Cards intentionally contain only a title, short description, canonical resource link, and discovery tags. Every tag remains visible and clickable; expand a card to inspect the complete tag set.
Core research
Find related
Palo Alto Networks Unit 42 operational CTI publication covering CAPTCHA bypass, Identity fraud and impersonation, and Malware development. Indexed with FunkSec, Artificial Intelligence, and Anthropic context.
AI relevance core_ai_attackAI technology Agentic AIAI technology Large language modelAI use case CAPTCHA bypassAI use case Identity fraud and impersonationAI use case Malware developmentAI use case Obfuscation and evasionAI use case Reconnaissance and target researchAttack vector Credential theftCountry or region ChinaCountry or region IndiaCountry or region Japan
Show 86 more tags Country or region South KoreaData type Credentials and passwordsData type Documents and filesEvidence inventory Contains extracted IOCsEvidence inventory Contains extracted metricsEvidence landscape Incident responseEvidence landscape Proof of conceptEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 1062 Targets · medium confidenceExtracted metric · Blast Radius 12 samples · medium confidenceExtracted metric · Blast Radius 405 samples · medium confidenceExtracted metric · Blast Radius more than 50 organizations · medium confidenceExtracted metric · Blast Radius over 6,500 endpoint · medium confidenceExtracted metric · Percentage 100% · medium confidenceExtracted metric · Percentage 3.0% · medium confidenceExtracted metric · Percentage 3% · medium confidenceExtracted metric · Percentage 4% · medium confidenceExtracted metric · Percentage 97% · medium confidenceImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure EndpointInfrastructure MobileInfrastructure SaaSIOC · Sha256 1619bcad3785be31ac2fdee0ab91392d08d9392032246e42673c3cb8964d4cb7IOC · Sha256 20ed21bfdb7aa970b12e7368eba8e26a711752f1cc5416b6fd6629d0e2a44e5dIOC · Sha256 4fb58687a364c3f6d6f7e0ca03654f9dec0f8832a499d61d40b0d424db1b1b14IOC · Sha256 5226ea8e0f516565ba825a1bbed10020982c16414750237068b602c5b4ac6abdIOC · Sha256 66dbf939c00b09d8d22c692864b68c4a602e7a59c4b925b2e2bef57b1ad047bdIOC · Sha256 b1ef7b267d887e34bf0242a94b38e7dc9fd5e6f8b2c5c440ce4ec98cc74642fbIOC · Sha256 bb932056cae8940742e50b4f2b994a802e703f7bc235e7dd647d085ae2b2baf7IOC · Sha256 c233aec7917cf34294c19dd60ff79a6e0fac5ed6f0cb57af98013c08201a7a1cIOC · Sha256 c398b3e06ef860670b9597daed85632834fa961aea87164b8ba8bb2f094a14efIOC · Sha256 dcf536edd67a98868759f4e72bcbd1f4404c70048a2a3257e77d8af06cb036acIOC · Sha256 dd15ce869aa79884753e3baad19b0437075202be86268b84f3ec2303e1ecd966IOC · Sha256 e622f3b743c7fc0a011b07a2e656aa2b5e50a4876721bcf1f405d582ca4cda22Kill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase InstallationKill Chain phase ReconnaissanceLLM model ChatGPTLLM model ClaudeLLM provider AnthropicLLM provider OpenAIMalware or tool FunkSecMalware or tool FunkSec ransomwareMalware or tool JavaScript backdoorMalware or tool RhadamanthysMalware or tool TuxBotMITRE tactic CollectionMITRE tactic Command and ControlMITRE tactic Credential AccessMITRE tactic Defense EvasionMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic PersistenceMITRE tactic ReconnaissancePublication date method MetadataPublication date precision DayPublisher Palo Alto Networks Unit 42Publisher domain unit42.paloaltonetworks.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector Artificial IntelligenceSector Critical InfrastructureSector CryptocurrencySource type operational CTI publicationStatistical use incident_or_observationTarget DevelopersTarget EmployeesTarget ExecutivesThreat group FunkSecTTP CAPTCHA bypassTTP Command and controlTTP Credential harvestingTTP Credential theftTTP Data exfiltrationTTP Defense evasionTTP PowerShell executionTTP Target research / OSINTYear 2026
Core research
Find related
Cisco Talos operational CTI publication covering Code debugging and scripting, Identity fraud and impersonation, and Obfuscation and evasion. Indexed with UAT-10147, Education, and Anthropic context.
Actor motivation FinancialAI relevance core_ai_attackAI technology Agentic AIAI technology Generative AIAI use case Code debugging and scriptingAI use case Identity fraud and impersonationAI use case Obfuscation and evasionAI use case Reconnaissance and target researchAI use case Vulnerability researchAttack vector Credential theftCountry or region BrazilCountry or region Canada
Show 73 more tags Country or region ChinaCountry or region VietnamCVE CVE-2010-3904CVE CVE-2015-3246CVE CVE-2015-5287CVE CVE-2019-18935CVE CVE-2021-23758CVE CVE-2021-29441CVE CVE-2021-29442CVE CVE-2021-3156CVE CVE-2022-0847CVE CVE-2022-0995CVE CVE-2022-27925Data type Credentials and passwordsData type Documents and filesData type Source codeEvidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence landscape Incident responseEvidence landscape Proof of conceptEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 0995 targets · medium confidenceImpact Data theft or exfiltrationInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure EndpointInfrastructure SaaSKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationKill Chain phase ReconnaissanceKill Chain phase WeaponizationLLM model ClaudeLLM model GeminiLLM provider AnthropicLLM provider GoogleMalware or tool BadIIS malwareMalware or tool QuasarRATMITRE tactic Command and ControlMITRE tactic Credential AccessMITRE tactic Defense EvasionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic Initial AccessMITRE tactic PersistenceMITRE tactic Privilege EscalationMITRE tactic ReconnaissancePublication date method MetadataPublication date precision DayPublisher Cisco TalosPublisher domain blog.talosintelligence.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector EducationSector GovernmentSource type operational CTI publicationStatistical use incident_or_observationTarget DevelopersTarget Security researchersThreat group UAT-10147Threat-group identifier UAT-10147TTP Command and controlTTP Credential theftTTP Data exfiltrationTTP Defense evasionTTP PowerShell executionTTP Vulnerability scanningYear 2026
Core research
Find related
Cisco Talos operational CTI publication covering Malware development, Reconnaissance and target research, and Translation and localization. Indexed with UAT-10147, Cryptocurrency, and Anthropic context.
AI relevance core_ai_attackAI technology Agentic AIAI technology Large language modelAI use case Malware developmentAI use case Reconnaissance and target researchAI use case Translation and localizationAI use case Vulnerability researchAttack vector Credential theftCountry or region BrazilCountry or region ChinaCountry or region FranceCountry or region Russia
Show 62 more tags Data type Credentials and passwordsData type Documents and filesData type Source codeEvidence inventory Contains extracted IOCsEvidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence landscape Incident responseEvidence landscape Proof of conceptEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 54 targets · medium confidenceExtracted metric · Blast Radius over 1,300 users · medium confidenceExtracted metric · Duration Or Dwell 15 minutes · medium confidenceExtracted metric · Duration Or Dwell 30 seconds · medium confidenceExtracted metric · Duration Or Dwell 84500 seconds · medium confidenceExtracted metric · Percentage 0.0% · medium confidenceExtracted metric · Percentage 100% · medium confidenceImpact Service disruptionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure EndpointInfrastructure Messaging platformInfrastructure MobileInfrastructure SaaSIOC · Defanged Domain ixmax[.]cnIOC · Defanged Domain tubely[.]comKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationKill Chain phase ReconnaissanceLLM model ClaudeLLM model GeminiLLM provider AnthropicLLM provider GoogleLLM provider Hugging FaceLLM provider OpenAIMITRE tactic CollectionMITRE tactic Command and ControlMITRE tactic Credential AccessMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic Initial AccessMITRE tactic PersistenceMITRE tactic ReconnaissancePublication date method MetadataPublication date precision DayPublisher Cisco TalosPublisher domain blog.talosintelligence.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector CryptocurrencySource type operational CTI publicationStatistical use incident_or_observationTarget DevelopersThreat group UAT-10147Threat-group identifier UAT-10147TTP Command and controlTTP Credential theftYear 2026
Core research
Find related
Palo Alto Networks Unit 42 operational CTI publication covering Autonomous or agentic intrusion, CAPTCHA bypass, and Exploit development. Indexed with Anthropic context.
AI relevance core_ai_attackAI technology Agentic AIAI technology Generative AIAI use case Autonomous or agentic intrusionAI use case CAPTCHA bypassAI use case Exploit developmentAI use case Vulnerability researchAttack vector Credential theftAttack vector Supply chainCountry or region ChinaCVE CVE-2025-40947CVE CVE-2025-40948
Show 55 more tags CVE CVE-2026-0257Data type Credentials and passwordsData type Documents and filesData type Source codeEvidence inventory Contains extracted metricsEvidence landscape Controlled studyEvidence landscape Incident responseEvidence landscape Proof of conceptEvidence quality Usable Machine ExtractionExtracted metric · Duration Or Dwell 55 days · medium confidenceExtracted metric · Duration Or Dwell 8 weeks · medium confidenceExtracted metric · Percentage 28.6% · medium confidenceExtracted metric · Percentage 39.7% · medium confidenceExtracted metric · Percentage 4.0% · medium confidenceExtracted metric · Percentage 40% · medium confidenceExtracted metric · Percentage 8.0% · medium confidenceExtracted metric · Percentage 92% · medium confidenceExtracted metric · Percentage 99.4% · medium confidenceImpact Ransomware or extortionImpact Service disruptionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure EndpointInfrastructure Messaging platformInfrastructure SaaSKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase ReconnaissanceLLM model ChatGPTLLM model ClaudeLLM provider AnthropicLLM provider OpenAIMITRE tactic Credential AccessMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic Initial AccessPublication date method MetadataPublication date precision DayPublisher Palo Alto Networks Unit 42Publisher domain unit42.paloaltonetworks.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSource type operational CTI publicationStatistical use incident_or_observationTarget DevelopersTarget EmployeesTarget ExecutivesTTP CAPTCHA bypassTTP Credential theftTTP Exploit developmentTTP Supply-chain compromiseTTP Vulnerability scanningYear 2026
Core research
Find related
INTERPOL government or law-enforcement publication covering Deepfake video or image, Reconnaissance and target research, and Business email compromise. Indexed with Financial Services context.
AI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI use case Deepfake video or imageAI use case Reconnaissance and target researchAttack vector Business email compromiseAttack vector Credential theftCampaign Operation ContenderCampaign Operation Red CardCampaign Operation SentinelCampaign Operation SerengetiCountry or region AfricaCountry or region France
Show 34 more tags Country or region United KingdomData type Credentials and passwordsData type Documents and filesEvidence inventory Contains extracted metricsEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 17 countries · medium confidenceImpact Financial fraudImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure EmailInfrastructure Social mediaKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase ReconnaissanceMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic ReconnaissancePublication date method TextPublication date precision DayPublisher INTERPOLPublisher domain interpol.intRelevance basis official advisory, fraud alert, or regional threat reportRetrieval method DirectReview requirement Manual review requiredSector Financial ServicesSector MediaSector TelecommunicationsSource type government or law-enforcement publicationStatistical use context_or_incidentTarget Consumers or individualsTTP Business email compromiseTTP Credential harvestingYear 2026
Core research
Find related
Palo Alto Networks Unit 42 operational CTI publication covering Autonomous or agentic intrusion, CAPTCHA bypass, and Exploit development. Indexed with Government and Anthropic context.
AI relevance core_ai_attackAI technology Generative AIAI technology Large language modelAI use case Autonomous or agentic intrusionAI use case CAPTCHA bypassAI use case Exploit developmentAI use case Phishing and lure generationCampaign Operation Hermes AgentCountry or region ChinaCountry or region IndiaCountry or region JapanCountry or region Russia
Show 74 more tags Country or region South KoreaCVE CVE-2023-33538CVE CVE-2025-0921CVE CVE-2025-40947CVE CVE-2025-40948CVE CVE-2025-68613CVE CVE-2026-0257CVE CVE-2026-0300CVE CVE-2026-1281CVE CVE-2026-1340CVE CVE-2026-1731CVE CVE-2026-21858CVE CVE-2026-3055CVE CVE-2026-31431CVE CVE-2026-33017CVE CVE-2026-33824CVE CVE-2026-34486CVE CVE-2026-39987Data type Credentials and passwordsData type Documents and filesEvidence inventory Contains extracted IOCsEvidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence landscape Incident responseEvidence landscape Proof of conceptEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 100 systems · medium confidenceExtracted metric · Blast Radius over 460 targets · medium confidenceImpact Data theft or exfiltrationInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure EndpointInfrastructure Messaging platformInfrastructure SaaSIOC · Defanged Domain aliyuncs[.]comIOC · Defanged Domain deepseek[.]comIOC · Defanged Domain newcli[.]comKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase WeaponizationLLM model ChatGPTLLM model ClaudeLLM model DeepSeekLLM provider AnthropicLLM provider DeepSeekLLM provider OpenAIMITRE tactic Command and ControlMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic Initial AccessMITRE tactic Privilege EscalationPublication date method MetadataPublication date precision DayPublisher Palo Alto Networks Unit 42Publisher domain unit42.paloaltonetworks.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector GovernmentSource type operational CTI publicationStatistical use incident_or_observationTarget EmployeesTarget ExecutivesTarget Security researchersTTP CAPTCHA bypassTTP Command and controlTTP Data exfiltrationTTP Exploit developmentTTP PowerShell executionYear 2026
Core research
Find related
Palo Alto Networks Unit 42 operational CTI publication covering CAPTCHA bypass, Malware development, and Command and control. Indexed with Cryptocurrency and Anthropic context.
AI relevance core_ai_attackAI technology Large language modelAI use case CAPTCHA bypassAI use case Malware developmentAttack vector Credential theftCountry or region IndiaCountry or region IranCountry or region JapanCountry or region South KoreaCVE CVE-2007-3010CVE CVE-2007-5693CVE CVE-2013-7471
Show 128 more tags CVE CVE-2014-2321CVE CVE-2014-8361CVE CVE-2016-11021CVE CVE-2017-17215CVE CVE-2017-18377CVE CVE-2018-10561CVE CVE-2018-10562CVE CVE-2018-20062CVE CVE-2020-17456CVE CVE-2020-8515CVE CVE-2021-25646CVE CVE-2021-4045CVE CVE-2022-1388CVE CVE-2022-22947CVE CVE-2022-22965CVE CVE-2022-30525CVE CVE-2022-44877CVE CVE-2023-1389CVE CVE-2023-39780CVE CVE-2025-34037CVE CVE-2025-34117CVE CVE-2026-5815Data type Credentials and passwordsData type Documents and filesData type Source codeEvidence inventory Contains extracted IOCsEvidence inventory Contains extracted metricsEvidence landscape In-the-wild observedEvidence landscape Incident responseEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 17 target · medium confidenceExtracted metric · Blast Radius 17 targets · medium confidenceExtracted metric · Blast Radius 20 domains · medium confidenceExtracted metric · Blast Radius 20 system · medium confidenceExtracted metric · Blast Radius 82 samples · medium confidenceExtracted metric · Blast Radius 9 samples · medium confidenceExtracted metric · Blast Radius approximately 92 individual · medium confidenceExtracted metric · Duration Or Dwell 10 seconds · medium confidenceExtracted metric · Duration Or Dwell 5 seconds · medium confidenceExtracted metric · Percentage 5% · medium confidenceExtracted metric · Percentage 70% · medium confidenceImpact Data theft or exfiltrationImpact Ransomware or extortionImpact Service disruptionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure EndpointInfrastructure MobileInfrastructure SaaSIOC · Defanged Domain digikalas[.]onlineIOC · Defanged Domain jetross[.]comIOC · Sha1 2774a5f5991657eb9b0062cd3da0391c9bad2643IOC · Sha1 304e14a138b92135aad27bb37f4e9db440401ec2IOC · Sha1 4cba585d9f208bd712b28f867f908e503ccc9cfeIOC · Sha1 4e1483737f769e1cee80fa4d7a056a5d8e3b537eIOC · Sha1 64af594c7f91793813e3d769e63816b143102396IOC · Sha1 69dc276dde8efcb409411508da55d4cbe28d5600IOC · Sha1 74fba0bad93bbb0e1eedb196b6efe6af1c0bf23dIOC · Sha1 7ad840b1945cc346012987727ebcc062431965a4IOC · Sha1 81670f250f4b3492fd3e00920f9fe7395ecbf85cIOC · Sha1 877b804892ab218a53420b6dfbd0a2837368d0b5IOC · Sha1 a70cea846442c18ad265f311b5ced29a4071771dIOC · Sha1 a8fd13f6b1bdfa87c0f466df69b7e81325b5dd15IOC · Sha1 adf267caab78a74c4b4dfabe7b578b0a4d639782IOC · Sha1 b1cc41e2b9ddb11d0c9d03d319531fea9459cdaeIOC · Sha1 b21cdc5e1b96c640a1d553ed518c49729e367823IOC · Sha1 befb0e4d1cd7d2b4139b55f811993af2c8839e75IOC · Sha1 cd540bb31909440fd2bf773e6f1480f5b6f12400IOC · Sha1 e0f8dd23e4fb0086feb42ea0a5dcef70d7b4d17cIOC · Sha256 0f8bcca3ed65e980da2a1f90a767b7d543be32eeea3e9338d09d4d635a497988IOC · Sha256 146f6010f6ee082aab13e0148d39baefa77eaba4ff65817b511b08c2092bdfd2IOC · Sha256 15c17dce89deccd5172285b2650de957918aa1157cde8e4633ae15dfe31f2711IOC · Sha256 246c97957651de568e61eba1abe572f0b0f960456209995d43d53a0d7cc494a1IOC · Sha256 2f2c3551762c03da126e45dca6fc2f997c63f0f1bfc21fd0ceed680ac6f083ceIOC · Sha256 3ec016d637e4c9cd331edd2580a229621ad638e924a4aa29ac0342e9144ace19IOC · Sha256 511d3ffb4091cbcc94571d9fb3102e8cb424c6e187d01d53ff12078d54929bdaIOC · Sha256 6aa4034dc7a2858094ff4dc59af07d6fe31119591e41599bcc0f3d0b516ee734IOC · Sha256 6b7a8e0c96c2318e747f074f9a99d26738700769ac01bba692d19fc884847737IOC · Sha256 71dfbb171eca4ef9d02ff630b56e5283bbef7b375d4dbe9e8c9531bef312fa8dIOC · Sha256 96b1f96efca3b9df2dea85678d60da27e3265b4a00e39e20e64b27bb985e1561IOC · Sha256 9cd5e7e3c8bad321ef6c3d47fe25b3b56e9487f703a7eeee52db4067e6bafe61IOC · Sha256 a03b0d41f5ef03328150331ffa0ed970998883f7e0343d79b2d3b95330d8e7c1IOC · Sha256 a8d70d16509e227d8306be361bc37a3dc9fe34bf476f51e361e55e6d293c2b3fIOC · Sha256 bd6431fb06e4689142ef597cf00382e38ae20a5393a4d9277e45a3f5b3cbcff9IOC · Sha256 c7a36d6b8128c41f93a32413675401a10a2b5769b221bbaa8c5c309585b73cebIOC · Sha256 e3a5296e762e9ee16010399666441d663beeea956382e97cca032a6a5ad06811IOC · Sha256 eb2fa179fde2f097c18d5d700ad87d660fc238ee14cbe5477032e60856859621IOC · Sha256 f1efb78887bb8783d7781c07cd13b53c9c79ebe5baa81f335838d0a6e73dec7eIOC · Sha256 f324a45fcd2a9db4e542c09486c21b08bc42d6bf76fbd5f17871090361b10815Kill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase ExploitationKill Chain phase InstallationKill Chain phase WeaponizationLLM model ClaudeLLM provider AnthropicMalware or tool IoT botnetMalware or tool TuxBotMITRE tactic CollectionMITRE tactic Command and ControlMITRE tactic Credential AccessMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic PersistenceMITRE tactic Resource DevelopmentPublication date method MetadataPublication date precision DayPublisher Palo Alto Networks Unit 42Publisher domain unit42.paloaltonetworks.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector CryptocurrencySource type operational CTI publicationStatistical use incident_or_observationTarget DevelopersTarget EmployeesTarget ExecutivesTTP CAPTCHA bypassTTP Command and controlTTP Credential harvestingTTP Credential theftTTP Data exfiltrationTTP Malware generationYear 2026
Core research
Find related
Check Point provider or government report covering Malware development, Translation and localization, and Credential theft. Indexed with Financial Services and Anthropic context.
AI relevance core_ai_attackAI technology Large language modelAI use case Malware developmentAI use case Translation and localizationAttack vector Credential theftCountry or region AfricaCountry or region BrazilCountry or region CanadaCountry or region ChinaCountry or region FranceCountry or region GermanyCountry or region India
Show 63 more tags Country or region IranCountry or region IsraelCountry or region JapanCountry or region North KoreaCountry or region RussiaCountry or region South KoreaCountry or region TaiwanCountry or region UkraineCountry or region United KingdomCountry or region United StatesCountry or region VietnamData type Credentials and passwordsData type Documents and filesEvidence inventory Contains extracted IOCsEvidence landscape Controlled studyEvidence landscape In-the-wild observedEvidence landscape Proof of conceptEvidence quality Usable Machine ExtractionImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure CloudInfrastructure EmailInfrastructure EndpointInfrastructure MobileIOC · Sha256 07c39f79ab92fb21557b82283472dce1c112f577d796111fb752c3c6d84c86b5Kill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationKill Chain phase WeaponizationLLM model ChatGPTLLM model ClaudeLLM model DeepSeekLLM provider AnthropicLLM provider DeepSeekLLM provider OpenAIMITRE tactic CollectionMITRE tactic Credential AccessMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic PersistenceMITRE tactic Resource DevelopmentPublication date method MetadataPublication date precision DayPublisher Check PointPublisher domain research.checkpoint.comRelevance basis AI misuse, abuse-disruption, or threat research reportRetrieval method DirectReview requirement Manual review requiredSector Financial ServicesSource type provider or government reportStatistical use incident_or_observationTarget DevelopersTTP Credential theftTTP Data exfiltrationTTP Malware generationTTP PowerShell executionYear 2026
Core research
Find related
CISA government or law-enforcement publication covering Exploit development, Obfuscation and evasion, and Reconnaissance and target research. Indexed with Critical Infrastructure context.
AI relevance core_ai_attackAI use case Exploit developmentAI use case Obfuscation and evasionAI use case Reconnaissance and target researchCountry or region United StatesData type Credentials and passwordsData type Documents and filesEvidence quality Usable Machine ExtractionImpact Service disruptionInclusion Core AI-attack researchInfrastructure EmailInfrastructure Endpoint
Show 38 more tags Kill Chain phase ExploitationKill Chain phase ReconnaissanceMITRE ATT&CK ID T0821MITRE ATT&CK ID T0834MITRE ATT&CK ID T0849MITRE ATT&CK ID T0893MITRE ATT&CK ID T1587MITRE ATT&CK ID T1587.004MITRE ATT&CK ID T1588MITRE ATT&CK ID T1588.007MITRE ATT&CK ID T1596MITRE ATT&CK ID T1596.005MITRE ATT&CK ID T1694MITRE tactic CollectionMITRE tactic Credential AccessMITRE tactic Defense EvasionMITRE tactic ExecutionMITRE tactic Initial AccessMITRE tactic Lateral MovementMITRE tactic ReconnaissanceMITRE tactic Resource DevelopmentPublication date method MetadataPublication date precision DayPublisher CISAPublisher domain cisa.govRelevance basis official advisory, fraud alert, or regional threat reportRetrieval method Jina Reader ProxyReview requirement Manual review requiredSector Critical InfrastructureSector EnergySector GovernmentSource type government or law-enforcement publicationStatistical use context_or_incidentTarget ExecutivesTTP Defense evasionTTP Exploit developmentTTP Script generationYear 2026
Core research
Find related
CISA government or law-enforcement publication covering Obfuscation and evasion, Reconnaissance and target research, and Command and control. Indexed with Defense context.
