In the dynamic landscape of cybersecurity, the emergence of Large Language Models (LLMs) has elicited both anticipation and concern.
While some predict that LLMs will unleash a deluge of new malware, others believe these tools hold the key to solving all security challenges. However, amidst the hype, it is crucial to ground our understanding in tangible evidence.
Recent insights from Microsoft and OpenAI offer a sobering perspective, revealing that sophisticated adversaries are leveraging LLMs not to revolutionise their tactics, but to refine and augment their existing methods. Rather than heralding a seismic shift in attacker behaviour, the utilisation of LLMs by threat actors largely serves to enhance their operational effectiveness while also offering valuable insights for threat intelligence.
According to Microsoft various threat actors, including APT28 (Fancy Bear, Sofacy, Strontium, Grizzly Steppe, Sednit, SIG40, Group 74, PawnStorm, Snakemackerel, TG-4127, Tsar Team, Blue Athena, IRON TWILIGHT, Swallowtail, Threat Group-4127, Forest Blizzard, FROZENLAKE), APT37 (Thallium, Reaper, ScarCruft, InkySquid, Velvet Chollima, Konni Group, Black Banshee, Group 123, RICOCHET CHOLLIMA, NICKEL FOXCROFT, NICKEL KIMBALL, SharpTongue, RedEyes, Emerald Sleet), TortoiseShell (Houseblend, CURIUM, TA456, Crimson Sandstorm), Charcoal Typhoon (ControlX, CHROMIUM, BRONZE UNIVERSITY, RedHotel), and APT4 (Maverick Panda, Sykipot Group, Wisp, BRONZE EDISON, TG-0623, Salmon Typhoon), are actively exploring the capabilities of LLMs to bolster their cyber operations. These adversaries employ LLMs as productivity tools, utilising them for tasks such as:
These insights underscore that while LLMs offer novel capabilities, their current usage by threat actors largely aligns with traditional tactics, albeit with greater efficiency and sophistication.
Contrary to the notion of LLMs heralding a new era of cyber threats, their integration into the arsenals of sophisticated adversaries represents an evolution rather than a revolution. Threat actors are not fundamentally altering their strategies but rather leveraging LLMs to refine and amplify their existing methods. This highlights the importance for defenders to adapt their security measures accordingly.
For blue teamers, understanding how threat actors utilise LLMs provides valuable insights into potential attack vectors and vulnerabilities. Red teamers, meanwhile, can draw inspiration from these adversaries to refine their own offensive techniques and enhance their simulation exercises.
Furthermore, the specific ways in which threat actors utilise LLMs offer valuable intelligence for defenders. Looking at the Microsoft report:
While the integration of LLMs into the arsenal of sophisticated adversaries presents new challenges for defenders, it also offers opportunities for the security community to learn from and adapt to these adversaries. Ultimately, while LLMs may not herald a paradigm shift in cybersecurity, they undoubtedly represent a significant evolution in the tactics and capabilities of threat actors.
“As a premier cyber security provider, Fortian is dedicated to delivering industry-leading security solutions to our clients. Arachne Digital’s cyber threat intelligence (CTI) plays a critical role in our 24×7 Managed Security Services, empowering us to stay ahead of evolving threats and safeguard our clients’ digital assets.
Arachne Digital’s timely and actionable CTI provides us with relevant indicators that are seamlessly integrated into our security tools and processes. This integration enhances our ability to monitor, detect, and respond to threats in real-time and improves the efficiency of our threat hunting and incident response processes.
Fortian is proud to partner with Arachne Digital, and we look forward to continuing our collaboration to protect our clients against the ever-evolving cyber threat landscape.”
Arachne Digital is proud to partner with the DISARM Foundation as the inaugural member of their Partner Programme, launched at the beginning of 2024.
This partnership is crucial in supporting the DISARM Foundation’s mission to maintain and enhance the DISARM Framework, ensuring it remains a free and continuously updated resource in the fight against disinformation.
Through our collaboration, Arachne Digital provides valuable feedback, promotes the integration of the framework into our operations, and encourages wider adoption within the defender community. This partnership highlights our commitment to combating evolving threats and fostering a secure digital environment.