.

Through our collaboration, Arachne Digital provides valuable feedback, promotes the integration of the framework into our operations, and encourages wider adoption within the defender community. This partnership highlights our commitment to combating evolving threats and fostering a secure digital environment.

Get In Touch

Identify 
threat 
actors 
and 
access 
empowering 
tools 
and 
information 
for 
real-world 
applications.


Timely 
and 
actionable 
cyber 
threat 
intelligence.

Newsletter
Stay in the loop with our latest updates, exclusive offers, and content by subscribing to our newsletter.

© 2024 Arachne.Digital, ALL RIGHTS RESERVED
Built by