AI relevance core_ai_attackAI use case Obfuscation and evasionAI use case Reconnaissance and target researchAttack vector SpearphishingCampaign Operation GhostMailCountry or region CanadaCountry or region FranceCountry or region RussiaCountry or region UkraineCountry or region United KingdomCountry or region United StatesCVE CVE-2025-66376
Show 128 more tags Data type Credentials and passwordsData type Documents and filesData type Session cookies or tokensEvidence inventory Contains extracted IOCsEvidence inventory Contains extracted metricsEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 1035, Domain · medium confidenceExtracted metric · Duration Or Dwell 60 days · medium confidenceExtracted metric · Duration Or Dwell 60 seconds · medium confidenceExtracted metric · Duration Or Dwell 90 days · medium confidenceImpact Credential compromiseImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure EndpointIOC · Defanged Domain analyticemailmeter[.]comIOC · Defanged Domain buildandconsulting[.]comIOC · Defanged Domain istc-cloud[.]comIOC · Defanged Domain mailnalysis[.]comIOC · Defanged Domain pinmx[.]netIOC · Defanged Domain proton[.]meIOC · Defanged Domain zimbra-metadata[.]comIOC · Defanged Domain zimbrastat[.]comIOC · Defanged Domain zmailanalytics[.]comIOC · Sha1 18b3ad442ce73cc8656d51d75bbd7c855f2cb7e8IOC · Sha1 1b25041ececf2457eef0270fc1d785cec8ec9dedIOC · Sha1 2e4f314bc9943cab5005d6fde0b271c74d47bc9dIOC · Sha1 50a87d926621dd06389ba50d86e0ff574ed713a8IOC · Sha1 62eb76432597694edb01c1fe57aab0cfe03a7178IOC · Sha1 8959c4d29e29f02ea94ea8bb21c8df2594c5549dIOC · Sha1 b6b77c9a455225d525834a403ca9ef5481ed0447IOC · Sha1 c5a72420e7bb308d078e62128430897f82194c95IOC · Sha1 cddf5c3be1e07f28140aed165b929bf2d614922aIOC · Sha1 e4fe6466a4f9a4249fe330651e914e45bbdca44aIOC · Sha256 1517b3caa495f6c4e832df9c75fc94667e3c233773f7fa4e056d5e30e5ead760IOC · Sha256 60db9abae75cd8ccc49dd7ea5feb41677566dcd442f12ebc5745ffd2810fb874IOC · Sha256 98df604ecc57f884a2e6ce3266a0013ad64455cac48442c2312cfa4765007aafIOC · Sha256 b1f5beb1175fc5c7d1806a2f0d900eb124c54f0286c5c52b66eea7a6633adb1dIOC · Sha256 ef1955ae757c8b966c83248350331bd3a30f658ced11f387f8ebf05ab3368629Kill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationKill Chain phase ReconnaissanceMITRE ATT&CK ID T1027MITRE ATT&CK ID T1027.010MITRE ATT&CK ID T1027.013MITRE ATT&CK ID T1027.017MITRE ATT&CK ID T1048MITRE ATT&CK ID T1048.002MITRE ATT&CK ID T1048.003MITRE ATT&CK ID T1074MITRE ATT&CK ID T1074.002MITRE ATT&CK ID T1078MITRE ATT&CK ID T1087MITRE ATT&CK ID T1098MITRE ATT&CK ID T1114MITRE ATT&CK ID T1114.002MITRE ATT&CK ID T1119MITRE ATT&CK ID T1185MITRE ATT&CK ID T1199MITRE ATT&CK ID T1203MITRE ATT&CK ID T1550MITRE ATT&CK ID T1550.004MITRE ATT&CK ID T1556MITRE ATT&CK ID T1556.006MITRE ATT&CK ID T1557MITRE ATT&CK ID T1560MITRE ATT&CK ID T1566MITRE ATT&CK ID T1583MITRE ATT&CK ID T1583.003MITRE ATT&CK ID T1587MITRE ATT&CK ID T1587.001MITRE ATT&CK ID T1587.004MITRE ATT&CK ID T1588MITRE ATT&CK ID T1588.002MITRE ATT&CK ID T1588.007MITRE ATT&CK ID T1589MITRE ATT&CK ID T1589.001MITRE ATT&CK ID T1589.002MITRE ATT&CK ID T1593MITRE ATT&CK ID T1595MITRE ATT&CK ID T1596MITRE ATT&CK ID T1596.005MITRE ATT&CK ID T1597MITRE ATT&CK ID T1597.002MITRE ATT&CK ID T1608MITRE tactic CollectionMITRE tactic Command and ControlMITRE tactic Credential AccessMITRE tactic Defense EvasionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic Initial AccessMITRE tactic PersistenceMITRE tactic Privilege EscalationMITRE tactic ReconnaissanceMITRE tactic Resource DevelopmentPublication date method MetadataPublication date precision DayPublisher CISAPublisher domain cisa.govRelevance basis official advisory, fraud alert, or regional threat reportRetrieval method Jina Reader ProxyReview requirement Manual review requiredSector DefenseSector GovernmentSector Nonprofit / NGOSource type government or law-enforcement publicationStatistical use context_or_incidentTarget DevelopersTarget EmployeesTarget ExecutivesThreat-group identifier TA488TTP Command and controlTTP Credential theftTTP Data exfiltrationTTP MFA/session-token theftTTP ObfuscationTTP Password sprayingTTP Phishing link or attachmentTTP SpearphishingTTP Target research / OSINTYear 2026
Core research
Find related
Anthropic provider or government report covering Autonomous or agentic intrusion, Malware development, and Obfuscation and evasion. Indexed with Critical Infrastructure and Anthropic context.
Actor motivation EspionageAI relevance core_ai_attackAI technology Agentic AIAI technology Large language modelAI use case Autonomous or agentic intrusionAI use case Malware developmentAI use case Obfuscation and evasionAI use case Reconnaissance and target researchAttack vector SpearphishingData type Credentials and passwordsData type Cryptocurrency keys or seed phrasesData type Documents and files
Show 96 more tags Evidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence landscape In-the-wild observedEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 832 accounts · medium confidenceExtracted metric · Duration Or Dwell 11 months · medium confidenceExtracted metric · Duration Or Dwell 12 months · medium confidenceExtracted metric · Percentage 0.7% · medium confidenceExtracted metric · Percentage 12% · medium confidenceExtracted metric · Percentage 2.4% · medium confidenceExtracted metric · Percentage 2.8% · medium confidenceExtracted metric · Percentage 22.5% · medium confidenceExtracted metric · Percentage 30.3% · medium confidenceExtracted metric · Percentage 33.5% · medium confidenceExtracted metric · Percentage 33% · medium confidenceExtracted metric · Percentage 54.8% · medium confidenceExtracted metric · Percentage 54.9% · medium confidenceExtracted metric · Percentage 55.9% · medium confidenceExtracted metric · Percentage 56.1% · medium confidenceExtracted metric · Percentage 56% · medium confidenceExtracted metric · Percentage 6.2% · medium confidenceExtracted metric · Percentage 6.5% · medium confidenceExtracted metric · Percentage 64.7% · medium confidenceExtracted metric · Percentage 69% · medium confidenceExtracted metric · Percentage 8.6% · medium confidenceExtracted metric · Percentage 8.7% · medium confidenceExtracted metric · Percentage 8.9% · medium confidenceExtracted metric · Percentage 80% · medium confidenceExtracted metric · Percentage 84.4% · medium confidenceExtracted metric · Percentage 99% · medium confidenceImpact Data theft or exfiltrationImpact EspionageImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure CloudInfrastructure EndpointKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase ReconnaissanceKill Chain phase WeaponizationLLM model ClaudeLLM provider AnthropicMITRE ATT&CK ID T1003MITRE ATT&CK ID T1005MITRE ATT&CK ID T1020MITRE ATT&CK ID T1021MITRE ATT&CK ID T1021.004MITRE ATT&CK ID T1027MITRE ATT&CK ID T1055MITRE ATT&CK ID T1078.003MITRE ATT&CK ID T1087MITRE ATT&CK ID T1210MITRE ATT&CK ID T1505.003MITRE ATT&CK ID T1560MITRE ATT&CK ID T1562MITRE ATT&CK ID T1566MITRE ATT&CK ID T1587MITRE ATT&CK ID T1587.001MITRE tactic CollectionMITRE tactic Command and ControlMITRE tactic Credential AccessMITRE tactic Defense EvasionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic Lateral MovementMITRE tactic Privilege EscalationMITRE tactic ReconnaissanceMITRE tactic Resource DevelopmentPublication date method Publisher Verified OverridePublication date precision DayPublisher AnthropicPublisher domain anthropic.comRelevance basis AI misuse, abuse-disruption, or threat research reportRetrieval method DirectReview requirement Manual review requiredSector Critical InfrastructureSector Financial ServicesSector GovernmentSource type provider or government reportStatistical use incident_or_observationTarget Consumers or individualsTarget DevelopersTTP Command and controlTTP Credential harvestingTTP Data exfiltrationTTP Defense evasionTTP Malware generationTTP ObfuscationTTP SpearphishingYear 2026
Core research
Find related
Anthropic provider or government report covering Phishing and lure generation, Data exfiltration, and Agentic AI. Indexed with Financial Services and Anthropic context.
Actor motivation EspionageAI relevance core_ai_attackAI technology Agentic AIAI use case Phishing and lure generationData type Credentials and passwordsEvidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence landscape Provider abuse telemetryEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 832 accounts · medium confidenceExtracted metric · Percentage 33% · medium confidenceExtracted metric · Percentage 56% · medium confidence
Show 33 more tags Extracted metric · Percentage 6.5% · medium confidenceExtracted metric · Percentage 67.3% · medium confidenceExtracted metric · Percentage 8.6% · medium confidenceExtracted metric · Percentage 8.9% · medium confidenceImpact Data theft or exfiltrationImpact EspionageInclusion Core AI-attack researchInfrastructure BrowserKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationLLM model ClaudeLLM provider AnthropicMITRE tactic DiscoveryMITRE tactic ExfiltrationMITRE tactic Initial AccessMITRE tactic Lateral MovementMITRE tactic Privilege EscalationPublication date method Publisher Verified OverridePublication date precision DayPublisher AnthropicPublisher domain anthropic.comRelevance basis AI misuse, abuse-disruption, or threat research reportRetrieval method DirectReview requirement Manual review requiredSector Financial ServicesSector GovernmentSource type provider or government reportStatistical use incident_or_observationTarget Consumers or individualsTarget DevelopersTTP Data exfiltrationYear 2026
Context
Find related
SANS Institute research publication on AI and cybersecurity. Indexed with Financial Services context.
AI relevance background_ai_mentionCountry or region United StatesEvidence inventory Contains extracted metricsEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 2024 Organizations · medium confidenceExtracted metric · Duration Or Dwell 15 years · medium confidenceExtracted metric · Percentage 1% · medium confidenceExtracted metric · Percentage 10% · medium confidenceExtracted metric · Percentage 22% · medium confidenceExtracted metric · Percentage 27% · medium confidenceExtracted metric · Percentage 3% · medium confidence
Show 27 more tags Extracted metric · Percentage 31% · medium confidenceExtracted metric · Percentage 36% · medium confidenceExtracted metric · Percentage 38% · medium confidenceExtracted metric · Percentage 48% · medium confidenceExtracted metric · Percentage 52% · medium confidenceExtracted metric · Percentage 56% · medium confidenceExtracted metric · Percentage 62% · medium confidenceExtracted metric · Percentage 74% · medium confidenceExtracted metric · Percentage 75% · medium confidenceExtracted metric · Percentage 78% · medium confidenceExtracted metric · Percentage 83% · medium confidenceExtracted metric · Percentage 93% · medium confidenceInclusion Context onlyMITRE tactic CollectionPublication date method TextPublication date precision DayPublisher SANS InstitutePublisher domain sans.orgRelevance basis requires manual relevance reviewRetrieval method DirectReview requirement Manual review requiredSector Financial ServicesSector GovernmentSource type research publicationStatistical use do_not_aggregateTarget EmployeesYear 2026
Core research
Find related
Google Threat Intelligence Group / Mandiant operational CTI publication covering Autonomous or agentic intrusion, CAPTCHA bypass, and Deepfake video or image. Indexed with Financial Services and Anthropic context.
Actor motivation FinancialActor motivation Influence / information operationsAI relevance core_ai_attackAI technology Agentic AIAI technology Deepfake / synthetic mediaAI technology Generative AIAI technology Large language modelAI technology Speech or voice synthesisAI use case Autonomous or agentic intrusionAI use case CAPTCHA bypassAI use case Deepfake video or imageAI use case Deepfake voice
Show 118 more tags AI use case Exploit developmentAI use case Identity fraud and impersonationAI use case Malware developmentAI use case Obfuscation and evasionAI use case Reconnaissance and target researchAI use case Translation and localizationAI use case Vulnerability researchAttack vector Supply chainAttack vector VishingCampaign Operation OverloadCountry or region ChinaCountry or region IranCountry or region JapanCountry or region North KoreaCountry or region RussiaCountry or region UkraineData type Credentials and passwordsData type Documents and filesData type Source codeEvidence landscape Controlled studyEvidence landscape Forecast or predictionEvidence landscape In-the-wild observedEvidence landscape Incident responseEvidence landscape Proof of conceptEvidence quality Usable Machine ExtractionImpact Credential compromiseImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EndpointInfrastructure MobileKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationKill Chain phase ReconnaissanceKill Chain phase WeaponizationLLM model ChatGPTLLM model ClaudeLLM model GeminiLLM provider AnthropicLLM provider GoogleLLM provider OpenAIMalware or tool PromptFluxMalware or tool PROMPTSPYMITRE ATT&CK ID T0008.000MITRE ATT&CK ID T0008.005MITRE ATT&CK ID T0010.001MITRE ATT&CK ID T0016.001MITRE ATT&CK ID T0016.002MITRE ATT&CK ID T0021MITRE ATT&CK ID T0040MITRE ATT&CK ID T0054MITRE ATT&CK ID T0072MITRE ATT&CK ID T0088MITRE ATT&CK ID T0102MITRE ATT&CK ID T0103MITRE ATT&CK ID T1027.014MITRE ATT&CK ID T1027.016MITRE ATT&CK ID T1090.003MITRE ATT&CK ID T1566MITRE ATT&CK ID T1587.001MITRE ATT&CK ID T1587.004MITRE ATT&CK ID T1588.002MITRE ATT&CK ID T1588.005MITRE ATT&CK ID T1588.006MITRE ATT&CK ID T1588.007MITRE ATT&CK ID T1591.002MITRE ATT&CK ID T1591.004MITRE ATT&CK ID T1592.001MITRE tactic CollectionMITRE tactic Command and ControlMITRE tactic Defense EvasionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic PersistenceMITRE tactic ReconnaissanceMITRE tactic Resource DevelopmentPublication date method TextPublication date precision DayPublisher Google Threat Intelligence Group / MandiantPublisher domain cloud.google.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector Financial ServicesSector GovernmentSector MediaSector TelecommunicationsSource type operational CTI publicationStatistical use incident_or_observationTarget DevelopersTarget ExecutivesThreat-group identifier APT27Threat-group identifier APT45Threat-group identifier UNC2814Threat-group identifier UNC5673Threat-group identifier UNC6201Threat-group identifier UNC6671Threat-group identifier UNC6780TTP CAPTCHA bypassTTP Command and controlTTP Credential theftTTP Data exfiltrationTTP Deepfake impersonationTTP Defense evasionTTP Exploit developmentTTP ObfuscationTTP Prompt injectionTTP Ransomware deploymentTTP Supply-chain compromiseTTP Voice phishing / vishingYear 2026
Core research
Find related
IBM X-Force threat-research report covering Reconnaissance and target research, Vulnerability research, and Spearphishing.
AI relevance core_ai_attackAI technology Generative AIAI technology Large language modelAI use case Reconnaissance and target researchAI use case Vulnerability researchAttack vector SpearphishingEvidence inventory Contains extracted metricsEvidence landscape In-the-wild observedEvidence landscape Incident responseEvidence landscape Proof of conceptEvidence quality Usable Machine ExtractionExtracted metric · Percentage 56% · medium confidence
Show 18 more tags Inclusion Core AI-attack researchKill Chain phase DeliveryKill Chain phase ReconnaissanceMITRE tactic Initial AccessMITRE tactic Lateral MovementMITRE tactic ReconnaissancePublication date method MetadataPublication date precision DayPublisher IBM X-ForcePublisher domain ibm.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSource type threat-research reportStatistical use context_or_observationTarget Security researchersTTP SpearphishingYear 2026
Core research
Find related
Google Threat Intelligence Group / Mandiant operational CTI publication covering Exploit development, Vulnerability research, and Prompt injection. Indexed with Critical Infrastructure and Anthropic context.
AI relevance core_ai_attackAI technology Agentic AIAI technology Large language modelAI use case Exploit developmentAI use case Vulnerability researchAttack vector Supply chainAttack vector VishingCountry or region ChinaCountry or region RussiaData type Credentials and passwordsData type Source codeEvidence landscape Forecast or prediction
Show 40 more tags Evidence landscape In-the-wild observedEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EndpointKill Chain phase Actions on ObjectivesKill Chain phase ExploitationKill Chain phase ReconnaissanceKill Chain phase WeaponizationLLM model ClaudeLLM model GeminiLLM provider AnthropicLLM provider GoogleMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ImpactPublication date method TextPublication date precision DayPublisher Google Threat Intelligence Group / MandiantPublisher domain cloud.google.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector Critical InfrastructureSector Financial ServicesSector GovernmentSector TelecommunicationsSource type operational CTI publicationStatistical use incident_or_observationTarget DevelopersTarget EmployeesThreat-group identifier UNC6671TTP Exploit developmentTTP Prompt injectionTTP Supply-chain compromiseTTP Voice phishing / vishingTTP Vulnerability scanningYear 2026
Core research
Find related
Trend Micro threat-research report covering Reconnaissance and target research, Business email compromise, and Prompt injection. Indexed with Government context.
AI relevance core_ai_attackAI technology Agentic AIAI technology Generative AIAI technology Large language modelAI use case Reconnaissance and target researchAttack vector Business email compromiseCountry or region ChinaCountry or region GermanyCountry or region North KoreaCountry or region RussiaData type Documents and filesEvidence inventory Contains extracted metrics
Show 33 more tags Evidence landscape Controlled studyEvidence landscape Forecast or predictionEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 2026 Email · medium confidenceImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure CloudInfrastructure EmailInfrastructure EndpointKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase ReconnaissanceMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic Lateral MovementMITRE tactic Privilege EscalationMITRE tactic ReconnaissancePublication date method Publisher Verified OverridePublication date precision DayPublisher Trend MicroPublisher domain trendmicro.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSector GovernmentSource type threat-research reportStatistical use context_or_observationTarget ExecutivesTTP Business email compromiseTTP Prompt injectionYear 2026
Core research
Find related
Check Point provider or government report covering Data exfiltration. Indexed with OpenAI context.
AI relevance core_ai_attackCountry or region AfricaCountry or region BrazilCountry or region CanadaCountry or region ChinaCountry or region FranceCountry or region GermanyCountry or region IndiaCountry or region IranCountry or region IsraelCountry or region JapanCountry or region North Korea
Show 39 more tags Country or region RussiaCountry or region South KoreaCountry or region TaiwanCountry or region UkraineCountry or region United KingdomCountry or region United StatesCountry or region VietnamData type Documents and filesData type Financial and payment dataEvidence landscape Proof of conceptEvidence quality Usable Machine ExtractionImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure EmailInfrastructure MobileInfrastructure Social mediaKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationLLM model ChatGPTLLM provider OpenAIMITRE tactic CollectionMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessPublication date method MetadataPublication date precision DayPublisher Check PointPublisher domain research.checkpoint.comRelevance basis AI misuse, abuse-disruption, or threat research reportRetrieval method DirectReview requirement Manual review requiredSource type provider or government reportStatistical use incident_or_observationTarget DevelopersTTP Data exfiltrationYear 2026
Core research
Find related
Palo Alto Networks Unit 42 operational CTI publication covering Autonomous or agentic intrusion, CAPTCHA bypass, and Malware development. Indexed with Anthropic context.
AI relevance core_ai_attackAI technology Agentic AIAI technology Generative AIAI technology Large language modelAI use case Autonomous or agentic intrusionAI use case CAPTCHA bypassAI use case Malware developmentAI use case Obfuscation and evasionAI use case Reconnaissance and target researchAttack vector Credential theftCountry or region ChinaCountry or region India
Show 67 more tags Country or region JapanCountry or region South KoreaData type Credentials and passwordsData type Documents and filesEvidence inventory Contains extracted IOCsEvidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence landscape In-the-wild observedEvidence landscape Incident responseEvidence quality Usable Machine ExtractionExtracted metric · Duration Or Dwell 2 seconds · medium confidenceExtracted metric · Duration Or Dwell 5 seconds · medium confidenceExtracted metric · Percentage 100 % · medium confidenceImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure EndpointInfrastructure MobileInfrastructure SaaSIOC · Sha256 02ce798981fb2aa68776e53672a24103579ca77a1d3e7f8aaeccf6166d1a9cc6IOC · Sha256 052d5220529b6bd4b01e5e375b5dc3ffd50c4b137e242bbfb26655fd7f475ac6IOC · Sha256 1b6326857fa635d396851a9031949cfdf6c806130767c399727d78a1c2a0126cIOC · Sha256 7c7b7b99f248662a1f9aea1563e60f90d19b0ee95934e476c423d0bf373f6493Kill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase InstallationKill Chain phase ReconnaissanceLLM model ChatGPTLLM model ClaudeLLM model GPT-4LLM provider AnthropicLLM provider OpenAIMITRE tactic CollectionMITRE tactic Command and ControlMITRE tactic Credential AccessMITRE tactic Defense EvasionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Lateral MovementMITRE tactic PersistencePublication date method MetadataPublication date precision DayPublisher Palo Alto Networks Unit 42Publisher domain unit42.paloaltonetworks.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSource type operational CTI publicationStatistical use incident_or_observationTarget DevelopersTarget EmployeesTarget ExecutivesTTP CAPTCHA bypassTTP Command and controlTTP Credential harvestingTTP Credential theftTTP Data exfiltrationTTP Defense evasionTTP Malware generationTTP ObfuscationTTP PowerShell executionTTP Target research / OSINTYear 2026
Core research
Find related
OpenAI operational CTI publication covering Influence operations. Indexed with OpenAI context.
Actor motivation Influence / information operationsAI relevance core_ai_attackAI use case Influence operationsEvidence quality Usable Machine ExtractionInclusion Core AI-attack researchInfrastructure MobileKill Chain phase Actions on ObjectivesKill Chain phase ExploitationLLM provider OpenAIPublication date method Publisher Verified OverridePublication date precision DayPublisher OpenAI
Show 7 more tags Publisher domain openai.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method Jina Reader ProxyReview requirement Manual review requiredSource type operational CTI publicationStatistical use incident_or_observationYear 2026
Core research
Find related
Check Point forecast or strategic assessment covering CAPTCHA bypass, Command and control, and Malware development. Indexed with Critical Infrastructure and Anthropic context.
AI relevance core_ai_attackAI technology Agentic AIAI use case CAPTCHA bypassAI use case Command and controlAI use case Malware developmentAI use case Reconnaissance and target researchAI use case Translation and localizationCountry or region AfricaCountry or region BrazilCountry or region CanadaCountry or region ChinaCountry or region France
Show 75 more tags Country or region GermanyCountry or region IndiaCountry or region IranCountry or region IsraelCountry or region JapanCountry or region North KoreaCountry or region RussiaCountry or region South KoreaCountry or region TaiwanCountry or region UkraineCountry or region United KingdomCountry or region United StatesCountry or region VietnamData type Credentials and passwordsData type Documents and filesData type Personally identifiable informationEvidence inventory Contains extracted metricsEvidence landscape Controlled studyEvidence landscape Forecast or predictionEvidence landscape Incident responseEvidence landscape Proof of conceptEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 11 systems · medium confidenceImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure EndpointInfrastructure MobileKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationKill Chain phase ReconnaissanceKill Chain phase WeaponizationLLM model ChatGPTLLM model GeminiLLM model GrokLLM model Microsoft CopilotLLM provider AnthropicLLM provider GoogleLLM provider MicrosoftLLM provider OpenAILLM provider xAIMalicious AI tool FraudGPTMITRE tactic Command and ControlMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic Lateral MovementMITRE tactic PersistenceMITRE tactic ReconnaissanceMITRE tactic Resource DevelopmentPublication date method MetadataPublication date precision DayPublisher Check PointPublisher domain research.checkpoint.comRelevance basis threat assessment, forecast, or red-team studyRetrieval method DirectReview requirement Manual review requiredSector Critical InfrastructureSector DefenseSource type forecast or strategic assessmentStatistical use context_onlyTarget DevelopersTTP CAPTCHA bypassTTP Command and controlTTP Data exfiltrationTTP Malware generationTTP PowerShell executionYear 2026
Core research
Find related
Google Threat Intelligence Group / Mandiant operational CTI publication covering Identity fraud and impersonation, Malware development, and Obfuscation and evasion. Indexed with APT31, Cryptocurrency, and DeepSeek context.
Actor motivation FinancialActor motivation HacktivismActor motivation Influence / information operationsAI relevance core_ai_attackAI technology Agentic AIAI technology Generative AIAI technology Large language modelAI use case Identity fraud and impersonationAI use case Malware developmentAI use case Obfuscation and evasionAI use case Phishing and lure generationAI use case Reconnaissance and target research
Show 100 more tags AI use case Translation and localizationAI use case Vulnerability researchAttack vector Credential theftAttack vector Malicious advertisementAttack vector SpearphishingAttack vector Supply chainAttack vector VishingCountry or region ChinaCountry or region IranCountry or region North KoreaCountry or region RussiaCountry or region UkraineCountry or region United StatesData type Credentials and passwordsData type Cryptocurrency keys or seed phrasesData type Documents and filesData type Financial and payment dataData type Source codeEvidence landscape Controlled studyEvidence landscape Forecast or predictionEvidence landscape In-the-wild observedEvidence landscape Proof of conceptEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure CloudInfrastructure EmailInfrastructure EndpointKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationKill Chain phase ReconnaissanceKill Chain phase WeaponizationLLM model ChatGPTLLM model DeepSeekLLM model GeminiLLM model GrokLLM model Microsoft CopilotLLM provider DeepSeekLLM provider GoogleLLM provider MicrosoftLLM provider OpenAILLM provider xAIMalware or tool HONESTCUE malwareMalware or tool PromptFluxMITRE tactic CollectionMITRE tactic Command and ControlMITRE tactic Defense EvasionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic ReconnaissanceMITRE tactic Resource DevelopmentPublication date method TextPublication date precision DayPublisher Google Threat Intelligence Group / MandiantPublisher domain cloud.google.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector CryptocurrencySector DefenseSector Financial ServicesSector GovernmentSector TelecommunicationsSource type operational CTI publicationStatistical use incident_or_observationTarget DevelopersTarget ExecutivesTarget Security researchersThreat group APT31Threat group APT41Threat group APT42 / Charming KittenThreat-group identifier APT31Threat-group identifier APT41Threat-group identifier APT42Threat-group identifier UNC2970Threat-group identifier UNC5356Threat-group identifier UNC6418Threat-group identifier UNC6671Threat-group identifier UNC795TTP Command and controlTTP Credential harvestingTTP Data exfiltrationTTP Malicious advertisingTTP Malware generationTTP ObfuscationTTP Prompt injectionTTP SpearphishingTTP Supply-chain compromiseTTP Target research / OSINTTTP Voice phishing / vishingYear 2026
Core research
Find related
Google Threat Intelligence Group / Mandiant operational CTI publication covering Deepfake video or image, Reconnaissance and target research, and Translation and localization. Indexed with BlueNoroff, Cryptocurrency, and Google context.
Actor motivation FinancialAI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI technology Generative AIAI use case Deepfake video or imageAI use case Reconnaissance and target researchAI use case Translation and localizationAttack vector SpearphishingAttack vector Supply chainAttack vector VishingCountry or region North KoreaCountry or region Russia
Show 79 more tags Data type Credentials and passwordsData type Documents and filesData type Session cookies or tokensData type Source codeEvidence inventory Contains extracted IOCsEvidence landscape In-the-wild observedEvidence landscape Incident responseEvidence quality Usable Machine ExtractionImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EndpointInfrastructure Messaging platformInfrastructure Social mediaIOC · Defanged Domain breakdream[.]comIOC · Defanged Domain dreamdie[.]comIOC · Defanged Domain mylingocoin[.]comIOC · Defanged Domain supportzm[.]comIOC · Defanged Domain zmsupport[.]comIOC · Md5 3712793d3847dd0962361aa528fa124cIOC · Md5 4e4f2dfe143ba261fd8a18d1c4b58f2eIOC · Md5 c91725905b273e81e9cc6983a11c8d60IOC · Md5 eb7635f4836c9e0aa4c315b18b051cb5IOC · Sha256 03f00a143b8929585c122d490b6a3895d639c17d92c2223917e3a9ca1b8d30f9IOC · Sha256 1a30d6cdb0b98feed62563be8050db55ae0156ed437701d36a7b46aabf086edeIOC · Sha256 603848f37ab932dccef98ee27e3c5af9221d3b6ccfe457ccf93cb572495ac325IOC · Sha256 b452c2da7c012eda25a1403b3313444b5eb7c2c3e25eee489f1bd256f8434735IOC · Sha256 b525837273dde06b86b5f93f9aec2c29665324105b0b66f6df81884754f8080dIOC · Sha256 c3e5d878a30a6c46e22d1dd2089b32086c91f13f8b9c413aa84e1dbaa03b9375IOC · Sha256 c8f7608d4e19f6cb03680941bbd09fe969668bcb09c7ca985048a22e014dffcdKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase InstallationKill Chain phase ReconnaissanceLLM model GeminiLLM provider GoogleMalware or tool HIDDENCALL backdoorMalware or tool UNC1069 malwareMITRE tactic CollectionMITRE tactic Command and ControlMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic Initial AccessMITRE tactic PersistenceMITRE tactic ReconnaissancePublication date method TextPublication date precision DayPublisher Google Threat Intelligence Group / MandiantPublisher domain cloud.google.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector CryptocurrencySector Financial ServicesSector GovernmentSector TechnologySector TelecommunicationsSource type operational CTI publicationStatistical use incident_or_observationTarget DevelopersTarget EmployeesTarget ExecutivesThreat group BlueNoroffThreat group UNC1069Threat-group identifier UNC1069Threat-group identifier UNC4899Threat-group identifier UNC6671TTP Command and controlTTP Credential harvestingTTP Data exfiltrationTTP Deepfake impersonationTTP MFA/session-token theftTTP SpearphishingTTP Supply-chain compromiseTTP Voice phishing / vishingYear 2026
Core research
Find related
Palo Alto Networks Unit 42 operational CTI publication covering CAPTCHA bypass, Identity fraud and impersonation, and Malware development. Indexed with APT28 / Fancy Bear, Cryptocurrency, and Anthropic context.
Actor motivation EspionageAI relevance core_ai_attackAI technology Generative AIAI technology Large language modelAI use case CAPTCHA bypassAI use case Identity fraud and impersonationAI use case Malware developmentAI use case Obfuscation and evasionAI use case Phishing and lure generationAI use case Translation and localizationAttack vector Credential theftCountry or region China
Show 65 more tags Country or region FranceCountry or region IndiaCountry or region JapanCountry or region RussiaCountry or region South KoreaCountry or region UkraineData type Credentials and passwordsData type Documents and filesEvidence inventory Contains extracted metricsEvidence landscape Incident responseEvidence landscape Proof of conceptEvidence quality Usable Machine ExtractionExtracted metric · Percentage 36% · medium confidenceImpact Data theft or exfiltrationImpact EspionageImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure CloudInfrastructure EmailInfrastructure EndpointInfrastructure MobileInfrastructure SaaSKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryLLM model ClaudeLLM model DeepSeekLLM model GeminiLLM provider AnthropicLLM provider DeepSeekLLM provider GoogleMalware or tool LAMEHUGMITRE tactic Command and ControlMITRE tactic Credential AccessMITRE tactic Defense EvasionMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessPublication date method MetadataPublication date precision DayPublisher Palo Alto Networks Unit 42Publisher domain unit42.paloaltonetworks.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector CryptocurrencySector DefenseSource type operational CTI publicationStatistical use incident_or_observationTarget EmployeesTarget ExecutivesThreat group APT28 / Fancy BearThreat-group identifier APT28TTP CAPTCHA bypassTTP Command and controlTTP Credential harvestingTTP Credential theftTTP Data exfiltrationTTP Defense evasionTTP Malware generationTTP ObfuscationTTP Script generationYear 2026
Core research
Find related
FBI government or law-enforcement publication covering Deepfake voice, Identity fraud and impersonation, and Deepfake impersonation. Indexed with Cryptocurrency context.
AI relevance core_ai_attackAI technology Speech or voice synthesisAI use case Deepfake voiceAI use case Identity fraud and impersonationAttack vector SmishingAttack vector SpearphishingAttack vector VishingCountry or region United StatesData type Documents and filesData type Personally identifiable informationEvidence quality Usable Machine ExtractionImpact Financial fraud
Show 23 more tags Inclusion Core AI-attack researchInfrastructure EmailInfrastructure Messaging platformKill Chain phase Actions on ObjectivesKill Chain phase DeliveryMITRE tactic Initial AccessPublication date method TextPublication date precision DayPublisher FBIPublisher domain fbi.govRelevance basis official advisory, fraud alert, or regional threat reportRetrieval method Jina Reader ProxyReview requirement Manual review requiredSector CryptocurrencySector Financial ServicesSector GovernmentSource type government or law-enforcement publicationStatistical use context_or_incidentTarget EmployeesTTP Deepfake impersonationTTP SpearphishingTTP Voice phishing / vishingYear 2025
Core research
Find related
Anthropic provider or government report covering Autonomous or agentic intrusion, Exploit development, and Malware development. Indexed with Financial Services and Anthropic context.
Actor motivation EspionageAI relevance core_ai_attackAI technology Agentic AIAI use case Autonomous or agentic intrusionAI use case Exploit developmentAI use case Malware developmentAI use case Reconnaissance and target researchAI use case Vulnerability researchAttack vector Credential theftCompanion source src-053Country or region ChinaData type Credentials and passwords
Show 59 more tags Data type Documents and filesDuplicate lineage dup-004Evidence inventory Contains extracted metricsEvidence landscape Controlled studyEvidence landscape Forecast or predictionEvidence landscape Incident responseEvidence quality Usable Machine ExtractionExtracted metric · Campaign Or Intrusion Duration 20 minutes · medium confidenceExtracted metric · Campaign Or Intrusion Duration 6 hours · medium confidenceExtracted metric · Duration Or Dwell 10 minutes · medium confidenceExtracted metric · Duration Or Dwell 4 hours · medium confidenceExtracted metric · Percentage 90% · medium confidenceImpact Credential compromiseImpact Data theft or exfiltrationImpact EspionageInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EndpointKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase ExploitationKill Chain phase InstallationKill Chain phase ReconnaissanceKill Chain phase WeaponizationLLM model ClaudeLLM provider AnthropicMITRE tactic CollectionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic Initial AccessMITRE tactic Lateral MovementMITRE tactic PersistenceMITRE tactic Privilege EscalationMITRE tactic ReconnaissanceMITRE tactic Resource DevelopmentPublication date method Publisher Verified OverridePublication date precision DayPublisher AnthropicPublisher domain www-cdn.anthropic.comRelevance basis AI misuse, abuse-disruption, or threat research reportRetrieval method DirectReview requirement Manual review requiredSector Financial ServicesSector GovernmentSector ManufacturingSource type provider or government reportStatistical use incident_or_observationTarget Consumers or individualsTarget DevelopersTarget EmployeesTarget ExecutivesTTP Credential harvestingTTP Credential theftTTP Data exfiltrationTTP Exploit developmentTTP Malware generationTTP Vulnerability scanningYear 2025
Core research
Find related
Proofpoint operational CTI publication covering Identity fraud and impersonation, Obfuscation and evasion, and Command and control. Indexed with TA547, Cryptocurrency, and Anthropic context.
AI relevance core_ai_attackAI technology Agentic AIAI technology Computer vision / OCRAI technology Generative AIAI use case Identity fraud and impersonationAI use case Obfuscation and evasionAttack vector Malicious advertisementCampaign Operation EndgameCountry or region RussiaData type Credentials and passwordsData type Cryptocurrency keys or seed phrasesData type Documents and files
Show 101 more tags Evidence inventory Contains extracted IOCsEvidence inventory Contains extracted metricsEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionExtracted metric · Financial Value $300 · medium confidenceExtracted metric · Financial Value $500 · medium confidenceExtracted metric · Percentage 1% · medium confidenceExtracted metric · Percentage 17% · medium confidenceImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure EndpointIOC · Defanged Domain appeal[.]strike-submit[.]comIOC · Defanged Domain application-review[.]orgIOC · Defanged Domain budparbanjarnegara[.]comIOC · Defanged Domain cashorix[.]xyzIOC · Defanged Domain channel-review[.]orgIOC · Defanged Domain cloudwardena[.]comIOC · Defanged Domain compliance-review[.]orgIOC · Defanged Domain flaezguerad[.]comIOC · Defanged Domain flaezguered[.]comIOC · Defanged Domain flaxergaurds[.]comIOC · Defanged Domain flcreagurade[.]comIOC · Defanged Domain flenieregurd[.]comIOC · Defanged Domain flheregurend[.]comIOC · Defanged Domain flnaresgurard[.]comIOC · Defanged Domain flsaregursd[.]comIOC · Defanged Domain google[.]strike-submit[.]comIOC · Defanged Domain security[.]flacergurad[.]comIOC · Defanged Domain security[.]flaegrudad[.]comIOC · Defanged Domain security[.]flaezguerad[.]comIOC · Defanged Domain security[.]flaezguered[.]comIOC · Defanged Domain security[.]flavregurads[.]comIOC · Defanged Domain security[.]flheregurend[.]comIOC · Defanged Domain security[.]flqaergwaard[.]comIOC · Defanged Domain security[.]flsaregursd[.]comIOC · Defanged Domain security[.]gueradflwre[.]comIOC · Defanged Domain strike-submit[.]comIOC · Defanged Domain submit-appeal[.]comIOC · Defanged Domain support-review[.]orgIOC · Defanged Domain tdsworkout[.]comIOC · Defanged Domain theguardshield[.]comIOC · Defanged Domain trust-review[.]orgIOC · Defanged Domain xoiiasdpsdoasdpojas[.]comIOC · Defanged Domain xpoalswwkjddsljsy[.]comIOC · Sha256 13f0bf908679bea560806fd3c14ef581b3cadbab2ff07a6adf04d97995924707IOC · Sha256 b0c9d619256fdf220fbb39945fac5a040b5e836f1eae0459b4fcbf2b451420a7IOC · Sha256 bc2508708feb0ccc652494f8e28620bd871a8b6e1d26c7cdd61ab070f2594bbcIOC · Sha256 c9026ffc02f11204ac1eb1183376a5cee74f7897d948bdcd59c06f31de2671faIOC · Sha256 ccdd8a6dc97eeba07e586f059eae7944dd767519f2c3b2233ff90d3dc4e8e3f0IOC · Sha256 ff14b28408121ebe4a5d0c2f14b9dc99e987e89b56392dc214481197d4815456Kill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationLLM model ClaudeLLM provider AnthropicMalware or tool DanaBotMalware or tool DarkGateMalware or tool LummaMalware or tool RemcosMalware or tool RhadamanthysMalware or tool ScreenshotterMITRE tactic Command and ControlMITRE tactic Defense EvasionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessPublication date method MetadataPublication date precision DayPublisher ProofpointPublisher domain proofpoint.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector CryptocurrencySector Financial ServicesSector GovernmentSector Transportation and LogisticsSource type operational CTI publicationStatistical use incident_or_observationTarget DevelopersTarget EmployeesTarget ExecutivesThreat group TA547Threat-group identifier TA2541Threat-group identifier TA547Threat-group identifier TA571Threat-group identifier TA585Threat-group identifier TA866TTP Command and controlTTP Data exfiltrationTTP Malicious advertisingTTP ObfuscationTTP PowerShell executionYear 2025
Core research
Find related
Rapid7 threat-research report covering Deepfake video or image, Deepfake voice, and Identity fraud and impersonation. Indexed with Akira and Critical Infrastructure context.
Actor motivation Disruption / destructionActor motivation FinancialActor motivation Influence / information operationsAI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI technology Generative AIAI technology Large language modelAI use case Deepfake video or imageAI use case Deepfake voiceAI use case Identity fraud and impersonationAI use case Influence operationsAI use case Malware development
Show 144 more tags AI use case Obfuscation and evasionAI use case Reconnaissance and target researchAttack vector Credential theftAttack vector SpearphishingAttack vector Supply chainAttack vector VishingCompanion source src-093Country or region CanadaCountry or region ChinaCountry or region FranceCountry or region GermanyCountry or region IranCountry or region North KoreaCountry or region RussiaCountry or region UkraineCountry or region United StatesCVE CVE-2007-0671CVE CVE-2018-0296CVE CVE-2025-10035CVE CVE-2025-20333CVE CVE-2025-20362CVE CVE-2025-20363CVE CVE-2025-49704CVE CVE-2025-49706CVE CVE-2025-53770CVE CVE-2025-53771CVE CVE-2025-54309CVE CVE-2025-7775CVE CVE-2026-18577CVE CVE-2026-19490CVE CVE-2026-63077CVE CVE-2026-63520Data type Credentials and passwordsData type Cryptocurrency keys or seed phrasesData type Documents and filesData type Source codeDuplicate lineage dup-005Evidence inventory Contains extracted metricsEvidence landscape Controlled studyEvidence landscape Forecast or predictionEvidence landscape In-the-wild observedEvidence landscape Incident responseEvidence landscape Proof of conceptEvidence landscape Threat landscape reportEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionExtracted metric · Duration Or Dwell 18 years · medium confidenceExtracted metric · Dwell Time 12 months · medium confidenceExtracted metric · Percentage 13% · medium confidenceExtracted metric · Percentage 15% · medium confidenceExtracted metric · Percentage 18% · medium confidenceExtracted metric · Percentage 3% · medium confidenceExtracted metric · Percentage 4% · medium confidenceExtracted metric · Percentage 5% · medium confidenceExtracted metric · Percentage 6% · medium confidenceExtracted metric · Percentage 67% · medium confidenceImpact Credential compromiseImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure EndpointInfrastructure SaaSKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationKill Chain phase ReconnaissanceKill Chain phase WeaponizationMalware or tool BRICKSTORM backdoorMalware or tool FunkSecMalware or tool LAMEHUGMITRE ATT&CK ID T1003MITRE ATT&CK ID T1018MITRE ATT&CK ID T1021MITRE ATT&CK ID T1047MITRE ATT&CK ID T1059MITRE ATT&CK ID T1078MITRE ATT&CK ID T1087MITRE ATT&CK ID T1133MITRE ATT&CK ID T1560MITRE ATT&CK ID T1566MITRE tactic CollectionMITRE tactic Command and ControlMITRE tactic Credential AccessMITRE tactic Defense EvasionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic Lateral MovementMITRE tactic PersistenceMITRE tactic ReconnaissanceMITRE tactic Resource DevelopmentPublication date method Publisher Verified OverridePublication date precision DayPublisher Rapid7Publisher domain rapid7.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSector Critical InfrastructureSector CryptocurrencySector DefenseSector Financial ServicesSector GovernmentSector HealthcareSector Legal ServicesSector TechnologySector TelecommunicationsSector Transportation and LogisticsSource type threat-research reportStatistical use context_or_observationTarget DevelopersTarget EmployeesThreat group AkiraThreat group APT29 / Cozy BearThreat group APT41Threat group APT43 / KimsukyThreat group APT44 / SandwormThreat group Black BastaThreat group Famous ChollimaThreat group FunkSecThreat group Lazarus GroupThreat group RansomHubThreat-group identifier APT29Threat-group identifier APT41Threat-group identifier STORM-1175Threat-group identifier UNC5221TTP Command and controlTTP Credential theftTTP Data exfiltrationTTP Deepfake impersonationTTP Defense evasionTTP Malware generationTTP PowerShell executionTTP Ransomware deploymentTTP SpearphishingTTP Supply-chain compromiseTTP Voice phishing / vishingYear 2025
Context
Find related
ENISA threat-research report on AI and cybersecurity.
Actor motivation HacktivismAI relevance background_ai_mentionCountry or region European UnionData type Documents and filesEvidence landscape Incident responseEvidence landscape Threat landscape reportEvidence quality Usable Machine ExtractionImpact Service disruptionInclusion Context onlyInfrastructure EmailKill Chain phase ExploitationPublication date method Metadata
Show 9 more tags Publication date precision DayPublisher ENISAPublisher domain enisa.europa.euRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSource type threat-research reportStatistical use context_or_observationYear 2025
Core research
Find related
Google Threat Intelligence Group / Mandiant operational CTI publication covering Deepfake video or image, Exploit development, and Identity fraud and impersonation. Indexed with APT28 / Fancy Bear, Cryptocurrency, and Google context.
Actor motivation FinancialActor motivation Influence / information operationsAI relevance core_ai_attackAI technology Agentic AIAI technology Deepfake / synthetic mediaAI technology Generative AIAI technology Large language modelAI use case Deepfake video or imageAI use case Exploit developmentAI use case Identity fraud and impersonationAI use case Malware developmentAI use case Obfuscation and evasion
Show 106 more tags AI use case Reconnaissance and target researchAI use case Translation and localizationAI use case Vulnerability researchAttack vector Credential theftAttack vector SmishingAttack vector Supply chainAttack vector VishingCompanion source src-039Country or region AfricaCountry or region ChinaCountry or region IranCountry or region IsraelCountry or region North KoreaCountry or region RussiaCountry or region UkraineData type Credentials and passwordsData type Cryptocurrency keys or seed phrasesData type Documents and filesData type Personally identifiable informationData type Session cookies or tokensData type Source codeDuplicate lineage dup-002Evidence landscape Controlled studyEvidence landscape Forecast or predictionEvidence landscape In-the-wild observedEvidence landscape Proof of conceptEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure CloudInfrastructure EmailInfrastructure EndpointInfrastructure MobileKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationKill Chain phase ReconnaissanceKill Chain phase WeaponizationLLM model GeminiLLM provider GoogleLLM provider Hugging FaceMalware or tool BIGMACHO backdoorMalware or tool Cobalt StrikeMalware or tool LAMEHUGMalware or tool PromptFluxMalware or tool PromptStealMalware or tool QuietVaultMITRE tactic Command and ControlMITRE tactic Defense EvasionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic Lateral MovementMITRE tactic PersistenceMITRE tactic Privilege EscalationMITRE tactic ReconnaissanceMITRE tactic Resource DevelopmentPublication date method TextPublication date precision DayPublisher Google Threat Intelligence Group / MandiantPublisher domain cloud.google.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector CryptocurrencySector EducationSector Financial ServicesSector GovernmentSector TelecommunicationsSource type operational CTI publicationStatistical use incident_or_observationTarget DevelopersTarget ExecutivesTarget Security researchersThreat group APT28 / Fancy BearThreat group APT41Threat group APT42 / Charming KittenThreat group UNC1069Threat-group identifier APT28Threat-group identifier APT41Threat-group identifier APT42Threat-group identifier UNC1069Threat-group identifier UNC4899Threat-group identifier UNC6671TTP Command and controlTTP Credential harvestingTTP Data exfiltrationTTP Deepfake impersonationTTP Defense evasionTTP Exploit developmentTTP Malware generationTTP MFA/session-token theftTTP ObfuscationTTP PowerShell executionTTP Prompt injectionTTP Script generationTTP Supply-chain compromiseTTP Voice phishing / vishingYear 2025
Core research
Find related
Kaspersky GReAT operational CTI publication covering CAPTCHA bypass, Deepfake video or image, and Identity fraud and impersonation. Indexed with APT43 / Kimsuky, Cryptocurrency, and OpenAI context.
Actor motivation Disruption / destructionActor motivation FinancialAI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI technology Generative AIAI use case CAPTCHA bypassAI use case Deepfake video or imageAI use case Identity fraud and impersonationAI use case Malware developmentAI use case Obfuscation and evasionAI use case Reconnaissance and target researchAttack vector Credential theft
Show 191 more tags Attack vector SpearphishingCampaign GhostCallCampaign GhostHireCampaign Operation SyncHoleCountry or region AfricaCountry or region BrazilCountry or region FranceCountry or region IndiaCountry or region JapanCountry or region RussiaCountry or region United StatesData type Credentials and passwordsData type Cryptocurrency keys or seed phrasesData type Documents and filesData type Source codeEvidence inventory Contains extracted IOCsEvidence inventory Contains extracted metricsEvidence landscape Controlled studyEvidence landscape Forecast or predictionEvidence landscape Incident responseEvidence quality Usable Machine ExtractionExtracted metric · Campaign Or Intrusion Duration 2025 minute · medium confidenceExtracted metric · Duration Or Dwell 30 seconds · medium confidenceImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure EndpointInfrastructure Messaging platformInfrastructure MobileInfrastructure Social mediaIOC · Defanged Domain alwayswait[.]siteIOC · Defanged Domain autoupdate[.]onlineIOC · Defanged Domain autoupdate[.]xyzIOC · Defanged Domain awaitingfor[.]onlineIOC · Defanged Domain awaitingfor[.]siteIOC · Defanged Domain bots[.]autoupdate[.]onlineIOC · Defanged Domain chkactive[.]onlineIOC · Defanged Domain chkstate[.]onlineIOC · Defanged Domain commoncome[.]onlineIOC · Defanged Domain datatabletemplate[.]xyzIOC · Defanged Domain filedrive[.]onlineIOC · Defanged Domain firstfromsep[.]onlineIOC · Defanged Domain image-support[.]xyzIOC · Defanged Domain instant-update[.]onlineIOC · Defanged Domain longlastfor[.]onlineIOC · Defanged Domain readysafe[.]xyzIOC · Defanged Domain real-update[.]xyzIOC · Defanged Domain safefor[.]xyzIOC · Defanged Domain safeupload[.]onlineIOC · Defanged Domain secondshop[.]onlineIOC · Defanged Domain security-update[.]xyzIOC · Defanged Domain signsafe[.]siteIOC · Defanged Domain signsafe[.]xyzIOC · Defanged Domain system-update[.]xyzIOC · Defanged Domain video-meeting[.]onlineIOC · Md5 00dd47af3db45548d2722fe8a4489508IOC · Md5 01d3ed1c228f09d8e56bfbc5f5622a6cIOC · Md5 0af11f610da1f691e43173d44643283fIOC · Md5 0ca37675d75af0e7def0025cd564d6c5IOC · Md5 10cd1ef394bc2a2d8d8f2558b73ac7b8IOC · Md5 1243968876262c3ad4250e1371447b23IOC · Md5 1653d75d579872fadec1f22cf7fee3c0IOC · Md5 17baae144d383e4dc32f1bf69700e587IOC · Md5 19a7e16332a6860b65e6944f1f3c5001IOC · Md5 1ee10fa01587cec51f455ceec779a160IOC · Md5 261a409946b6b4d9ce706242a76134e3IOC · Md5 2b499eb3865a7ef17264d15252b7f73eIOC · Md5 2c42253ebf9a743814b9b16a89522befIOC · Md5 31b88dd319af8e4b8a96fc9732ebc708IOC · Md5 358c2969041c8be74ce478edb2ffcd19IOC · Md5 389447013870120775556bb4519dba97IOC · Md5 38c8d80dd32d00e9c9440a498f7dd739IOC · Md5 3bbe4dfe3134c8a7928d10c948e20beeIOC · Md5 50f341b24cb75f37d042d1e5f9e3e5aaIOC · Md5 529fe6eff1cf452680976087e2250c02IOC · Md5 5ad40a5fd18a1b57b69c44bc2963dc6bIOC · Md5 5cb4f0084f3c25e640952753ed5b25d0IOC · Md5 60bfe4f378e9f5a84183ac505a032228IOC · Md5 6348b49f3499d760797247b94385fda3IOC · Md5 6422795a6df10c45c1006f92d686ee7eIOC · Md5 6aa93664b4852cb5bad84ba1a187f645IOC · Md5 7168ce5c6e5545a5b389db09c90038daIOC · Md5 73d26eb56e5a3426884733c104c3f625IOC · Md5 7581854ff6c890684823f3aed03c210fIOC · Md5 76ace3a6892c25512b17ed42ac2ebd05IOC · Md5 7e50c3f301dd045eb189ba1644ded155IOC · Md5 7f94ed2d5f566c12de5ebe4b5e3d8aa3IOC · Md5 8006efb8dd703073197e5a27682b35bfIOC · Md5 8f8942cd14f646f59729f83cbd4c357bIOC · Md5 931cec3c80c78d233e3602a042a2e71bIOC · Md5 9551b4af789b2db563f9452eaf46b6aaIOC · Md5 963f473f1734d8b3fbb8c9a227c06d07IOC · Md5 a070b77c5028d7a5d2895f1c9d35016fIOC · Md5 a0eb7e480752d494709c63aa35ccf36cIOC · Md5 a26f2b97ca4e2b4b5d58933900f02131IOC · Md5 a6ce961f487b4cbdfe68d0a249647c48IOC · Md5 ab1e8693931f8c694247d96cf5a85197IOC · Md5 b2e9a6412fd7c068a5d7c38d0afd946fIOC · Md5 b567bfdaac131a2d8a23ad8fd450a31dIOC · Md5 c42c7a2ea1c2f00dddb0cc4c8bfb5bcfIOC · Md5 c446682f33641cff21083ac2ce477dbeIOC · Md5 c6f0c8d41b9ad4f079161548d2435d80IOC · Md5 d63805e89053716b6ab93ce6decf8450IOC · Md5 d8529855fab4b4aa6c2b34449cb3b9fbIOC · Md5 de93e85199240de761a8ba0a56f0088dIOC · Md5 e33f942cf1479ca8530a916868bad954IOC · Md5 e8680d17fba6425e4a9bb552fb8db2b1IOC · Md5 e9fdd703e60b31eb803b1b59985cabecIOC · Md5 eda0525c078f5a216a977bc64e86160aIOC · Md5 f1bad0efbd3bd5a4202fe740756f977aIOC · Md5 f1d2af27b13cd3424556b18dfd3cf83fIOC · Md5 f8bb2528bf35f8c11fbc4369e68c4038IOC · Sha256 3dd226d0b700f33974f409142defb62a8cd172ae5f2eb9beb7f5750eb1702e2aIOC · Sha256 4451ee8bc53ea7c148d8348bc7b82aca9977bdd31c0156dfe25c4a879a1d2190IOC · Sha256 5b77f83ecefa0e32ba922f61c9efff7f755ba51a010db844ca7e8ad3db28650aIOC · Sha256 71b743c529f0b27735f7774a0903cb908edc93423b60fe9be49a3729982d0e8dIOC · Sha256 a6c1a7ce43b029a1ef4ae69b26f745440ecce8368c89f11ac999d4ed04a31572IOC · Sha256 b3cc15c1033de79024f9cf3cd6a6a7a9b7e54a1a57d3156036f5c05f541694b7IOC · Sha256 b494a0ae421afe170f6cb9de2c1193a78fbe16f627f85139676afc5d9bfe93a2IOC · Sha256 c4db903322d17c8cbf1d1db55124854c0b070d6ece54162b6a4d06df24c572dfKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationKill Chain phase ReconnaissanceKill Chain phase WeaponizationLLM model ChatGPTLLM model GPT-4LLM provider OpenAIMalware or tool CoolClient backdoorMalware or tool DownTroy malwareMalware or tool KANDYKORN malwareMalware or tool KONNI malwareMalware or tool NightLedger backdoorMalware or tool ObjCShellZ malwareMalware or tool RooTroy backdoorMalware or tool RustBucket malwareMalware or tool SugarLoader malwareMalware or tool SysPhon malwareMalware or tool SysPhone backdoorMalware or tool TeamsClutch malwareMalware or tool TripleWatch stealerMITRE tactic Command and ControlMITRE tactic Credential AccessMITRE tactic Defense EvasionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic PersistenceMITRE tactic Privilege EscalationMITRE tactic ReconnaissanceMITRE tactic Resource DevelopmentPublication date method MetadataPublication date precision DayPublisher Kaspersky GReATPublisher domain securelist.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector CryptocurrencySector Financial ServicesSector TelecommunicationsSector Transportation and LogisticsSource type operational CTI publicationStatistical use incident_or_observationTarget DevelopersTarget EmployeesTarget ExecutivesThreat group APT43 / KimsukyThreat group BlueNoroffThreat group Lazarus GroupThreat-group identifier APT38Threat-group identifier TA444Threat-group identifier UNC1549TTP CAPTCHA bypassTTP Command and controlTTP Credential theftTTP Data exfiltrationTTP Deepfake impersonationTTP Defense evasionTTP Fake website or serviceTTP Malware generationTTP PowerShell executionTTP SpearphishingTTP Target research / OSINTYear 2025
Core research
Find related
Recorded Future threat-research report covering Identity fraud and impersonation, Obfuscation and evasion, and Reconnaissance and target research. Indexed with APT28 / Fancy Bear, Cryptocurrency, and Hugging Face context.
Actor motivation EspionageActor motivation FinancialAI relevance core_ai_attackAI technology Large language modelAI use case Identity fraud and impersonationAI use case Obfuscation and evasionAI use case Reconnaissance and target researchAI use case Translation and localizationAI use case Vulnerability researchAttack vector Business email compromiseAttack vector Credential theftAttack vector Spearphishing
Show 125 more tags Attack vector Supply chainCampaign Operation SalmonSlalomCountry or region BrazilCountry or region CanadaCountry or region ChinaCountry or region FranceCountry or region GermanyCountry or region IranCountry or region JapanCountry or region North KoreaCountry or region RussiaCountry or region TaiwanCountry or region UkraineCountry or region United StatesCVE CVE-2021-26855CVE CVE-2021-26857CVE CVE-2021-26858CVE CVE-2021-27065CVE CVE-2021-43798CVE CVE-2023-2868CVE CVE-2023-3519CVE CVE-2023-7102CVE CVE-2024-3400CVE CVE-2025-0282CVE CVE-2025-61882Data type Credentials and passwordsData type Cryptocurrency keys or seed phrasesData type Documents and filesData type Financial and payment dataData type Personally identifiable informationData type Session cookies or tokensData type Source codeEvidence inventory Contains extracted IOCsEvidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence landscape In-the-wild observedEvidence landscape Proof of conceptEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius approximately 1,400 accounts · medium confidenceExtracted metric · Blast Radius at least 1,494 individuals · medium confidenceExtracted metric · Blast Radius over 50 victims · medium confidenceExtracted metric · Duration Or Dwell 30 days · medium confidenceExtracted metric · Percentage 1% · medium confidenceExtracted metric · Percentage 10% · medium confidenceImpact Credential compromiseImpact Data theft or exfiltrationImpact EspionageImpact Ransomware or extortionImpact Service disruptionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure CloudInfrastructure EmailInfrastructure EndpointInfrastructure Messaging platformInfrastructure SaaSIOC · Defanged Domain hopto[.]orgIOC · Defanged Domain my5353[.]comIOC · Defanged Domain resource[.]infinityfreeapp[.]comIOC · Defanged Domain stayathomeclasses[.]comKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationKill Chain phase ReconnaissanceLLM model ChatGPTLLM provider Hugging FaceLLM provider OpenAIMalware or tool FatalRAT backdoorMalware or tool LAMEHUGMITRE tactic CollectionMITRE tactic Command and ControlMITRE tactic Credential AccessMITRE tactic Defense EvasionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic Lateral MovementMITRE tactic PersistenceMITRE tactic Privilege EscalationMITRE tactic ReconnaissanceMITRE tactic Resource DevelopmentPublication date method TextPublication date precision DayPublisher Recorded FuturePublisher domain recordedfuture.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSector CryptocurrencySector EducationSector Financial ServicesSector GovernmentSector TelecommunicationsSector Transportation and LogisticsSource type threat-research reportStatistical use context_or_observationTarget Consumers or individualsTarget DevelopersTarget EmployeesTarget ExecutivesThreat group APT28 / Fancy BearThreat group APT41Threat group Scattered SpiderThreat-group identifier APT28Threat-group identifier APT41Threat-group identifier STORM-0501Threat-group identifier UNC3944Threat-group identifier UNC4841TTP Business email compromiseTTP Command and controlTTP Credential theftTTP Data exfiltrationTTP Defense evasionTTP Fake website or serviceTTP MFA/session-token theftTTP ObfuscationTTP Password sprayingTTP PowerShell executionTTP SpearphishingTTP Supply-chain compromiseYear 2025
Core research
Find related
UK Government forecast or strategic assessment covering Deepfake video or image, Deepfake voice, and Identity fraud and impersonation. Indexed with Artificial Intelligence and Anthropic context.
Actor motivation Influence / information operationsAI relevance core_ai_attackAI technology Agentic AIAI technology Computer vision / OCRAI technology Deepfake / synthetic mediaAI technology Generative AIAI technology Large language modelAI technology Speech or voice synthesisAI use case Deepfake video or imageAI use case Deepfake voiceAI use case Identity fraud and impersonationAI use case Influence operations
Show 152 more tags AI use case Obfuscation and evasionAI use case Translation and localizationAI use case Vulnerability researchAttack vector Business email compromiseAttack vector SpearphishingCountry or region AfricaCountry or region BrazilCountry or region CanadaCountry or region ChinaCountry or region European UnionCountry or region FranceCountry or region GermanyCountry or region IndiaCountry or region IsraelCountry or region JapanCountry or region UkraineCountry or region United KingdomCountry or region United StatesData type Credentials and passwordsData type Documents and filesData type Financial and payment dataData type Personally identifiable informationEvidence inventory Contains extracted IOCsEvidence inventory Contains extracted metricsEvidence landscape Controlled studyEvidence landscape Forecast or predictionEvidence landscape In-the-wild observedEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 10 Countries · medium confidenceExtracted metric · Blast Radius 3 system · medium confidenceExtracted metric · Blast Radius 30 countries · medium confidenceExtracted metric · Duration Or Dwell 10 years · medium confidenceExtracted metric · Duration Or Dwell 15 years · medium confidenceExtracted metric · Duration Or Dwell 16 months · medium confidenceExtracted metric · Duration Or Dwell 2 months · medium confidenceExtracted metric · Duration Or Dwell 2 years · medium confidenceExtracted metric · Duration Or Dwell 20 months · medium confidenceExtracted metric · Duration Or Dwell 3 years · medium confidenceExtracted metric · Duration Or Dwell 5 years · medium confidenceExtracted metric · Duration Or Dwell 50 days · medium confidenceExtracted metric · Duration Or Dwell 6 months · medium confidenceExtracted metric · Duration Or Dwell 8 months · medium confidenceExtracted metric · Financial Value $15,000 · medium confidenceExtracted metric · Financial Value $700k · medium confidenceExtracted metric · Percentage 1.5% · medium confidenceExtracted metric · Percentage 1% · medium confidenceExtracted metric · Percentage 10% · medium confidenceExtracted metric · Percentage 135% · medium confidenceExtracted metric · Percentage 2% · medium confidenceExtracted metric · Percentage 20% · medium confidenceExtracted metric · Percentage 21% · medium confidenceExtracted metric · Percentage 22% · medium confidenceExtracted metric · Percentage 26% · medium confidenceExtracted metric · Percentage 3% · medium confidenceExtracted metric · Percentage 30% · medium confidenceExtracted metric · Percentage 38% · medium confidenceExtracted metric · Percentage 4% · medium confidenceExtracted metric · Percentage 40% · medium confidenceExtracted metric · Percentage 42.5% · medium confidenceExtracted metric · Percentage 50% · medium confidenceExtracted metric · Percentage 54% · medium confidenceExtracted metric · Percentage 60% · medium confidenceExtracted metric · Percentage 80% · medium confidenceExtracted metric · Percentage 84.3% · medium confidenceImpact Service disruptionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure Social mediaIOC · Ipv4 5.2.1.1IOC · Ipv4 5.2.1.2IOC · Ipv4 5.2.3.2IOC · Md5 075b051ec3d22dac7b33f788da631fd4IOC · Md5 077e29b11be80ab57e1a2ecabb7da330IOC · Md5 1457c0d6bfcb4967418bfb8ac142f64aIOC · Md5 294a8ed24b1ad22ec2e7efea049b8737IOC · Md5 3c44405d619a6920384a45bce876b41eIOC · Md5 3f5ee243547dee91fbd053c1c4a845aaIOC · Md5 41c542dfe6e4fc3deb251d64cf6ed2e4IOC · Md5 4496bf24afe7fab6f046bf4923da8de6IOC · Md5 462211f67c7d858f663355eff93b745eIOC · Md5 61d77652c97ef636343742fc3dcf3ba9IOC · Md5 65699726a3c601b9f31bf04019c8593cIOC · Md5 6b493230205f780e1bc26945df7481e5IOC · Md5 757b505cfd34c64c85ca5b5690ee5293IOC · Md5 9d2682367c3935defcb1f9e247a97c0dIOC · Md5 9d5609613524ecf4f15af0f7b31abca4IOC · Md5 9d89448b63ce1e2e8dc7af72c984c196IOC · Md5 ad1f8bb9b51f023cdc80cf94bb615aa9IOC · Md5 adf7ee2dcf142b0e11888e72b43fcb75IOC · Md5 b8b9c74ac526fffbeb2d39ab038d1cd7IOC · Md5 c26820b8a4c1b3c2aa868d6d57e14a79IOC · Md5 c74956ffb38ba48ed6ce977af6727275IOC · Md5 d76d8deea9c19cc9aaf2237d2bf2f785IOC · Sha1 de8ba9b01c9ab7cbabf5c33b80b7bbc618857627Kill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationLLM model ChatGPTLLM model ClaudeLLM model GeminiLLM model GPT-4LLM model LlamaLLM model Microsoft CopilotLLM model Mistral / MixtralLLM provider AnthropicLLM provider GoogleLLM provider MetaLLM provider MicrosoftLLM provider Mistral AILLM provider OpenAILLM provider xAIMalicious AI tool FraudGPTMalicious AI tool WormGPTMITRE tactic CollectionMITRE tactic Defense EvasionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic Initial AccessMITRE tactic Privilege EscalationPublication date method TextPublication date precision DayPublisher UK GovernmentPublisher domain gov.ukRelevance basis threat assessment, forecast, or red-team studyRetrieval method DirectReview requirement Manual review requiredSector Artificial IntelligenceSector DefenseSector EducationSector EnergySector Financial ServicesSector GovernmentSector HealthcareSector HospitalitySector Legal ServicesSector Nonprofit / NGOSector TechnologySector TelecommunicationsSector Transportation and LogisticsSource type forecast or strategic assessmentStatistical use context_onlyTarget AI researchers and expertsTarget Consumers or individualsTarget DevelopersTarget EmployeesTarget ExecutivesTTP Business email compromiseTTP Deepfake impersonationTTP Defense evasionTTP SpearphishingYear 2025
Core research
Find related
OpenAI operational CTI publication covering Influence operations. Indexed with OpenAI context.
Actor motivation Influence / information operationsAI relevance core_ai_attackAI use case Influence operationsCountry or region RussiaCountry or region United StatesEvidence inventory Contains extracted IOCsEvidence quality Usable Machine ExtractionInclusion Core AI-attack researchIOC · Md5 85b6659ca9e463e0750d31659f8e4cb4IOC · Md5 ab11d2d0849ad9544249bf7b77ee46feIOC · Md5 dba2f0e83ba4615a71894fd7fd1656e1IOC · Md5 ff8ab22ad273ff79a4c9840f0c209fe6
Show 14 more tags Kill Chain phase Actions on ObjectivesLLM model ChatGPTLLM provider OpenAIPublication date method TextPublication date precision DayPublisher OpenAIPublisher domain openai.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method Jina Reader ProxyReview requirement Manual review requiredSource type operational CTI publicationStatistical use incident_or_observationTarget DevelopersYear 2025
Core research
Find related
OpenAI operational CTI publication covering Identity fraud and impersonation, Obfuscation and evasion, and Translation and localization. Indexed with OpenAI context.
AI relevance core_ai_attackAI use case Identity fraud and impersonationAI use case Obfuscation and evasionAI use case Translation and localizationCountry or region ChinaEvidence inventory Contains extracted IOCsEvidence landscape Forecast or predictionEvidence quality Usable Machine ExtractionImpact Financial fraudInclusion Core AI-attack researchInfrastructure Messaging platformInfrastructure Social media
Show 19 more tags IOC · Md5 25a0f773cf5ad8f8324f2097f9a07ac2IOC · Md5 47a709ed076df4faf13594bbd8a3505bKill Chain phase Actions on ObjectivesLLM model ChatGPTLLM provider OpenAIMITRE tactic CollectionMITRE tactic Defense EvasionPublication date method Publisher Verified OverridePublication date precision DayPublisher OpenAIPublisher domain openai.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method Jina Reader ProxyReview requirement Manual review requiredSource type operational CTI publicationStatistical use incident_or_observationTarget EmployeesTTP ObfuscationYear 2025
Core research
Find related
SentinelOne operational CTI publication covering Malware development, Obfuscation and evasion, and Translation and localization. Indexed with APT28 / Fancy Bear, Education, and Anthropic context.
AI relevance core_ai_attackAI technology Large language modelAI use case Malware developmentAI use case Obfuscation and evasionAI use case Translation and localizationAI use case Vulnerability researchCountry or region IranCountry or region North KoreaData type Credentials and passwordsData type Documents and filesData type Personally identifiable informationEvidence inventory Contains extracted IOCs
Show 99 more tags Evidence inventory Contains extracted metricsEvidence landscape Controlled studyEvidence landscape Forecast or predictionEvidence landscape In-the-wild observedEvidence landscape Proof of conceptEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius more than 7,000 samples · medium confidenceExtracted metric · Duration Or Dwell 2 years · medium confidenceImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EndpointInfrastructure MobileIOC · Sha256 09bf891b7b35b2081d3ebca8de715da07a70151227ab55aec1da26eb769c006fIOC · Sha256 1458b6dc98a878f237bfb3c3f354ea6e12d76e340cefe55d6a1c9c7eb64c9aeeIOC · Sha256 1612ab799df51a7f1169d3f47ea129356b42c8ad81286d05b0256f80c17d4089IOC · Sha256 165eaf8183f693f644a8a24d2ec138cd4f8d9fd040e8bafc1b021a0f973692ddIOC · Sha256 2755e1ec1e4c3c0cd94ebe43bd66391f05282b6020b2177ee3b939fdd33216f6IOC · Sha256 2eb18873273e157a7244bb165d53ea3637c76087eea84b0ab635d04417ffbe1bIOC · Sha256 3082156a26534377a8a8228f44620a5bb00440b37b0cf7666c63c542232260f2IOC · Sha256 384e8f3d300205546fb8c9b9224011b3b3cb71adc994180ff55e1e6416f65715IOC · Sha256 3afbb9fe6bab2cad83c52a3f1a12e0ce979fe260c55ab22a43c18035ff7d7f38IOC · Sha256 4c73717d933f6b53c40ed1b211143df8d011800897be1ceb5d4a2af39c9d4cccIOC · Sha256 4ddbc14d8b6a301122c0ac6e22aef6340f45a3a6830bcdacf868c755a7162216IOC · Sha256 5ab16a59b12c7c5539d9e22a090ba6c7942fbc5ab8abbc5dffa6b6de6e0f2fc6IOC · Sha256 5f6bfdd430a23afdc518857dfff25a29d85ead441dfa0ee363f4e73f240c89f4IOC · Sha256 68ca559bf6654c7ca96c10abb4a011af1f4da0e6d28b43186d1d48d2f936684cIOC · Sha256 75b4ad99f33d1adbc0d71a9da937759e6e5788ad0f8a2c76a34690ef1c49ebf5IOC · Sha256 766c356d6a4b00078a0293460c5967764fcd788da8c1cd1df708695f3a15b777IOC · Sha256 7bbb06479a2e554e450beb2875ea19237068aa1055a4d56215f4e9a2317f8ce6IOC · Sha256 8013b23cb78407675f323d54b6b8dfb2a61fb40fb13309337f5b662dbd812a5dIOC · Sha256 854b559bae2ce8700edd75808267cfb5f60d61ff451f0cf8ec1d689334ac8d0bIOC · Sha256 943d3537730e41e0a6fe8048885a07ea2017847558a916f88c2c9afe32851fe6IOC · Sha256 a30930dfb655aa39c571c163ada65ba4dec30600df3bf548cc48bedd0e841416IOC · Sha256 a32a3751dfd4d7a0a66b7ecbd9bacb5087076377d486afdf05d3de3cb7555501IOC · Sha256 a67465075c91bb15b81e1f898f2b773196d3711d8e1fb321a9d6647958be436bIOC · Sha256 ae6ed1721d37477494f3f755c124d53a7dd3e24e98c20f3a1372f45cc8130989IOC · Sha256 b2bda70318af89b9e82751eb852ece626e2928b94ac6af6e6c7031b3d016ebd2IOC · Sha256 b3fcba809984eaffc5b88a1bcded28ac50e71965e61a66dd959792f7750b9e87IOC · Sha256 b43e7d481c4fdc9217e17908f3a4efa351a1dab867ca902883205fe7d1aab5e7IOC · Sha256 b49aa9efd41f82b34a7811a7894f0ebf04e1d9aab0b622e0083b78f54fe8b466IOC · Sha256 bb2836148527744b11671347d73ca798aca9954c6875082f9e1176d7b52b720fIOC · Sha256 bdb33bbb4ea11884b15f67e5c974136e6294aa87459cdc276ac2eea85b1deaa3IOC · Sha256 c1a80983779d8408a9c303d403999a9aef8c2f0fe63f8b5ca658862f66f3db16IOC · Sha256 c5ae843e1c7769803ca70a9d5b5574870f365fb139016134e5dd3cb1b1a65f5fIOC · Sha256 c86a5fcefbf039a72bd8ad5dc70bcb67e9c005f40a7bacd2f76c793f85e9a061IOC · Sha256 cf4d430d0760d59e2fa925792f9e2b62d335eaf4d664d02bff16dd1b522a462aIOC · Sha256 d1b48715ace58ee3bfb7af34066491263b885bd865863032820dccfe184614adIOC · Sha256 d6af1c9f5ce407e53ec73c8e7187ed804fb4f80cf8dbd6722fc69e15e135db2eIOC · Sha256 dc9f49044d16abfda299184af13aa88ab2c0fda9ca7999adcdbd44e3c037a8b1IOC · Sha256 e24fe0dd0bf8d3943d9c4282f172746af6b0787539b371e6626bdb86605ccd70IOC · Sha256 e88a7b9ad5d175383d466c5ad7ebd7683d60654d2fa2aca40e2c4eb9e955c927Kill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationLLM model ChatGPTLLM model DeepSeekLLM model GeminiLLM model GPT-4LLM model Mistral / MixtralLLM provider AnthropicLLM provider DeepSeekLLM provider GoogleLLM provider Mistral AILLM provider OpenAILLM provider xAIMalicious AI tool FraudGPTMalicious AI tool WormGPTMalware or tool LAMEHUGMalware or tool PromptStealMalware or tool PromptSteal malwareMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessPublication date method MetadataPublication date precision DayPublisher SentinelOnePublisher domain sentinelone.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector EducationSector TelecommunicationsSource type operational CTI publicationStatistical use incident_or_observationTarget DevelopersTarget ExecutivesTarget Security researchersThreat group APT28 / Fancy BearThreat-group identifier APT28TTP Data exfiltrationTTP Malware generationTTP ObfuscationTTP Prompt injectionYear 2025
Core research
Find related
UNODC government or law-enforcement publication covering CAPTCHA bypass, Deepfake video or image, and Deepfake voice. Indexed with FunkSec, Cryptocurrency, and OpenAI context.
Actor motivation Influence / information operationsAI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI technology Generative AIAI technology Large language modelAI technology Speech or voice synthesisAI use case CAPTCHA bypassAI use case Deepfake video or imageAI use case Deepfake voiceAI use case Identity fraud and impersonationAI use case Influence operationsAI use case Malware development
Show 97 more tags AI use case Obfuscation and evasionAI use case Phishing and lure generationAI use case Reconnaissance and target researchAI use case Translation and localizationAI use case Vulnerability researchAttack vector Business email compromiseAttack vector Credential theftAttack vector SmishingCountry or region ChinaCountry or region FranceCountry or region JapanCountry or region RussiaCountry or region South KoreaCountry or region United KingdomCountry or region United StatesCountry or region VietnamData type Credentials and passwordsData type Documents and filesData type Source codeEvidence inventory Contains extracted metricsEvidence landscape Controlled studyEvidence landscape Proof of conceptEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 43 countries · medium confidenceExtracted metric · Blast Radius 6 companies · medium confidenceExtracted metric · Blast Radius 85 Victim · medium confidenceExtracted metric · Duration Or Dwell 11 day · medium confidenceExtracted metric · Duration Or Dwell 20 seconds · medium confidenceExtracted metric · Duration Or Dwell 30 minutes · medium confidenceExtracted metric · Duration Or Dwell 64 Year · medium confidenceExtracted metric · Financial Value US $25 million · medium confidenceExtracted metric · Financial Value US $494,000 · medium confidenceExtracted metric · Financial Value US$118,000 · medium confidenceImpact Credential compromiseImpact Data theft or exfiltrationImpact Financial fraudImpact Ransomware or extortionImpact Service disruptionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure Messaging platformInfrastructure MobileInfrastructure Social mediaKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationKill Chain phase ReconnaissanceKill Chain phase WeaponizationLLM model ChatGPTLLM provider OpenAIMalicious AI tool WormGPTMalware or tool AkiraBotMalware or tool FunkSecMITRE tactic CollectionMITRE tactic Defense EvasionMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic ReconnaissancePublication date method Publisher Verified OverridePublication date precision MonthPublisher UNODCPublisher domain unodc.orgRelevance basis official advisory, fraud alert, or regional threat reportRetrieval method DirectReview requirement Manual review requiredSector CryptocurrencySector EducationSector Financial ServicesSector GovernmentSector HealthcareSector HospitalitySector TechnologySector TelecommunicationsSource type government or law-enforcement publicationStatistical use context_or_incidentTarget Consumers or individualsTarget DevelopersTarget EmployeesTarget ExecutivesThreat group FunkSecTTP Business email compromiseTTP CAPTCHA bypassTTP Credential harvestingTTP Credential theftTTP Data exfiltrationTTP Deepfake impersonationTTP Defense evasionTTP Fake website or serviceTTP ObfuscationTTP Phishing link or attachmentTTP Target research / OSINTYear 2025
Core research
Find related
Anthropic provider or government report covering Reconnaissance and target research, Data exfiltration, and Agentic AI. Indexed with Cryptocurrency and Anthropic context.
AI relevance core_ai_attackAI technology Agentic AIAI technology Large language modelAI use case Reconnaissance and target researchCountry or region North KoreaCountry or region VietnamData type Credentials and passwordsData type Cryptocurrency keys or seed phrasesData type Documents and filesData type Financial and payment dataEvidence inventory Contains extracted metricsEvidence landscape Forecast or prediction
Show 40 more tags Evidence landscape Underground-market observationEvidence quality Usable Machine ExtractionExtracted metric · Financial Value $1200 · medium confidenceExtracted metric · Financial Value $400 · medium confidenceExtracted metric · Financial Value $500,000. · medium confidenceImpact Data theft or exfiltrationImpact Financial fraudImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailKill Chain phase Actions on ObjectivesKill Chain phase ExploitationKill Chain phase ReconnaissanceLLM model ClaudeLLM provider AnthropicMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic ReconnaissancePublication date method Publisher Verified OverridePublication date precision DayPublisher AnthropicPublisher domain anthropic.comRelevance basis AI misuse, abuse-disruption, or threat research reportRetrieval method DirectReview requirement Manual review requiredSector CryptocurrencySector Financial ServicesSector GovernmentSector TechnologySector TelecommunicationsSource type provider or government reportStatistical use incident_or_observationTarget Consumers or individualsTarget DevelopersTarget EmployeesTarget ExecutivesTTP Data exfiltrationYear 2025
Core research
Find related
Palo Alto Networks Unit 42 operational CTI publication covering CAPTCHA bypass, Deepfake video or image, and Identity fraud and impersonation. Indexed with Akira and Legal Services context.
AI relevance core_ai_attackAI technology Agentic AIAI technology Deepfake / synthetic mediaAI technology Generative AIAI use case CAPTCHA bypassAI use case Deepfake video or imageAI use case Identity fraud and impersonationAI use case Phishing and lure generationAttack vector Business email compromiseCountry or region FranceCountry or region IndiaCountry or region Japan
Show 49 more tags Country or region North KoreaCountry or region RussiaData type Credentials and passwordsData type Documents and filesEvidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence landscape In-the-wild observedEvidence landscape Incident responseEvidence quality Usable Machine ExtractionExtracted metric · Duration Or Dwell 10 seconds · medium confidenceExtracted metric · Duration Or Dwell 60 seconds · medium confidenceExtracted metric · Percentage 11% · medium confidenceExtracted metric · Percentage 16% · medium confidenceExtracted metric · Percentage 30% · medium confidenceExtracted metric · Percentage 40% · medium confidenceExtracted metric · Percentage 70% · medium confidenceImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure EndpointInfrastructure Messaging platformInfrastructure SaaSKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationMITRE tactic CollectionMITRE tactic ImpactMITRE tactic Initial AccessPublication date method MetadataPublication date precision DayPublisher Palo Alto Networks Unit 42Publisher domain unit42.paloaltonetworks.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector Legal ServicesSector TelecommunicationsSource type operational CTI publicationStatistical use incident_or_observationTarget EmployeesTarget ExecutivesThreat group AkiraThreat group Lazarus GroupTTP Business email compromiseTTP CAPTCHA bypassTTP Deepfake impersonationTTP Phishing link or attachmentYear 2025
Core research
Find related
CrowdStrike threat-research report covering Command and control, Deepfake video or image, and Deepfake voice. Indexed with Financial Services and Anthropic context.
AI relevance core_ai_attackAI technology Agentic AIAI technology Deepfake / synthetic mediaAI technology Generative AIAI technology Large language modelAI use case Command and controlAI use case Deepfake video or imageAI use case Deepfake voiceAI use case Identity fraud and impersonationAI use case Obfuscation and evasionAI use case Reconnaissance and target researchAI use case Translation and localization
Show 73 more tags AI use case Vulnerability researchAttack vector Business email compromiseAttack vector SpearphishingAttack vector Supply chainAttack vector VishingCountry or region ChinaData type Credentials and passwordsData type Documents and filesEvidence inventory Contains extracted metricsEvidence landscape Incident responseEvidence landscape Threat landscape reportEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 25 Endpoint · medium confidenceExtracted metric · Blast Radius 26 Endpoint · medium confidenceExtracted metric · Duration Or Dwell 10 Minutes · medium confidenceExtracted metric · Percentage 12% · medium confidenceExtracted metric · Percentage 54% · medium confidenceExtracted metric · Percentage 94% · medium confidenceImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure EndpointKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationKill Chain phase ReconnaissanceKill Chain phase WeaponizationLLM model ClaudeLLM model Microsoft CopilotLLM provider AnthropicLLM provider MicrosoftLLM provider OpenAIMalware or tool PoisonIvy malwareMITRE tactic Command and ControlMITRE tactic Credential AccessMITRE tactic Defense EvasionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic Initial AccessMITRE tactic Lateral MovementMITRE tactic PersistenceMITRE tactic Privilege EscalationMITRE tactic ReconnaissancePublication date method TextPublication date precision DayPublisher CrowdStrikePublisher domain crowdstrike.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSector Financial ServicesSector GovernmentSource type threat-research reportStatistical use context_or_observationTarget DevelopersTarget ExecutivesTTP Business email compromiseTTP Command and controlTTP Data exfiltrationTTP Deepfake impersonationTTP Defense evasionTTP ObfuscationTTP PowerShell executionTTP Script generationTTP SpearphishingTTP Supply-chain compromiseTTP Voice phishing / vishingYear 2025
Core research
Find related
CrowdStrike threat-research report covering Deepfake video or image, Identity fraud and impersonation, and Malware development. Indexed with APT42 / Charming Kitten, Financial Services, and Anthropic context.
Actor motivation HacktivismAI relevance core_ai_attackAI technology Agentic AIAI technology Deepfake / synthetic mediaAI technology Generative AIAI technology Large language modelAI use case Deepfake video or imageAI use case Identity fraud and impersonationAI use case Malware developmentAI use case Obfuscation and evasionAI use case Phishing and lure generationAI use case Vulnerability research
Show 84 more tags Attack vector Credential theftAttack vector Supply chainAttack vector VishingCountry or region ChinaCountry or region North KoreaCountry or region RussiaData type Credentials and passwordsData type Documents and filesData type Personally identifiable informationEvidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence landscape Incident responseEvidence landscape Threat landscape reportEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 25 Endpoint · medium confidenceExtracted metric · Blast Radius 26 Endpoint · medium confidenceExtracted metric · Blast Radius over 320 companies · medium confidenceExtracted metric · Duration Or Dwell 10 Minutes · medium confidenceExtracted metric · Duration Or Dwell 12 months · medium confidenceExtracted metric · Duration Or Dwell 24 hours · medium confidenceExtracted metric · Percentage 130% · medium confidenceExtracted metric · Percentage 136% · medium confidenceExtracted metric · Percentage 185% · medium confidenceExtracted metric · Percentage 220% · medium confidenceExtracted metric · Percentage 27% · medium confidenceExtracted metric · Percentage 40% · medium confidenceExtracted metric · Percentage 71% · medium confidenceExtracted metric · Percentage 73% · medium confidenceExtracted metric · Percentage 81% · medium confidenceExtracted metric · Percentage 94% · medium confidenceImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EndpointInfrastructure SaaSKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationKill Chain phase WeaponizationLLM model ClaudeLLM model Microsoft CopilotLLM provider AnthropicLLM provider MicrosoftLLM provider OpenAIMalware or tool GenAI-built malwareMITRE tactic Defense EvasionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic Lateral MovementMITRE tactic PersistenceMITRE tactic Resource DevelopmentPublication date method TextPublication date precision DayPublisher CrowdStrikePublisher domain crowdstrike.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSector Financial ServicesSector GovernmentSector TelecommunicationsSource type threat-research reportStatistical use context_or_observationTarget DevelopersTarget EmployeesTarget ExecutivesThreat group APT42 / Charming KittenThreat group Famous ChollimaThreat group Scattered SpiderTTP Credential harvestingTTP Data exfiltrationTTP Deepfake impersonationTTP Malware generationTTP ObfuscationTTP Ransomware deploymentTTP Script generationTTP Supply-chain compromiseTTP Voice phishing / vishingYear 2025
Core research
Find related
Recorded Future threat-research report covering Code debugging and scripting, Deepfake video or image, and Identity fraud and impersonation. Indexed with Critical Infrastructure and Anthropic context.
Actor motivation HacktivismActor motivation Influence / information operationsAI relevance core_ai_attackAI technology Agentic AIAI technology Deepfake / synthetic mediaAI technology Generative AIAI technology Large language modelAI use case Code debugging and scriptingAI use case Deepfake video or imageAI use case Identity fraud and impersonationAI use case Influence operationsAI use case Malware development
Show 70 more tags AI use case Obfuscation and evasionAI use case Phishing and lure generationAI use case Reconnaissance and target researchAI use case Translation and localizationAttack vector SpearphishingCompanion source src-099Country or region CanadaCountry or region ChinaCountry or region IranCountry or region RussiaData type Credentials and passwordsData type Personally identifiable informationDuplicate lineage dup-001Evidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence landscape Incident responseEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 80 countries · medium confidenceExtracted metric · Duration Or Dwell 15 years · medium confidenceExtracted metric · Percentage 25% · medium confidenceImpact Credential compromiseImpact Data theft or exfiltrationImpact Financial fraudImpact Ransomware or extortionImpact Service disruptionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure Social mediaKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase ReconnaissanceKill Chain phase WeaponizationLLM model ClaudeLLM provider AnthropicLLM provider OpenAIMalicious AI tool FraudGPTMalicious AI tool WormGPTMalware or tool LAMEHUGMITRE tactic Defense EvasionMITRE tactic DiscoveryMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic ReconnaissanceMITRE tactic Resource DevelopmentPublication date method Publisher Verified OverridePublication date precision MonthPublisher Recorded FuturePublisher domain assets.recordedfuture.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSector Critical InfrastructureSector DefenseSector GovernmentSource type threat-research reportStatistical use context_or_observationTarget DevelopersTarget EmployeesTarget ExecutivesTTP Credential theftTTP Data exfiltrationTTP Deepfake impersonationTTP Defense evasionTTP Malware generationTTP Prompt injectionTTP SpearphishingYear 2025
Core research
Find related
Palo Alto Networks Unit 42 operational CTI publication covering CAPTCHA bypass, Identity fraud and impersonation, and Reconnaissance and target research. Indexed with Financial Services and Anthropic context.
Actor motivation FinancialAI relevance core_ai_attackAI technology Agentic AIAI technology Generative AIAI use case CAPTCHA bypassAI use case Identity fraud and impersonationAI use case Reconnaissance and target researchAttack vector Business email compromiseAttack vector Credential theftAttack vector Malicious advertisementAttack vector SmishingCountry or region France
Show 79 more tags Country or region IranCountry or region JapanCountry or region North KoreaCountry or region RussiaCVE CVE-2024-3400Data type Credentials and passwordsData type Documents and filesData type Session cookies or tokensEvidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence landscape Incident responseEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 2000 companies · medium confidenceExtracted metric · Campaign Or Intrusion Duration 40 minutes · medium confidenceExtracted metric · Duration Or Dwell 90 minutes · medium confidenceExtracted metric · Percentage 23% · medium confidenceExtracted metric · Percentage 27% · medium confidenceExtracted metric · Percentage 35% · medium confidenceExtracted metric · Percentage 36% · medium confidenceExtracted metric · Percentage 45% · medium confidenceExtracted metric · Percentage 60% · medium confidenceExtracted metric · Percentage 65% · medium confidenceExtracted metric · Percentage 66% · medium confidenceExtracted metric · Percentage 73% · medium confidenceImpact Credential compromiseImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure CloudInfrastructure EmailInfrastructure EndpointInfrastructure MobileInfrastructure SaaSInfrastructure Social mediaKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationKill Chain phase ReconnaissanceLLM model ClaudeLLM provider AnthropicMalware or tool LummaMITRE tactic Command and ControlMITRE tactic Credential AccessMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic Lateral MovementMITRE tactic PersistenceMITRE tactic ReconnaissancePublication date method MetadataPublication date precision DayPublisher Palo Alto Networks Unit 42Publisher domain unit42.paloaltonetworks.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector Financial ServicesSector GovernmentSector RetailSector TelecommunicationsSource type operational CTI publicationStatistical use incident_or_observationTarget EmployeesTarget ExecutivesTTP Business email compromiseTTP CAPTCHA bypassTTP Command and controlTTP Credential harvestingTTP Credential theftTTP Data exfiltrationTTP Malicious advertisingTTP MFA/session-token theftTTP Phishing link or attachmentTTP PowerShell executionYear 2025
Core research
Find related
Rapid7 threat-research report covering Identity fraud and impersonation, Credential harvesting, and Data exfiltration. Indexed with Black Basta and Transportation and Logistics context.
AI relevance core_ai_attackAI technology Generative AIAI use case Identity fraud and impersonationAttack vector Credential theftData type Credentials and passwordsData type Documents and filesEvidence landscape Incident responseEvidence quality Usable Machine ExtractionImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure Email
Show 26 more tags Infrastructure EndpointInfrastructure Messaging platformKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic Lateral MovementPublication date method MetadataPublication date precision DayPublisher Rapid7Publisher domain rapid7.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSector Transportation and LogisticsSource type threat-research reportStatistical use context_or_observationThreat group Black BastaThreat group Scattered SpiderTTP Credential harvestingTTP Data exfiltrationTTP MFA/session-token theftTTP Phishing link or attachmentYear 2025
Core research
Find related
Rapid7 threat-research report covering Deepfake video or image, Exploit development, and Identity fraud and impersonation. Indexed with Critical Infrastructure and Hugging Face context.
Actor motivation Disruption / destructionActor motivation Influence / information operationsAI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI technology Generative AIAI technology Large language modelAI use case Deepfake video or imageAI use case Exploit developmentAI use case Identity fraud and impersonationAI use case Influence operationsAI use case Malware developmentAI use case Obfuscation and evasion
Show 56 more tags AI use case Reconnaissance and target researchAttack vector Business email compromiseAttack vector Credential theftCampaign Operation ASTERIXCountry or region IranCountry or region IsraelData type Credentials and passwordsEvidence inventory Contains extracted metricsEvidence landscape Controlled studyEvidence landscape Incident responseEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionExtracted metric · Percentage 40% · medium confidenceExtracted metric · Percentage 95% · medium confidenceImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure EmailKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase ReconnaissanceKill Chain phase WeaponizationLLM model ChatGPTLLM model GrokLLM model Mistral / MixtralLLM provider Hugging FaceLLM provider Mistral AILLM provider OpenAILLM provider xAIMalicious AI tool DarkBERTMalicious AI tool FraudGPTMalicious AI tool WormGPTMITRE tactic Credential AccessMITRE tactic Defense EvasionMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic ReconnaissancePublication date method MetadataPublication date precision DayPublisher Rapid7Publisher domain rapid7.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSector Critical InfrastructureSource type threat-research reportStatistical use context_or_observationTarget EmployeesTarget ExecutivesTTP Business email compromiseTTP Credential theftTTP Deepfake impersonationTTP Exploit developmentTTP Malware generationTTP ObfuscationYear 2025
Core research
Find related
Rapid7 threat-research report covering Deepfake video or image, Identity fraud and impersonation, and Influence operations. Indexed with APT28 / Fancy Bear and Hugging Face context.
Actor motivation HacktivismActor motivation Influence / information operationsAI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI technology Generative AIAI technology Large language modelAI use case Deepfake video or imageAI use case Identity fraud and impersonationAI use case Influence operationsAI use case Malware developmentAI use case Obfuscation and evasionAI use case Reconnaissance and target research
Show 56 more tags Attack vector Business email compromiseAttack vector SpearphishingCampaign Operation ASTERIXCountry or region ChinaCountry or region RussiaData type Documents and filesEvidence landscape Incident responseEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure EmailInfrastructure Messaging platformKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase ReconnaissanceKill Chain phase WeaponizationLLM provider Hugging FaceLLM provider OpenAIMalicious AI tool FraudGPTMalicious AI tool Nytheon AIMalicious AI tool WormGPTMalware or tool FunkSecMITRE tactic Defense EvasionMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic ReconnaissanceMITRE tactic Resource DevelopmentPublication date method MetadataPublication date precision DayPublisher Rapid7Publisher domain rapid7.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSource type threat-research reportStatistical use context_or_observationTarget EmployeesTarget ExecutivesThreat group APT28 / Fancy BearThreat group APT31Threat group CyberAv3ngersThreat group FunkSecThreat group Lazarus GroupThreat group RansomHubThreat group SweetSpecterThreat-group identifier APT28Threat-group identifier APT31TTP Business email compromiseTTP Deepfake impersonationTTP Defense evasionTTP Malware generationTTP Ransomware deploymentTTP SpearphishingYear 2025
Core research
Find related
OpenAI operational CTI publication covering Influence operations. Indexed with OpenAI context.
Actor motivation EspionageActor motivation Influence / information operationsAI relevance core_ai_attackAI use case Influence operationsEvidence quality Usable Machine ExtractionImpact EspionageInclusion Core AI-attack researchKill Chain phase Actions on ObjectivesKill Chain phase ExploitationLLM provider OpenAIPublication date method Publisher Verified OverridePublication date precision Day
Show 8 more tags Publisher OpenAIPublisher domain openai.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method Jina Reader ProxyReview requirement Manual review requiredSource type operational CTI publicationStatistical use incident_or_observationYear 2025
Core research
Find related
Google Threat Intelligence Group / Mandiant operational CTI publication covering Obfuscation and evasion, Reconnaissance and target research, and Command and control. Indexed with UNC6032 and Cryptocurrency context.
AI relevance core_ai_attackAI use case Obfuscation and evasionAI use case Reconnaissance and target researchAttack vector Fake AI websiteAttack vector Malicious advertisementAttack vector Supply chainAttack vector VishingCountry or region European UnionCountry or region RussiaCountry or region United StatesCountry or region VietnamData type Credentials and passwords
Show 92 more tags Data type Cryptocurrency keys or seed phrasesData type Documents and filesData type Financial and payment dataData type Source codeEvidence inventory Contains extracted IOCsEvidence landscape Forecast or predictionEvidence quality Usable Machine ExtractionImpact Data theft or exfiltrationImpact Ransomware or extortionImpact Service disruptionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure Messaging platformInfrastructure Social mediaIOC · Defanged Domain adobe-express[.]comIOC · Defanged Domain ai-kling[.]comIOC · Defanged Domain aisoraplus[.]comIOC · Defanged Domain api[.]telegram[.]orgIOC · Defanged Domain artisanaqua[.]ddnsking[.]comIOC · Defanged Domain boostcreatives-ai[.]comIOC · Defanged Domain canva-dreamlab[.]comIOC · Defanged Domain canvadream-lab[.]comIOC · Defanged Domain canvadreamlab[.]comIOC · Defanged Domain canvaproai[.]comIOC · Defanged Domain capcutproai[.]comIOC · Defanged Domain creativepro-ai[.]comIOC · Defanged Domain creativespro-ai[.]comIOC · Defanged Domain dreamai-luma[.]comIOC · Defanged Domain github[.]comIOC · Defanged Domain klings-ai[.]comIOC · Defanged Domain klingxai[.]comIOC · Defanged Domain luma-aidream[.]comIOC · Defanged Domain luma-dream[.]comIOC · Defanged Domain luma-dreamai[.]comIOC · Defanged Domain luma-dreammachine[.]comIOC · Defanged Domain lumaai-dream[.]comIOC · Defanged Domain lumaai-lab[.]comIOC · Defanged Domain lumaai-labs[.]comIOC · Defanged Domain lumaaidream[.]comIOC · Defanged Domain lumaailabs[.]comIOC · Defanged Domain quirkquestai[.]comIOC · Defanged Domain strokes[.]zapto[.]orgIOC · Defanged Domain zapto[.]orgIOC · Sha256 1a037da4103e38ff95cb0008a5e38fd6a8e7df5bc8e2d44e496b7a5909ddebebIOC · Sha256 4982a33e0c2858980126b8279191cb4eddd0a35f936cf3eda079526ba7c76959IOC · Sha256 839260ac321a44da55d4e6a5130c12869066af712f71c558bd42edd56074265bIOC · Sha256 8863065544df546920ce6189dd3f99ab3f5d644d3d9c440667c1476174ba862bIOC · Sha256 8d2c9c2b5af31e0e74185a82a816d3d019a0470a7ad8f5c1b40611aa1fd275ccIOC · Sha256 a0e75bd0b0fa0174566029d0e50875534c2fcc5ba982bd539bdeff506cae32d3IOC · Sha256 d3f50dc61d8c2be665a2d3933e2668448edc31546fea84517f8e61237c6d2e5dIOC · Sha256 dcb1e9c6b066c2169928ae64e82343a250261f198eb5d091fd7928b69ed135d3IOC · Sha256 e663c1ba289d890a74e33c7e99f872c9a7b63e385a6a4af10a856d5226c9a822Kill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase ExploitationKill Chain phase InstallationKill Chain phase ReconnaissanceMalware or tool STARKVEIL malwareMITRE tactic CollectionMITRE tactic Command and ControlMITRE tactic Defense EvasionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic PersistenceMITRE tactic ReconnaissancePublication date method TextPublication date precision DayPublisher Google Threat Intelligence Group / MandiantPublisher domain cloud.google.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector CryptocurrencySector Financial ServicesSector GovernmentSector TelecommunicationsSource type operational CTI publicationStatistical use incident_or_observationTarget DevelopersThreat group UNC6032Threat-group identifier UNC6032Threat-group identifier UNC6671TTP Command and controlTTP Data exfiltrationTTP Defense evasionTTP Malicious advertisingTTP ObfuscationTTP PowerShell executionTTP Supply-chain compromiseTTP Voice phishing / vishingYear 2025
Core research
Find related
Check Point provider or government report covering Identity fraud and impersonation, Obfuscation and evasion, and Command and control. Indexed with Cryptocurrency and Google context.
AI relevance core_ai_attackAI technology Generative AIAI technology Large language modelAI use case Identity fraud and impersonationAI use case Obfuscation and evasionAttack vector Fake AI websiteAttack vector Malicious advertisementCountry or region AfricaCountry or region BrazilCountry or region CanadaCountry or region ChinaCountry or region France
Show 103 more tags Country or region GermanyCountry or region IndiaCountry or region IranCountry or region IsraelCountry or region JapanCountry or region North KoreaCountry or region RussiaCountry or region South KoreaCountry or region TaiwanCountry or region UkraineCountry or region United KingdomCountry or region United StatesCountry or region VietnamData type Credentials and passwordsData type Cryptocurrency keys or seed phrasesData type Documents and filesData type Session cookies or tokensEvidence inventory Contains extracted IOCsEvidence quality Usable Machine ExtractionImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure EndpointInfrastructure Messaging platformInfrastructure MobileInfrastructure Social mediaIOC · Defanged Domain ai-kling[.]comIOC · Defanged Domain facebook[.]comIOC · Defanged Domain kingaimediapro[.]comIOC · Defanged Domain kingaiplus[.]comIOC · Defanged Domain kingaitext[.]comIOC · Defanged Domain kingaivideotext[.]comIOC · Defanged Domain klingaieditor[.]comIOC · Defanged Domain klingaimedia[.]comIOC · Defanged Domain klingaistudio[.]comIOC · Defanged Domain klings-ai[.]comIOC · Defanged Domain klingturbo[.]comIOC · Defanged Domain klingxai[.]comIOC · Sha256 06d9d60ddbe835abc5b16911a35732cc9b56ea9425de210961a15d465823978fIOC · Sha256 0c9228983fbd928ac94c057a00d744d6be4bd4c1b39d1465b7d955b7d35bf496IOC · Sha256 1e66ebaef295c2a32245162979d167cebad1fece51b7cdb6a6c3a1d705befa6bIOC · Sha256 2588fdfa7417d617df2d31eddea710d0f964008abc2f4860cdff588ab9786d0aIOC · Sha256 2d5e01cfacdf9f900b51b0539e0809f22ce1859eac0886866af35a2eb2dc2d42IOC · Sha256 30e26f4fd7cb0ac626950bb01e01a2c02e277727d1d3ec94286a44af262f37cfIOC · Sha256 39d771c12bd5da15d3fb63905df1e2c4c7c12b8f77c630a35b247c418950eafeIOC · Sha256 3fba4a0942244e9c3ad25a57a21f91b06f8732a2ca36da948ae5f0afa51dc72bIOC · Sha256 4bbaf3ececd53bc4028723e87b1669268a6fadc4d480590c2d59bb4322a17de7IOC · Sha256 5200b27726c0be8e6f34a3920fbd5d40aeaec460169b1f3c7a174ebeee6553d9IOC · Sha256 557becfcc7eccaa5a7368a6d5583404af26aadede2c345d6070e6e9fab44a641IOC · Sha256 699e348260ae5b60cd822325f1c4bf2c793f6f25001357856c58520a9af10987IOC · Sha256 7035b5ba24146db537eedb1f05e6cad1775f9f5e81306f72422c03b288f75448IOC · Sha256 732aa8ed8ca9a12f4bfc29a693ec3eba74ed1b2d00de4296180d91b86d09747bIOC · Sha256 839371cd5a5d66828ac9524182769371dede9606826ad7c22c3bb18fb2ee91cbIOC · Sha256 9dab2badfdae86963b2f13ce8942fe78dd66ec497f8d82dd40c0cb5bec4fb2a7IOC · Sha256 a5baceb97a2be17fdd0c282292ebb0b5a56a555013a4c8fffcc2335c504780fbIOC · Sha256 b33e162a78b7b8e7dbbab5d1572d63814077fa524067ce79c37f52441b8bd384IOC · Sha256 beeea592251a0a205b3bdb34802bd2f4f5181ee38226a05ec468a86be44e9508IOC · Sha256 cee3f98b5f175219d025a92eddec4fd8bcaae31e6ad99321ae7c00b822063fc3IOC · Sha256 d1b712b215612c8df5fef02b614c616a78b723bffbec6e10e32bfd0b758df41bIOC · Sha256 d95b3eabfe9892371cb518fd6e733d2d33d2fabb2b1df4dab650a8f8e1ea8745IOC · Sha256 f5b31bd394e0a3adb6bd175207b8c3ccc51850c8f2cee1149a8421736168e13eIOC · Sha256 f89298933fed52511bb78f8f377979190e37367d72ccf4f3b81374a70362cc42Kill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationLLM model ChatGPTLLM model GeminiLLM provider GoogleLLM provider OpenAIMalware or tool PureHVNC RATMITRE tactic CollectionMITRE tactic Command and ControlMITRE tactic Defense EvasionMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic PersistencePublication date method MetadataPublication date precision DayPublisher Check PointPublisher domain research.checkpoint.comRelevance basis AI misuse, abuse-disruption, or threat research reportRetrieval method DirectReview requirement Manual review requiredSector CryptocurrencySector Financial ServicesSource type provider or government reportStatistical use incident_or_observationTarget DevelopersTarget Security researchersTTP Command and controlTTP Data exfiltrationTTP Defense evasionTTP Fake website or serviceTTP Malicious advertisingTTP MFA/session-token theftTTP ObfuscationYear 2025
Core research
Find related
UK Government provider or government report covering Exploit development, Influence operations, and Malware development. Indexed with Education context.
Actor motivation Disruption / destructionActor motivation HacktivismActor motivation Influence / information operationsAI relevance core_ai_attackAI technology Agentic AIAI technology Generative AIAI use case Exploit developmentAI use case Influence operationsAI use case Malware developmentAI use case Obfuscation and evasionAI use case Reconnaissance and target researchAI use case Vulnerability research
Show 43 more tags Attack vector Credential theftAttack vector Supply chainData type Credentials and passwordsData type Documents and filesEvidence landscape Controlled studyEvidence landscape Forecast or predictionEvidence quality Usable Machine ExtractionImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure Social mediaKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase ReconnaissanceKill Chain phase WeaponizationMITRE tactic Credential AccessMITRE tactic Defense EvasionMITRE tactic DiscoveryMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic ReconnaissancePublication date method MetadataPublication date precision DayPublisher UK GovernmentPublisher domain ncsc.gov.ukRelevance basis AI misuse, abuse-disruption, or threat research reportRetrieval method DirectReview requirement Manual review requiredSector EducationSector GovernmentSource type provider or government reportStatistical use incident_or_observationTarget DevelopersTTP Credential theftTTP Data exfiltrationTTP Defense evasionTTP Exploit developmentTTP Malware generationTTP Prompt injectionTTP Supply-chain compromiseYear 2025
Core research
Find related
Palo Alto Networks Unit 42 operational CTI publication covering CAPTCHA bypass, Identity fraud and impersonation, and Command and control. Indexed with Anthropic context.
AI relevance core_ai_attackAI technology Agentic AIAI technology Generative AIAI technology Large language modelAI use case CAPTCHA bypassAI use case Identity fraud and impersonationAttack vector Credential theftCountry or region IndiaCountry or region JapanData type Credentials and passwordsData type Documents and filesData type Source code
Show 51 more tags Evidence inventory Contains extracted IOCsEvidence inventory Contains extracted metricsEvidence landscape Controlled studyEvidence landscape Forecast or predictionEvidence landscape Incident responseEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionExtracted metric · Duration Or Dwell 30 days · medium confidenceExtracted metric · Duration Or Dwell 60 days · medium confidenceImpact Data theft or exfiltrationImpact Service disruptionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure CloudInfrastructure EmailInfrastructure EndpointInfrastructure MobileInfrastructure SaaSIOC · Defanged Domain badnews[.]xyzKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase ExploitationKill Chain phase ReconnaissanceLLM model ClaudeLLM provider AnthropicMITRE tactic Command and ControlMITRE tactic Credential AccessMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic Lateral MovementMITRE tactic Privilege EscalationPublication date method MetadataPublication date precision DayPublisher Palo Alto Networks Unit 42Publisher domain unit42.paloaltonetworks.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSource type operational CTI publicationStatistical use incident_or_observationTarget EmployeesTarget ExecutivesTTP CAPTCHA bypassTTP Command and controlTTP Credential harvestingTTP Credential theftTTP Data exfiltrationTTP Prompt injectionTTP Vulnerability scanningYear 2025
Core research
Find related
Check Point provider or government report covering Agentic AI. Indexed with Financial Services context.
AI relevance core_ai_attackAI technology Agentic AICountry or region ChinaCountry or region FranceCountry or region GermanyCountry or region JapanCountry or region TaiwanEvidence inventory Contains extracted IOCsEvidence inventory Contains extracted metricsEvidence landscape Incident responseEvidence quality Usable Machine ExtractionExtracted metric · Percentage 100% · medium confidence
Show 27 more tags Extracted metric · Percentage 20% · medium confidenceImpact Ransomware or extortionImpact Service disruptionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure CloudInfrastructure EmailInfrastructure EndpointInfrastructure SaaSIOC · Md5 8fe6d620a2ec11f1892ca9ec6d1bc182IOC · Md5 8fe6fc70a2ec11f1a7370f68f28e8e46Kill Chain phase Actions on ObjectivesMITRE tactic DiscoveryMITRE tactic ImpactPublication date method Publisher Verified OverridePublication date precision DayPublisher Check PointPublisher domain checkpoint.comRelevance basis AI misuse, abuse-disruption, or threat research reportRetrieval method Jina Reader ProxyReview requirement Manual review requiredSector Financial ServicesSector GovernmentSource type provider or government reportStatistical use incident_or_observationTarget EmployeesYear 2025
Core research
Find related
Check Point provider or government report covering Deepfake video or image, Deepfake voice, and Exploit development. Indexed with DeepSeek context.
Actor motivation Influence / information operationsAI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI technology Generative AIAI technology Large language modelAI use case Deepfake video or imageAI use case Deepfake voiceAI use case Exploit developmentAI use case Identity fraud and impersonationAI use case Influence operationsAI use case Malware developmentAI use case Translation and localization
Show 83 more tags AI use case Vulnerability researchAttack vector Supply chainCountry or region AfricaCountry or region BrazilCountry or region CanadaCountry or region ChinaCountry or region FranceCountry or region GermanyCountry or region IndiaCountry or region IranCountry or region IsraelCountry or region JapanCountry or region North KoreaCountry or region RussiaCountry or region South KoreaCountry or region TaiwanCountry or region UkraineCountry or region United KingdomCountry or region United StatesCountry or region VietnamData type Credentials and passwordsData type Documents and filesData type Financial and payment dataData type Session cookies or tokensEvidence inventory Contains extracted IOCsEvidence inventory Contains extracted metricsEvidence landscape In-the-wild observedEvidence landscape Incident responseEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionExtracted metric · Percentage 1.25% · medium confidenceExtracted metric · Percentage 11% · medium confidenceExtracted metric · Percentage 18% · medium confidenceExtracted metric · Percentage 21% · medium confidenceExtracted metric · Percentage 25% · medium confidenceExtracted metric · Percentage 27% · medium confidenceExtracted metric · Percentage 33% · medium confidenceExtracted metric · Percentage 37% · medium confidenceExtracted metric · Percentage 51% · medium confidenceExtracted metric · Percentage 7.5% · medium confidenceExtracted metric · Percentage 8% · medium confidenceImpact Data theft or exfiltrationImpact Financial fraudImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure EmailInfrastructure MobileIOC · Defanged Domain fia-gov[.]netIOC · Defanged Domain militarytc[.]comKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase WeaponizationLLM model ChatGPTLLM model DeepSeekLLM model Microsoft CopilotLLM provider DeepSeekLLM provider Hugging FaceLLM provider MicrosoftLLM provider OpenAIMITRE tactic CollectionMITRE tactic DiscoveryMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessPublication date method MetadataPublication date precision DayPublisher Check PointPublisher domain research.checkpoint.comRelevance basis AI misuse, abuse-disruption, or threat research reportRetrieval method DirectReview requirement Manual review requiredSource type provider or government reportStatistical use incident_or_observationTarget EmployeesTTP Data exfiltrationTTP Deepfake impersonationTTP Exploit developmentTTP Malware generationTTP MFA/session-token theftTTP Ransomware deploymentTTP Supply-chain compromiseYear 2025
Core research
Find related
Fortinet threat-research report covering Deepfake video or image, Identity fraud and impersonation, and Malware development. Indexed with APT28 / Fancy Bear, Critical Infrastructure, and OpenAI context.
Actor motivation EspionageActor motivation HacktivismAI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI use case Deepfake video or imageAI use case Identity fraud and impersonationAI use case Malware developmentAI use case Obfuscation and evasionAI use case Phishing and lure generationAI use case Reconnaissance and target researchAttack vector Credential theftAttack vector Spearphishing
Show 169 more tags Attack vector VishingCountry or region AfricaCountry or region CanadaCountry or region ChinaCountry or region United KingdomCountry or region United StatesCVE CVE-2017-0147CVE CVE-2017-18377CVE CVE-2018-10561CVE CVE-2019-18935CVE CVE-2022-30525CVE CVE-2023-1389CVE CVE-2024-21887Data type Credentials and passwordsData type Documents and filesData type Financial and payment dataData type Session cookies or tokensData type Source codeEvidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence landscape Proof of conceptEvidence landscape Threat landscape reportEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 2024, organizations · medium confidenceExtracted metric · Financial Value $150, · medium confidenceExtracted metric · Percentage 0.9% · medium confidenceExtracted metric · Percentage 1.2% · medium confidenceExtracted metric · Percentage 1.6% · medium confidenceExtracted metric · Percentage 1% · medium confidenceExtracted metric · Percentage 10.5% · medium confidenceExtracted metric · Percentage 10.6% · medium confidenceExtracted metric · Percentage 10% · medium confidenceExtracted metric · Percentage 11.1% · medium confidenceExtracted metric · Percentage 11.6% · medium confidenceExtracted metric · Percentage 11% · medium confidenceExtracted metric · Percentage 12.3% · medium confidenceExtracted metric · Percentage 12% · medium confidenceExtracted metric · Percentage 13% · medium confidenceExtracted metric · Percentage 14.7% · medium confidenceExtracted metric · Percentage 14% · medium confidenceExtracted metric · Percentage 16.7% · medium confidenceExtracted metric · Percentage 16.71% · medium confidenceExtracted metric · Percentage 16% · medium confidenceExtracted metric · Percentage 17% · medium confidenceExtracted metric · Percentage 18.4% · medium confidenceExtracted metric · Percentage 18% · medium confidenceExtracted metric · Percentage 19% · medium confidenceExtracted metric · Percentage 2.1% · medium confidenceExtracted metric · Percentage 2.5% · medium confidenceExtracted metric · Percentage 20.2% · medium confidenceExtracted metric · Percentage 20% · medium confidenceExtracted metric · Percentage 21% · medium confidenceExtracted metric · Percentage 25.3% · medium confidenceExtracted metric · Percentage 26.3% · medium confidenceExtracted metric · Percentage 26.7% · medium confidenceExtracted metric · Percentage 26% · medium confidenceExtracted metric · Percentage 27% · medium confidenceExtracted metric · Percentage 3.2% · medium confidenceExtracted metric · Percentage 3.3% · medium confidenceExtracted metric · Percentage 3.5% · medium confidenceExtracted metric · Percentage 30% · medium confidenceExtracted metric · Percentage 32% · medium confidenceExtracted metric · Percentage 37% · medium confidenceExtracted metric · Percentage 39% · medium confidenceExtracted metric · Percentage 4% · medium confidenceExtracted metric · Percentage 42.4% · medium confidenceExtracted metric · Percentage 42% · medium confidenceExtracted metric · Percentage 49% · medium confidenceExtracted metric · Percentage 5% · medium confidenceExtracted metric · Percentage 50% · medium confidenceExtracted metric · Percentage 500% · medium confidenceExtracted metric · Percentage 55% · medium confidenceExtracted metric · Percentage 6.1% · medium confidenceExtracted metric · Percentage 6.8% · medium confidenceExtracted metric · Percentage 6% · medium confidenceExtracted metric · Percentage 60% · medium confidenceExtracted metric · Percentage 61% · medium confidenceExtracted metric · Percentage 7.9% · medium confidenceExtracted metric · Percentage 70% · medium confidenceExtracted metric · Percentage 8.4% · medium confidenceExtracted metric · Percentage 8% · medium confidenceExtracted metric · Percentage 88% · medium confidenceExtracted metric · Percentage 9% · medium confidenceImpact Credential compromiseImpact Data theft or exfiltrationImpact EspionageImpact Financial fraudImpact Ransomware or extortionImpact Service disruptionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure CloudInfrastructure EmailInfrastructure EndpointInfrastructure Messaging platformKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationKill Chain phase ReconnaissanceLLM model ChatGPTLLM provider OpenAIMalicious AI tool FraudGPTMalicious AI tool WormGPTMalware or tool Cobalt StrikeMalware or tool LockBit ransomwareMalware or tool VidarMITRE ATT&CK ID T1059MITRE ATT&CK ID T1078MITRE ATT&CK ID T1102MITRE ATT&CK ID T1190MITRE ATT&CK ID T1496MITRE ATT&CK ID T1556.004MITRE tactic CollectionMITRE tactic Command and ControlMITRE tactic Credential AccessMITRE tactic Defense EvasionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic Lateral MovementMITRE tactic PersistenceMITRE tactic Privilege EscalationMITRE tactic ReconnaissancePublication date method Publisher Verified OverridePublication date precision DayPublisher FortinetPublisher domain filestore.fortinet.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSector Critical InfrastructureSector CryptocurrencySector Financial ServicesSector GovernmentSector TelecommunicationsSource type threat-research reportStatistical use context_or_observationTarget ExecutivesThreat group APT28 / Fancy BearThreat group APT29 / Cozy BearThreat group APT43 / KimsukyThreat group Lazarus GroupThreat group RansomHubThreat-group identifier APT28Threat-group identifier APT29Threat-group identifier APT73Threat-group identifier TA0001Threat-group identifier TA0003Threat-group identifier TA0004Threat-group identifier TA0007Threat-group identifier TA0008Threat-group identifier TA0011TTP Command and controlTTP Credential theftTTP Data exfiltrationTTP Deepfake impersonationTTP Defense evasionTTP Malware generationTTP MFA/session-token theftTTP ObfuscationTTP PowerShell executionTTP SpearphishingTTP Voice phishing / vishingYear 2025
Core research
Find related
Fortinet threat-research report covering Deepfake video or image, Malware development, and Reconnaissance and target research. Indexed with Artificial Intelligence context.
Actor motivation EspionageAI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI use case Deepfake video or imageAI use case Malware developmentAI use case Reconnaissance and target researchAttack vector Credential theftCVE CVE-2017-0147CVE CVE-2019-18935CVE CVE-2021-44228Data type Credentials and passwordsData type Session cookies or tokens
Show 63 more tags Data type Source codeEvidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence landscape Threat landscape reportEvidence quality Usable Machine ExtractionExtracted metric · Percentage 11.6% · medium confidenceExtracted metric · Percentage 16.7% · medium confidenceExtracted metric · Percentage 20% · medium confidenceExtracted metric · Percentage 25% · medium confidenceExtracted metric · Percentage 26.7% · medium confidenceExtracted metric · Percentage 42% · medium confidenceExtracted metric · Percentage 500% · medium confidenceExtracted metric · Percentage 8% · medium confidenceExtracted metric · Percentage 88% · medium confidenceImpact Credential compromiseImpact Data theft or exfiltrationImpact EspionageImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure CloudInfrastructure EmailKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationKill Chain phase ReconnaissanceKill Chain phase WeaponizationMalicious AI tool FraudGPTMalware or tool VidarMITRE tactic Command and ControlMITRE tactic Credential AccessMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic Lateral MovementMITRE tactic PersistenceMITRE tactic ReconnaissanceMITRE tactic Resource DevelopmentPublication date method MetadataPublication date precision DayPublisher FortinetPublisher domain fortinet.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSector Artificial IntelligenceSector Critical InfrastructureSource type threat-research reportStatistical use context_or_observationTarget DevelopersTarget ExecutivesTTP Command and controlTTP Credential harvestingTTP Credential theftTTP Data exfiltrationTTP Deepfake impersonationTTP Malware generationTTP MFA/session-token theftTTP PowerShell executionYear 2025
Context
Find related
Google Threat Intelligence Group / Mandiant research publication covering Agentic AI and Large language model. Indexed with Financial Services and Google context.
AI relevance adjacent_ai_securityAI technology Agentic AIAI technology Large language modelData type Credentials and passwordsData type Documents and filesEvidence inventory Contains extracted metricsEvidence landscape Controlled studyEvidence quality Usable Machine ExtractionExtracted metric · Duration Or Dwell 30 minutes · medium confidenceInclusion Context onlyInfrastructure BrowserInfrastructure Endpoint
Show 19 more tags Kill Chain phase ExploitationLLM model GeminiLLM provider GoogleMITRE tactic ExecutionMITRE tactic Initial AccessPublication date method TextPublication date precision DayPublisher Google Threat Intelligence Group / MandiantPublisher domain cloud.google.comRelevance basis requires manual relevance reviewRetrieval method DirectReview requirement Manual review requiredSector Financial ServicesSector GovernmentSector TelecommunicationsSource type research publicationStatistical use do_not_aggregateTarget DevelopersYear 2025
Core research
Find related
Anthropic provider or government report covering Identity fraud and impersonation, Influence operations, and Malware development. Indexed with Artificial Intelligence and Anthropic context.
Actor motivation Influence / information operationsAI relevance core_ai_attackAI technology Agentic AIAI technology Generative AIAI technology Large language modelAI use case Identity fraud and impersonationAI use case Influence operationsAI use case Malware developmentCountry or region United StatesData type Credentials and passwordsEvidence landscape Forecast or predictionEvidence landscape Underground-market observation
Show 26 more tags Evidence quality Usable Machine ExtractionImpact Credential compromiseInclusion Core AI-attack researchInfrastructure BrowserInfrastructure Messaging platformInfrastructure Social mediaKill Chain phase Actions on ObjectivesLLM model ClaudeLLM provider AnthropicMITRE tactic Resource DevelopmentPublication date method Publisher Verified OverridePublication date precision DayPublisher AnthropicPublisher domain anthropic.comRelevance basis AI misuse, abuse-disruption, or threat research reportRetrieval method DirectReview requirement Manual review requiredSector Artificial IntelligenceSector Financial ServicesSector GovernmentSource type provider or government reportStatistical use incident_or_observationTarget Consumers or individualsTarget DevelopersTTP Malware generationYear 2025
Core research
Find related
Sophos threat-research report covering Obfuscation and evasion, Business email compromise, and Command and control. Indexed with Akira, Cryptocurrency, and OpenAI context.
Actor motivation FinancialActor motivation HacktivismAI relevance core_ai_attackAI technology Generative AIAI technology Large language modelAI use case Obfuscation and evasionAttack vector Business email compromiseAttack vector Credential theftAttack vector Malicious advertisementAttack vector VishingCVE CVE-2021-34473CVE CVE-2023-27532
Show 86 more tags CVE CVE-2023-3519CVE CVE-2023-48788CVE CVE-2023-4966CVE CVE-2024-1709CVE CVE-2024-21762CVE CVE-2024-27198CVE CVE-2024-3400CVE CVE-2024-37085CVE CVE-2024-4071CVE CVE-2024-40711Data type Credentials and passwordsData type Documents and filesData type Session cookies or tokensEvidence inventory Contains extracted metricsEvidence landscape Incident responseEvidence landscape Threat landscape reportEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 365 account · medium confidenceExtracted metric · Financial Value $375. · medium confidenceExtracted metric · Percentage 0.21% · medium confidenceExtracted metric · Percentage 0.43% · medium confidenceExtracted metric · Percentage 0.64% · medium confidenceExtracted metric · Percentage 0.85% · medium confidenceExtracted metric · Percentage 1.28% · medium confidenceExtracted metric · Percentage 14.53% · medium confidenceExtracted metric · Percentage 2.35% · medium confidenceExtracted metric · Percentage 2.78% · medium confidenceExtracted metric · Percentage 4.70% · medium confidenceImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure EndpointInfrastructure Messaging platformInfrastructure Social mediaKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationLLM model ChatGPTLLM provider OpenAIMalware or tool Cobalt StrikeMalware or tool DanaBotMalware or tool LummaMalware or tool MimikatzMalware or tool RansomHub ransomwareMalware or tool SystemBC malwareMITRE tactic CollectionMITRE tactic Command and ControlMITRE tactic Credential AccessMITRE tactic Defense EvasionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic Lateral MovementMITRE tactic PersistencePublication date method MetadataPublication date precision DayPublisher SophosPublisher domain sophos.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method Jina Reader ProxyReview requirement Manual review requiredSector CryptocurrencySource type threat-research reportStatistical use context_or_observationTarget DevelopersTarget EmployeesTarget ExecutivesThreat group AkiraThreat group RansomHubTTP Business email compromiseTTP Command and controlTTP Credential theftTTP Data exfiltrationTTP Defense evasionTTP Malicious advertisingTTP MFA/session-token theftTTP ObfuscationTTP Phishing link or attachmentTTP Voice phishing / vishingYear 2025
Core research
Find related
SentinelOne operational CTI publication covering CAPTCHA bypass, Malicious advertising, and Large language model. Indexed with Akira, Financial Services, and OpenAI context.
Actor motivation HacktivismAI relevance core_ai_attackAI technology Large language modelAI use case CAPTCHA bypassAttack vector Credential theftAttack vector Malicious advertisementCountry or region GermanyCountry or region IranCountry or region RussiaData type Credentials and passwordsData type Documents and filesEvidence inventory Contains extracted IOCs
Show 106 more tags Evidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 11,000 domains · medium confidenceExtracted metric · Blast Radius at least 80,000 websites · medium confidenceExtracted metric · Blast Radius more than 400,000 websites · medium confidenceExtracted metric · Duration Or Dwell 17 years · medium confidenceExtracted metric · Duration Or Dwell 4 years · medium confidenceExtracted metric · Duration Or Dwell 5 days · medium confidenceImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure Messaging platformIOC · Defanged Domain akirateam[.]comIOC · Defanged Domain bodis[.]comIOC · Defanged Domain firstpageprofs[.]comIOC · Defanged Domain getkira[.]infoIOC · Defanged Domain go-servicewrap[.]comIOC · Defanged Domain gogoservicewrap[.]comIOC · Defanged Domain goservicewrap[.]comIOC · Defanged Domain joinnowkira[.]orgIOC · Defanged Domain joinservicewrap[.]comIOC · Defanged Domain joinuseakira[.]comIOC · Defanged Domain kiraone[.]infoIOC · Defanged Domain letsgetcustomers[.]comIOC · Defanged Domain loveservice-wrap[.]comIOC · Defanged Domain mybkira[.]infoIOC · Defanged Domain onlyforyoursite[.]comIOC · Defanged Domain searchengineboosters[.]comIOC · Defanged Domain service-wrap[.]comIOC · Defanged Domain servicewrap-go[.]comIOC · Defanged Domain servicewrapgo[.]comIOC · Defanged Domain servicewrapone[.]comIOC · Defanged Domain theakirateam[.]comIOC · Defanged Domain topservicewrap[.]comIOC · Defanged Domain useakira[.]comIOC · Defanged Domain usekiara[.]comIOC · Defanged Domain useproakira[.]comIOC · Defanged Domain usethatakira[.]comIOC · Defanged Domain wantkiara[.]infoIOC · Defanged Domain wearetherealpros[.]comIOC · Sha1 09ec44b6d3555a0397142b4308825483b479bf5aIOC · Sha1 0de065d58b367ffb28ce53bc1dc023f95a6d0b89IOC · Sha1 13de9fcd4e7c36d32594924975b7ef2b91614556IOC · Sha1 2322964ea57312747ae9d1e918811201a0c86e9cIOC · Sha1 253684ea43cb0456a6fec5728e1091ff8fcb27cfIOC · Sha1 36b4e424ce8082d7606bb9f677f97c0f594f254dIOC · Sha1 3a443c72995254400da30fe203f3fbf287629969IOC · Sha1 3a7cc815b921166006f31c1065dadfeb8d5190e6IOC · Sha1 4d24dd5c166fa471554ed781180e353e6b9642b7IOC · Sha1 51ec20e5356bbebd43c03faae56fca4c3bbe318eIOC · Sha1 55affc664472c4657c8534e0508636394eac8828IOC · Sha1 5620b527dfc71e2ee7efb2e22a0441b60fd67b84IOC · Sha1 5fde3180373c420cfa5cfdea7f227a1e1fe6936cIOC · Sha1 62e66bae4b892593009d5261d898356b6d0be3efIOC · Sha1 6b65c296d9e1cda5af2f7dab94ce8e163b2a4ca8IOC · Sha1 6c56b986893dd1de83151510f4b6260613c5fbb9IOC · Sha1 6f342ff77cd43921210d144a403b8abb1e541a8bIOC · Sha1 7129194c63ae262c814da8045879aed7a037f196IOC · Sha1 71464c4f145c9a43ade999d385a9260aabcbf66dIOC · Sha1 730192b0f62e37d4d57bae9ff14ec8671fbf051eIOC · Sha1 769aa6ab69154ca87ccba0535e0180a985c21a0cIOC · Sha1 76aab3ab0f3f16cf30d7913ff767f67a116ff1e7IOC · Sha1 853fde052316be7887474996538b31f6ac0c3963IOC · Sha1 9d43494c6f87414c67533cce5ec86754311631fcIOC · Sha1 9f6ed2427e959e92eb1699024f457d87fa7b5279IOC · Sha1 aa72065673dc543e6bf627c7479bfe8a5e42a9c4IOC · Sha1 aac26242f4209bc59c82c8f223fcf2f152ce44bcIOC · Sha1 b643a1f2c4eb436db26763d5e2527f6bebe8bcbfIOC · Sha1 bbd754e36aee4702b9f20b90d509248945add4eaIOC · Sha1 cb194612ed003eaf8d8cf6ed3731f21f3edeb161IOC · Sha1 cc63ee921c29f47612096c34d6ee3ef244b33db2IOC · Sha1 e12c6911997d7c2af5550b7e989f1dc57b6733b8IOC · Sha1 eae675812c4274502051d6f2d36348f77a8464a0IOC · Sha1 f1c7c5d0870fd0abb7e419f2c2ba8df42fa74667IOC · Sha1 f2e71c9cbc4a18482a11ca3f54f2c958973360b4IOC · Sha1 fb7fdcc2fe11e95065a0ce9041348984427ca0f4Kill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryLLM model GPT-4LLM provider OpenAIMalware or tool AkiraBotMalware or tool BlackBasta ransomwareMITRE tactic CollectionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ImpactPublication date method MetadataPublication date precision DayPublisher SentinelOnePublisher domain sentinelone.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector Financial ServicesSector TelecommunicationsSource type operational CTI publicationStatistical use incident_or_observationTarget DevelopersTarget ExecutivesThreat group AkiraTTP CAPTCHA bypassTTP Malicious advertisingYear 2025
Core research
Find related
IBM X-Force threat-research report covering Malware development, Obfuscation and evasion, and Phishing and lure generation. Indexed with Hospitality context.
AI relevance core_ai_attackAI technology Generative AIAI technology Large language modelAI use case Malware developmentAI use case Obfuscation and evasionAI use case Phishing and lure generationAI use case Translation and localizationCampaign Operation EndgameCountry or region RussiaData type Credentials and passwordsData type Documents and filesData type Financial and payment data
Show 53 more tags Evidence inventory Contains extracted IOCsEvidence inventory Contains extracted metricsEvidence landscape Controlled studyEvidence landscape Forecast or predictionEvidence landscape Incident responseEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 2023 campaign · medium confidenceExtracted metric · Blast Radius 2024 campaign · medium confidenceExtracted metric · Blast Radius 26 campaign · medium confidenceImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure EmailIOC · Defanged Domain bien-fait[.]netIOC · Defanged Domain continentalgames[.]topIOC · Defanged Domain narkology[.]topIOC · Defanged Domain newsferinfo[.]comIOC · Defanged Domain raw[.]githubusercontent[.]comIOC · Md5 473c0737f6125ad0dff41521ab1e6331IOC · Md5 cd457c3253556b2bce4482ebf86e829bIOC · Sha256 86ea22f95841f79ff10391858c1f38f8a694adf625a5d7cc49e47903c55dc8a8Kill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase InstallationMalware or tool BlackBasta ransomwareMalware or tool DarkGateMalware or tool NetSupportMalware or tool NetSupport RATMITRE tactic CollectionMITRE tactic Command and ControlMITRE tactic Defense EvasionMITRE tactic ExecutionMITRE tactic ImpactMITRE tactic Initial AccessPublication date method MetadataPublication date precision DayPublisher IBM X-ForcePublisher domain ibm.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSector HospitalitySource type threat-research reportStatistical use context_or_observationTarget ExecutivesThreat-group identifier TA571Threat-group identifier TA577TTP Command and controlTTP MFA/session-token theftTTP ObfuscationTTP Phishing link or attachmentTTP PowerShell executionYear 2025
Core research
Find related
IBM X-Force threat-research report covering Credential theft and Generative AI.
AI relevance core_ai_attackAI technology Generative AIData type Credentials and passwordsData type Documents and filesEvidence inventory Contains extracted metricsEvidence landscape Incident responseEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionExtracted metric · Percentage 100% · medium confidenceExtracted metric · Percentage 11.5% · medium confidenceExtracted metric · Percentage 20% · medium confidenceExtracted metric · Percentage 266% · medium confidence
Show 31 more tags Extracted metric · Percentage 3% · medium confidenceExtracted metric · Percentage 30% · medium confidenceExtracted metric · Percentage 44% · medium confidenceExtracted metric · Percentage 50% · medium confidenceExtracted metric · Percentage 56% · medium confidenceExtracted metric · Percentage 71% · medium confidenceExtracted metric · Percentage 72% · medium confidenceImpact Credential compromiseImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationMalware or tool CL0P ransomwareMITRE tactic DiscoveryMITRE tactic ImpactMITRE tactic Initial AccessPublication date method MetadataPublication date precision DayPublisher IBM X-ForcePublisher domain ibm.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSource type threat-research reportStatistical use context_or_observationTarget ExecutivesTTP Credential theftYear 2025
Core research
Find related
Cisco Talos operational CTI publication covering CAPTCHA bypass, Code debugging and scripting, and Deepfake video or image. Indexed with Akira and Critical Infrastructure context.
Actor motivation Disruption / destructionActor motivation FinancialAI relevance core_ai_attackAI technology Agentic AIAI technology Deepfake / synthetic mediaAI technology Generative AIAI technology Large language modelAI use case CAPTCHA bypassAI use case Code debugging and scriptingAI use case Deepfake video or imageAI use case Identity fraud and impersonationAI use case Malware development
Show 171 more tags AI use case Obfuscation and evasionAI use case Reconnaissance and target researchAI use case Vulnerability researchAttack vector Business email compromiseAttack vector Credential theftAttack vector VishingCampaign Operation CronosCountry or region North KoreaCountry or region RussiaCountry or region UkraineCountry or region United StatesCVE CVE-2014-0160CVE CVE-2014-6271CVE CVE-2014-6277CVE CVE-2014-6278CVE CVE-2014-7169CVE CVE-2017-9841CVE CVE-2021-44228CVE CVE-2021-44529CVE CVE-2021-44832CVE CVE-2021-45046CVE CVE-2021-45105CVE CVE-2022-20933CVE CVE-2023-1389CVE CVE-2023-36845CVE CVE-2023-38035CVE CVE-2023-42793CVE CVE-2024-0012CVE CVE-2024-24919CVE CVE-2024-3272CVE CVE-2024-3273CVE CVE-2024-3400CVE CVE-2024-36401CVE CVE-2024-4577Data type Credentials and passwordsData type Documents and filesData type Financial and payment dataData type Personally identifiable informationData type Session cookies or tokensData type Source codeEvidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence landscape Incident responseEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 193 countries · medium confidenceExtracted metric · Blast Radius 2024 systems · medium confidenceExtracted metric · Blast Radius 499 users · medium confidenceExtracted metric · Blast Radius 5 Email · medium confidenceExtracted metric · Blast Radius 50 users · medium confidenceExtracted metric · Blast Radius more than 100,000 users · medium confidenceExtracted metric · Duration Or Dwell 2024 YEAR · medium confidenceExtracted metric · Financial Value $15 · medium confidenceExtracted metric · Percentage 1% · medium confidenceExtracted metric · Percentage 10% · medium confidenceExtracted metric · Percentage 11% · medium confidenceExtracted metric · Percentage 12% · medium confidenceExtracted metric · Percentage 14% · medium confidenceExtracted metric · Percentage 16% · medium confidenceExtracted metric · Percentage 17% · medium confidenceExtracted metric · Percentage 18% · medium confidenceExtracted metric · Percentage 19% · medium confidenceExtracted metric · Percentage 2% · medium confidenceExtracted metric · Percentage 20% · medium confidenceExtracted metric · Percentage 22 % · medium confidenceExtracted metric · Percentage 24% · medium confidenceExtracted metric · Percentage 25% · medium confidenceExtracted metric · Percentage 26% · medium confidenceExtracted metric · Percentage 3% · medium confidenceExtracted metric · Percentage 31% · medium confidenceExtracted metric · Percentage 32% · medium confidenceExtracted metric · Percentage 36% · medium confidenceExtracted metric · Percentage 4% · medium confidenceExtracted metric · Percentage 44% · medium confidenceExtracted metric · Percentage 48% · medium confidenceExtracted metric · Percentage 5% · medium confidenceExtracted metric · Percentage 50% · medium confidenceExtracted metric · Percentage 53% · medium confidenceExtracted metric · Percentage 57% · medium confidenceExtracted metric · Percentage 58% · medium confidenceExtracted metric · Percentage 6% · medium confidenceExtracted metric · Percentage 60% · medium confidenceExtracted metric · Percentage 69% · medium confidenceExtracted metric · Percentage 7% · medium confidenceExtracted metric · Percentage 70% · medium confidenceExtracted metric · Percentage 8.5% · medium confidenceExtracted metric · Percentage 8% · medium confidenceExtracted metric · Percentage 9% · medium confidenceImpact Credential compromiseImpact Data theft or exfiltrationImpact Financial fraudImpact Ransomware or extortionImpact Service disruptionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure CloudInfrastructure EmailInfrastructure EndpointInfrastructure Messaging platformInfrastructure Social mediaKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationKill Chain phase ReconnaissanceKill Chain phase WeaponizationMalware or tool BianLian ransomwareMalware or tool BlackBasta ransomwareMalware or tool Cobalt StrikeMalware or tool LockBit ransomwareMalware or tool MimikatzMITRE tactic Command and ControlMITRE tactic Credential AccessMITRE tactic Defense EvasionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic Lateral MovementMITRE tactic PersistenceMITRE tactic Privilege EscalationMITRE tactic ReconnaissanceMITRE tactic Resource DevelopmentPublication date method Publisher Verified OverridePublication date precision DayPublisher Cisco TalosPublisher domain blog.talosintelligence.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector Critical InfrastructureSector EducationSector Financial ServicesSector GovernmentSector Legal ServicesSector ManufacturingSector Nonprofit / NGOSector TelecommunicationsSector Transportation and LogisticsSource type operational CTI publicationStatistical use incident_or_observationTarget DevelopersTarget EmployeesThreat group AkiraThreat group APT28 / Fancy BearThreat group APT29 / Cozy BearThreat group Black BastaThreat group Lazarus GroupThreat group RansomHubThreat group Scattered SpiderThreat-group identifier APT28Threat-group identifier APT29TTP Business email compromiseTTP CAPTCHA bypassTTP Command and controlTTP Credential theftTTP Data exfiltrationTTP Deepfake impersonationTTP Defense evasionTTP Malware generationTTP MFA/session-token theftTTP Password sprayingTTP Phishing link or attachmentTTP PowerShell executionTTP Ransomware deploymentTTP Target research / OSINTTTP Voice phishing / vishingTTP Vulnerability scanningYear 2025
Core research
Find related
KELA threat-research report covering Deepfake video or image, Deepfake voice, and Exploit development. Indexed with Storm-2139, Financial Services, and Anthropic context.
Actor motivation FinancialActor motivation HacktivismActor motivation Influence / information operationsAI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI technology Generative AIAI technology Large language modelAI use case Deepfake video or imageAI use case Deepfake voiceAI use case Exploit developmentAI use case Identity fraud and impersonationAI use case Influence operations
Show 92 more tags AI use case Malware developmentAI use case Phishing and lure generationAI use case Reconnaissance and target researchAI use case Translation and localizationAI use case Vulnerability researchAttack vector Business email compromiseAttack vector VishingCompanion source src-080Country or region ChinaCountry or region FranceCountry or region GermanyCountry or region IranCountry or region North KoreaCountry or region RussiaCountry or region UkraineCountry or region United StatesCVE CVE-2025-24367Data type Credentials and passwordsData type Documents and filesData type Financial and payment dataDuplicate lineage dup-003Evidence inventory Contains extracted metricsEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionExtracted metric · Percentage 100% · medium confidenceExtracted metric · Percentage 200% · medium confidenceExtracted metric · Percentage 219% · medium confidenceExtracted metric · Percentage 51% · medium confidenceExtracted metric · Percentage 52% · medium confidenceExtracted metric · Percentage 95% · medium confidenceImpact Data theft or exfiltrationImpact Financial fraudImpact Ransomware or extortionImpact Service disruptionInclusion Core AI-attack researchInfrastructure EmailInfrastructure Messaging platformInfrastructure MobileInfrastructure Social mediaKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase ReconnaissanceKill Chain phase WeaponizationLLM model ChatGPTLLM model ClaudeLLM model DeepSeekLLM model GeminiLLM model GPT-4LLM model Mistral / MixtralLLM provider AnthropicLLM provider DeepSeekLLM provider GoogleLLM provider Mistral AILLM provider OpenAIMalicious AI tool Evil-GPTMalicious AI tool FraudGPTMalicious AI tool GhostGPTMalicious AI tool WormGPTMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic ReconnaissanceMITRE tactic Resource DevelopmentPublication date method Publisher Verified OverridePublication date precision DayPublisher KELAPublisher domain info.ke-la.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSector Financial ServicesSector GovernmentSource type threat-research reportStatistical use context_or_observationTarget DevelopersTarget EmployeesTarget ExecutivesThreat group Storm-2139Threat-group identifier STORM-2139Threat-group identifier UNC6780TTP Business email compromiseTTP Data exfiltrationTTP Deepfake impersonationTTP Exploit developmentTTP Malware generationTTP Phishing link or attachmentTTP Prompt injectionTTP Target research / OSINTTTP Voice phishing / vishingYear 2025
Core research
Find related
Zscaler ThreatLabz threat-research report covering Autonomous or agentic intrusion, Deepfake video or image, and Deepfake voice. Indexed with Artificial Intelligence and Anthropic context.
AI relevance core_ai_attackAI technology Agentic AIAI technology Deepfake / synthetic mediaAI technology Generative AIAI technology Large language modelAI technology Speech or voice synthesisAI use case Autonomous or agentic intrusionAI use case Deepfake video or imageAI use case Deepfake voiceAI use case Identity fraud and impersonationAI use case Obfuscation and evasionAI use case Phishing and lure generation
Show 178 more tags AI use case Reconnaissance and target researchAI use case Translation and localizationAttack vector Credential theftAttack vector VishingCountry or region AfricaCountry or region BrazilCountry or region CanadaCountry or region ChinaCountry or region European UnionCountry or region FranceCountry or region GermanyCountry or region IndiaCountry or region JapanCountry or region South KoreaCountry or region United KingdomCountry or region United StatesData type Credentials and passwordsData type Documents and filesData type Personally identifiable informationData type Source codeEvidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence landscape In-the-wild observedEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 317,583,902 User · medium confidenceExtracted metric · Blast Radius 5 countries · medium confidenceExtracted metric · Financial Value $0.55 · medium confidenceExtracted metric · Financial Value $1 billion · medium confidenceExtracted metric · Percentage 0.3% · medium confidenceExtracted metric · Percentage 1.1% · medium confidenceExtracted metric · Percentage 1.2% · medium confidenceExtracted metric · Percentage 1.3% · medium confidenceExtracted metric · Percentage 1.4% · medium confidenceExtracted metric · Percentage 1.6% · medium confidenceExtracted metric · Percentage 1.7% · medium confidenceExtracted metric · Percentage 1.8% · medium confidenceExtracted metric · Percentage 1% · medium confidenceExtracted metric · Percentage 10.1% · medium confidenceExtracted metric · Percentage 10.8% · medium confidenceExtracted metric · Percentage 11.3% · medium confidenceExtracted metric · Percentage 11.4% · medium confidenceExtracted metric · Percentage 11.5% · medium confidenceExtracted metric · Percentage 12.2% · medium confidenceExtracted metric · Percentage 12.4% · medium confidenceExtracted metric · Percentage 12.5% · medium confidenceExtracted metric · Percentage 12.7 % · medium confidenceExtracted metric · Percentage 13.6 % · medium confidenceExtracted metric · Percentage 15.0% · medium confidenceExtracted metric · Percentage 15.2% · medium confidenceExtracted metric · Percentage 15% · medium confidenceExtracted metric · Percentage 17.23% · medium confidenceExtracted metric · Percentage 18.4% · medium confidenceExtracted metric · Percentage 18.5% · medium confidenceExtracted metric · Percentage 19.2% · medium confidenceExtracted metric · Percentage 2.0% · medium confidenceExtracted metric · Percentage 2.2% · medium confidenceExtracted metric · Percentage 2.3% · medium confidenceExtracted metric · Percentage 2.4% · medium confidenceExtracted metric · Percentage 2.5% · medium confidenceExtracted metric · Percentage 2.6% · medium confidenceExtracted metric · Percentage 2.9% · medium confidenceExtracted metric · Percentage 20% · medium confidenceExtracted metric · Percentage 21.0% · medium confidenceExtracted metric · Percentage 21.6% · medium confidenceExtracted metric · Percentage 22.3% · medium confidenceExtracted metric · Percentage 24.8% · medium confidenceExtracted metric · Percentage 27.1% · medium confidenceExtracted metric · Percentage 28.3% · medium confidenceExtracted metric · Percentage 28.4% · medium confidenceExtracted metric · Percentage 29.1% · medium confidenceExtracted metric · Percentage 3.0% · medium confidenceExtracted metric · Percentage 3.1% · medium confidenceExtracted metric · Percentage 3.2% · medium confidenceExtracted metric · Percentage 3.3% · medium confidenceExtracted metric · Percentage 3.4% · medium confidenceExtracted metric · Percentage 3.6% · medium confidenceExtracted metric · Percentage 3.9% · medium confidenceExtracted metric · Percentage 36.4% · medium confidenceExtracted metric · Percentage 36% · medium confidenceExtracted metric · Percentage 39.5% · medium confidenceExtracted metric · Percentage 4.1% · medium confidenceExtracted metric · Percentage 4.2% · medium confidenceExtracted metric · Percentage 4.4% · medium confidenceExtracted metric · Percentage 4.5% · medium confidenceExtracted metric · Percentage 4.6% · medium confidenceExtracted metric · Percentage 40.9% · medium confidenceExtracted metric · Percentage 41.5% · medium confidenceExtracted metric · Percentage 45.2% · medium confidenceExtracted metric · Percentage 46.2% · medium confidenceExtracted metric · Percentage 46.9% · medium confidenceExtracted metric · Percentage 464.6% · medium confidenceExtracted metric · Percentage 5.1% · medium confidenceExtracted metric · Percentage 5.6% · medium confidenceExtracted metric · Percentage 5.7% · medium confidenceExtracted metric · Percentage 5.74% · medium confidenceExtracted metric · Percentage 5.8% · medium confidenceExtracted metric · Percentage 53.1% · medium confidenceExtracted metric · Percentage 54% · medium confidenceExtracted metric · Percentage 59.9% · medium confidenceExtracted metric · Percentage 6.0% · medium confidenceExtracted metric · Percentage 6.4% · medium confidenceExtracted metric · Percentage 6.5% · medium confidenceExtracted metric · Percentage 6.9% · medium confidenceExtracted metric · Percentage 60.4% · medium confidenceExtracted metric · Percentage 68% · medium confidenceExtracted metric · Percentage 8.7 % · medium confidenceExtracted metric · Percentage 9.6% · medium confidenceExtracted metric · Percentage 90% · medium confidenceImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure EndpointInfrastructure Messaging platformInfrastructure MobileInfrastructure Social mediaKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationKill Chain phase ReconnaissanceLLM model ChatGPTLLM model ClaudeLLM model DeepSeekLLM model GeminiLLM model GPT-4LLM model GrokLLM model Microsoft CopilotLLM model Mistral / MixtralLLM provider AnthropicLLM provider DeepSeekLLM provider GoogleLLM provider MicrosoftLLM provider Mistral AILLM provider OpenAILLM provider xAIMalware or tool RhadamanthysMITRE tactic Command and ControlMITRE tactic Credential AccessMITRE tactic Defense EvasionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic Lateral MovementMITRE tactic Privilege EscalationMITRE tactic ReconnaissancePublication date method Publisher Verified OverridePublication date precision DayPublisher Zscaler ThreatLabzPublisher domain zscaler.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSector Artificial IntelligenceSector Financial ServicesSector GovernmentSector HealthcareSector Transportation and LogisticsSource type threat-research reportStatistical use context_or_observationTarget DevelopersTarget EmployeesTarget ExecutivesTTP Command and controlTTP Credential theftTTP Data exfiltrationTTP Deepfake impersonationTTP Defense evasionTTP Phishing link or attachmentTTP PowerShell executionTTP Prompt injectionTTP Voice phishing / vishingYear 2025
Core research
Find related
ThreatDown / Malwarebytes threat-research report covering Malicious advertising, Agentic AI, and Generative AI. Indexed with Healthcare and OpenAI context.
AI relevance core_ai_attackAI technology Agentic AIAI technology Generative AIAttack vector Malicious advertisementEvidence inventory Contains extracted metricsEvidence quality Usable Machine ExtractionExtracted metric · Duration Or Dwell 1 minute · medium confidenceExtracted metric · Duration Or Dwell 12 minutes · medium confidenceExtracted metric · Duration Or Dwell 12 months · medium confidenceExtracted metric · Financial Value $75 million · medium confidenceExtracted metric · Percentage 13% · medium confidenceExtracted metric · Percentage 70% · medium confidence
Show 27 more tags Impact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure EndpointInfrastructure MobileKill Chain phase Actions on ObjectivesKill Chain phase DeliveryLLM model GrokLLM provider OpenAILLM provider xAIMalware or tool AMOSMITRE tactic ImpactMITRE tactic Initial AccessPublication date method Publisher Verified OverridePublication date precision DayPublisher ThreatDown / MalwarebytesPublisher domain threatdown.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSector HealthcareSource type threat-research reportStatistical use context_or_observationTarget ExecutivesTTP Malicious advertisingYear 2025
Core research
Find related
arXiv academic or empirical research covering Deepfake video or image, Deepfake impersonation, and Spearphishing. Indexed with Hugging Face context.
AI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI use case Deepfake video or imageAttack vector SpearphishingEvidence inventory Contains extracted metricsEvidence landscape Controlled studyEvidence quality Usable Machine ExtractionExtracted metric · Percentage 43% · medium confidenceExtracted metric · Percentage 66% · medium confidenceInclusion Core AI-attack researchInfrastructure EmailLLM provider Hugging Face
Show 12 more tags Publication date method Arxiv Id MonthPublication date precision MonthPublisher arXivPublisher domain arxiv.orgRelevance basis ai-cyber research or controlled studyRetrieval method DirectReview requirement Manual review requiredSource type academic or empirical researchStatistical use possible_denominatorTTP Deepfake impersonationTTP SpearphishingYear 2025
Core research
Find related
Google Threat Intelligence Group / Mandiant operational CTI publication covering Deepfake video or image, Identity fraud and impersonation, and Malware development. Indexed with APT41, Cryptocurrency, and Google context.
Actor motivation EspionageActor motivation FinancialActor motivation Influence / information operationsAI relevance core_ai_attackAI technology Agentic AIAI technology Generative AIAI technology Large language modelAI use case Deepfake video or imageAI use case Identity fraud and impersonationAI use case Malware developmentAI use case Obfuscation and evasionAI use case Reconnaissance and target research
Show 99 more tags AI use case Translation and localizationAI use case Vulnerability researchAttack vector Business email compromiseAttack vector Supply chainAttack vector VishingCountry or region ChinaCountry or region FranceCountry or region GermanyCountry or region IranCountry or region IsraelCountry or region North KoreaCountry or region RussiaCountry or region South KoreaCountry or region TaiwanCountry or region UkraineCountry or region United StatesData type Credentials and passwordsData type Documents and filesData type Source codeEvidence inventory Contains extracted metricsEvidence landscape In-the-wild observedEvidence landscape Proof of conceptEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 13 countries · medium confidenceExtracted metric · Blast Radius more than 20 countries · medium confidenceExtracted metric · Percentage 30% · medium confidenceExtracted metric · Percentage 40% · medium confidenceImpact Data theft or exfiltrationImpact EspionageImpact Ransomware or extortionImpact Service disruptionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure EndpointInfrastructure Messaging platformInfrastructure MobileInfrastructure Social mediaKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase ReconnaissanceKill Chain phase WeaponizationLLM model GeminiLLM provider GoogleMalicious AI tool FraudGPTMalicious AI tool WormGPTMalware or tool Cobalt StrikeMalware or tool MimikatzMITRE tactic CollectionMITRE tactic Command and ControlMITRE tactic Defense EvasionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic Lateral MovementMITRE tactic Privilege EscalationMITRE tactic ReconnaissanceMITRE tactic Resource DevelopmentPublication date method TextPublication date precision DayPublisher Google Threat Intelligence Group / MandiantPublisher domain cloud.google.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector CryptocurrencySector DefenseSector EducationSector Financial ServicesSector GovernmentSector TelecommunicationsSource type operational CTI publicationStatistical use incident_or_observationTarget DevelopersTarget EmployeesTarget ExecutivesThreat group APT41Threat group APT42 / Charming KittenThreat group APT43 / KimsukyThreat-group identifier APT41Threat-group identifier APT42Threat-group identifier APT43Threat-group identifier UNC6671TTP Business email compromiseTTP Command and controlTTP Data exfiltrationTTP Defense evasionTTP Malware generationTTP PowerShell executionTTP Prompt injectionTTP Supply-chain compromiseTTP Target research / OSINTTTP Voice phishing / vishingYear 2025
Core research
Find related
Check Point provider or government report covering Identity fraud and impersonation, Malware development, and Malware generation. Indexed with Akira and OpenAI context.
Actor motivation HacktivismAI relevance core_ai_attackAI technology Large language modelAI use case Identity fraud and impersonationAI use case Malware developmentCountry or region AfricaCountry or region BrazilCountry or region CanadaCountry or region ChinaCountry or region FranceCountry or region GermanyCountry or region India
Show 68 more tags Country or region IranCountry or region IsraelCountry or region JapanCountry or region North KoreaCountry or region RussiaCountry or region South KoreaCountry or region TaiwanCountry or region UkraineCountry or region United KingdomCountry or region United StatesCountry or region VietnamData type Credentials and passwordsData type Documents and filesData type Source codeEvidence inventory Contains extracted IOCsEvidence inventory Contains extracted metricsEvidence landscape Controlled studyEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius over 85 victims · medium confidenceExtracted metric · Financial Value $10,000, · medium confidenceImpact Data theft or exfiltrationImpact Ransomware or extortionImpact Service disruptionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure EndpointInfrastructure Messaging platformInfrastructure MobileIOC · Sha256 20ed21bfdb7aa970b12e7368eba8e26a711752f1cc5416b6fd6629d0e2a44e5dIOC · Sha256 5226ea8e0f516565ba825a1bbed10020982c16414750237068b602c5b4ac6abdIOC · Sha256 66dbf939c00b09d8d22c692864b68c4a602e7a59c4b925b2e2bef57b1ad047bdIOC · Sha256 7e223a685d5324491bcacf3127869f9f3ec5d5100c5e7cb5af45a227e6ab4603IOC · Sha256 b1ef7b267d887e34bf0242a94b38e7dc9fd5e6f8b2c5c440ce4ec98cc74642fbIOC · Sha256 c233aec7917cf34294c19dd60ff79a6e0fac5ed6f0cb57af98013c08201a7a1cIOC · Sha256 dcf536edd67a98868759f4e72bcbd1f4404c70048a2a3257e77d8af06cb036acIOC · Sha256 dd15ce869aa79884753e3baad19b0437075202be86268b84f3ec2303e1ecd966IOC · Sha256 e622f3b743c7fc0a011b07a2e656aa2b5e50a4876721bcf1f405d582ca4cda22Kill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase WeaponizationLLM model ChatGPTLLM provider OpenAIMalware or tool FunkSecMalware or tool FunkSec ransomwareMITRE tactic CollectionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic Privilege EscalationMITRE tactic Resource DevelopmentPublication date method MetadataPublication date precision DayPublisher Check PointPublisher domain research.checkpoint.comRelevance basis AI misuse, abuse-disruption, or threat research reportRetrieval method DirectReview requirement Manual review requiredSource type provider or government reportStatistical use incident_or_observationTarget DevelopersThreat group AkiraThreat group FunkSecTTP Malware generationTTP PowerShell executionYear 2025
Core research
Find related
Recorded Future threat-research report covering Command and control.
AI relevance core_ai_attackCampaign Operation EndgameEvidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence quality Usable Machine ExtractionExtracted metric · Percentage 50% · medium confidenceInclusion Core AI-attack researchInfrastructure MobileKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase InstallationMalware or tool AsyncRAT
Show 20 more tags Malware or tool Cobalt StrikeMalware or tool LummaMalware or tool QuasarRATMalware or tool RemcosMalware or tool REMCOS RATMalware or tool VidarMITRE tactic Command and ControlMITRE tactic Initial AccessPublication date method Publisher Verified OverridePublication date precision YearPublisher Recorded FuturePublisher domain recordedfuture.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSource type threat-research reportStatistical use context_or_observationTarget ExecutivesTTP Command and controlYear 2025
Core research
Find related
CERT-EU government or law-enforcement publication covering Deepfake video or image, Voice phishing / vishing, and Deepfake / synthetic media.
Actor motivation EspionageAI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI use case Deepfake video or imageAttack vector VishingEvidence inventory Contains extracted metricsEvidence landscape Threat landscape reportEvidence quality Usable Machine ExtractionExtracted metric · Percentage 38% · medium confidenceExtracted metric · Percentage 60% · medium confidenceExtracted metric · Percentage 80% · medium confidenceImpact Espionage
Show 16 more tags Inclusion Core AI-attack researchInfrastructure BrowserKill Chain phase DeliveryKill Chain phase ExploitationMITRE tactic Initial AccessPublication date method Url Year OnlyPublication date precision YearPublisher CERT-EUPublisher domain cert.europa.euRelevance basis official advisory, fraud alert, or regional threat reportRetrieval method DirectReview requirement Manual review requiredSource type government or law-enforcement publicationStatistical use context_or_incidentTTP Voice phishing / vishingYear 2025
Core research
Find related
CrowdStrike threat-research report covering Deepfake video or image, Phishing and lure generation, and Business email compromise. Indexed with Famous Chollima and Anthropic context.
AI relevance core_ai_attackAI technology Agentic AIAI technology Deepfake / synthetic mediaAI technology Generative AIAI technology Large language modelAI use case Deepfake video or imageAI use case Phishing and lure generationAttack vector Business email compromiseAttack vector Credential theftAttack vector SpearphishingAttack vector VishingCountry or region India
Show 45 more tags Country or region North KoreaData type Credentials and passwordsEvidence inventory Contains extracted metricsEvidence landscape Controlled studyEvidence landscape Threat landscape reportEvidence quality Usable Machine ExtractionExtracted metric · Duration Or Dwell 15 days · medium confidenceExtracted metric · Financial Value $25.6 million · medium confidenceExtracted metric · Percentage 12% · medium confidenceExtracted metric · Percentage 54% · medium confidenceInclusion Core AI-attack researchInfrastructure EmailInfrastructure EndpointInfrastructure MobileInfrastructure Social mediaKill Chain phase Actions on ObjectivesKill Chain phase DeliveryLLM model ChatGPTLLM model ClaudeLLM provider AnthropicLLM provider GoogleLLM provider OpenAIMalware or tool GoldPickaxe malwareMITRE tactic Initial AccessMITRE tactic Privilege EscalationPublication date method Publisher Verified OverridePublication date precision YearPublisher CrowdStrikePublisher domain crowdstrike.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSource type threat-research reportStatistical use context_or_observationTarget DevelopersTarget EmployeesTarget ExecutivesThreat group Famous ChollimaTTP Business email compromiseTTP Credential harvestingTTP Deepfake impersonationTTP Phishing link or attachmentTTP SpearphishingTTP Voice phishing / vishingYear 2025
Core research
Find related
CrowdStrike threat-research report covering Exploit development, Vulnerability research, and Prompt injection. Indexed with Critical Infrastructure context.
AI relevance core_ai_attackAI technology Generative AIAI technology Large language modelAI use case Exploit developmentAI use case Vulnerability researchCountry or region IranCountry or region United StatesCVE CVE-2024-3400Data type Credentials and passwordsEvidence inventory Contains extracted metricsEvidence landscape Threat landscape reportEvidence quality Usable Machine Extraction
Show 25 more tags Extracted metric · Duration Or Dwell 15 days · medium confidenceImpact Data theft or exfiltrationInclusion Core AI-attack researchInfrastructure CloudInfrastructure EndpointKill Chain phase Actions on ObjectivesKill Chain phase ExploitationKill Chain phase WeaponizationMITRE tactic ExecutionPublication date method Publisher Verified OverridePublication date precision YearPublisher CrowdStrikePublisher domain crowdstrike.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSector Critical InfrastructureSector GovernmentSource type threat-research reportStatistical use context_or_observationTarget DevelopersTarget ExecutivesTTP Exploit developmentTTP Prompt injectionYear 2025
Core research
Find related
FBI IC3 government or law-enforcement publication covering Identity fraud and impersonation, Phishing link or attachment, and Spearphishing. Indexed with Cryptocurrency context.
AI relevance core_ai_attackAI technology Generative AIAI use case Identity fraud and impersonationAttack vector SpearphishingData type Credentials and passwordsData type Documents and filesEvidence quality Usable Machine ExtractionImpact Financial fraudImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure EmailInfrastructure Social media
Show 20 more tags Kill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationMITRE tactic Initial AccessPublication date method MetadataPublication date precision DayPublisher FBI IC3Publisher domain ic3.govRelevance basis official advisory, fraud alert, or regional threat reportRetrieval method DirectReview requirement Manual review requiredSector CryptocurrencySector Financial ServicesSector GovernmentSource type government or law-enforcement publicationStatistical use context_or_incidentTarget ExecutivesTTP Phishing link or attachmentTTP SpearphishingYear 2024
Core research
Find related
Fortinet forecast or strategic assessment covering Deepfake video or image, Identity fraud and impersonation, and Malware development. Indexed with APT28 / Fancy Bear and Critical Infrastructure context.
Actor motivation Disruption / destructionActor motivation FinancialAI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI technology Large language modelAI use case Deepfake video or imageAI use case Identity fraud and impersonationAI use case Malware developmentAI use case Reconnaissance and target researchAttack vector Credential theftAttack vector SpearphishingAttack vector Vishing
Show 72 more tags Country or region FranceCountry or region RussiaCountry or region United StatesData type Credentials and passwordsEvidence inventory Contains extracted metricsEvidence landscape Controlled studyEvidence landscape Forecast or predictionEvidence landscape Incident responseEvidence landscape Threat landscape reportEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionExtracted metric · Duration Or Dwell 12 months · medium confidenceExtracted metric · Duration Or Dwell 4.76 days · medium confidenceExtracted metric · Financial Value $22 Million · medium confidenceExtracted metric · Percentage 27% · medium confidenceExtracted metric · Percentage 43% · medium confidenceExtracted metric · Percentage 65% · medium confidenceExtracted metric · Percentage 78% · medium confidenceExtracted metric · Percentage 80% · medium confidenceExtracted metric · Percentage 90% · medium confidenceImpact Ransomware or extortionImpact Service disruptionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EndpointInfrastructure Social mediaKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase ReconnaissanceMalware or tool BlackSuit ransomwareMITRE tactic CollectionMITRE tactic Credential AccessMITRE tactic DiscoveryMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic ReconnaissancePublication date method Publisher Verified OverridePublication date precision DayPublisher FortinetPublisher domain fortinet.comRelevance basis threat assessment, forecast, or red-team studyRetrieval method DirectReview requirement Manual review requiredSector Critical InfrastructureSector DefenseSector EducationSector EnergySector Financial ServicesSector GovernmentSector HealthcareSector ManufacturingSector Transportation and LogisticsSource type forecast or strategic assessmentStatistical use context_onlyTarget EmployeesTarget ExecutivesThreat group APT28 / Fancy BearThreat group APT29 / Cozy BearThreat group APT41Threat group Black BastaThreat group Lazarus GroupThreat-group identifier APT28Threat-group identifier APT29Threat-group identifier APT41TTP Credential theftTTP Deepfake impersonationTTP Malware generationTTP Password sprayingTTP SpearphishingTTP Voice phishing / vishingYear 2024
Core research
Find related
Google Threat Intelligence Group / Mandiant operational CTI publication covering Reconnaissance and target research, Supply-chain compromise, and Target research / OSINT. Indexed with Financial Services and Google context.
AI relevance core_ai_attackAI technology Large language modelAI use case Reconnaissance and target researchAttack vector Supply chainAttack vector VishingCountry or region RussiaData type Credentials and passwordsData type Documents and filesData type Source codeEvidence inventory Contains extracted metricsEvidence landscape Controlled studyEvidence landscape Forecast or prediction
Show 51 more tags Evidence quality Usable Machine ExtractionExtracted metric · Blast Radius 120 users · medium confidenceExtracted metric · Blast Radius 400 systems · medium confidenceExtracted metric · Blast Radius 900 users · medium confidenceExtracted metric · Blast Radius about 900 users · medium confidenceExtracted metric · Percentage 1% · medium confidenceExtracted metric · Percentage 2% · medium confidenceExtracted metric · Percentage 21% · medium confidenceExtracted metric · Percentage 23% · medium confidenceExtracted metric · Percentage 28% · medium confidenceExtracted metric · Percentage 3% · medium confidenceExtracted metric · Percentage 30% · medium confidenceExtracted metric · Percentage 4% · medium confidenceExtracted metric · Percentage 46% · medium confidenceExtracted metric · Percentage 47% · medium confidenceExtracted metric · Percentage 49% · medium confidenceImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure EndpointInfrastructure Social mediaKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase ReconnaissanceLLM model GeminiLLM provider GoogleLLM provider OpenAIMITRE tactic Initial AccessMITRE tactic Lateral MovementMITRE tactic Privilege EscalationMITRE tactic ReconnaissancePublication date method TextPublication date precision DayPublisher Google Threat Intelligence Group / MandiantPublisher domain cloud.google.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector Financial ServicesSector GovernmentSector TelecommunicationsSource type operational CTI publicationStatistical use incident_or_observationTarget DevelopersTarget EmployeesThreat-group identifier UNC6671TTP Supply-chain compromiseTTP Target research / OSINTTTP Voice phishing / vishingYear 2024
Core research
Find related
FinCEN government or law-enforcement publication covering Deepfake video or image, Deepfake impersonation, and Deepfake / synthetic media. Indexed with Financial Services context.
AI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI technology Generative AIAI use case Deepfake video or imageCountry or region United StatesData type Documents and filesEvidence quality Usable Machine ExtractionImpact Ransomware or extortionInclusion Core AI-attack researchKill Chain phase Actions on ObjectivesKill Chain phase ExploitationMITRE tactic Impact
Show 14 more tags Publication date method MetadataPublication date precision DayPublisher FinCENPublisher domain fincen.govRelevance basis official advisory, fraud alert, or regional threat reportRetrieval method DirectReview requirement Manual review requiredSector Financial ServicesSector GovernmentSource type government or law-enforcement publicationStatistical use context_or_incidentTarget Consumers or individualsTTP Deepfake impersonationYear 2024
Core research
Find related
OpenAI operational CTI publication covering Influence operations. Indexed with OpenAI context.
Actor motivation Influence / information operationsAI relevance core_ai_attackAI use case Influence operationsEvidence quality Usable Machine ExtractionInclusion Core AI-attack researchInfrastructure Social mediaKill Chain phase Actions on ObjectivesLLM provider OpenAIPublication date method Publisher Verified OverridePublication date precision DayPublisher OpenAIPublisher domain openai.com
Show 6 more tags Relevance basis campaign, actor, malware, or abuse investigationRetrieval method Jina Reader ProxyReview requirement Manual review requiredSource type operational CTI publicationStatistical use incident_or_observationYear 2024
Core research
Find related
OpenAI operational CTI publication covering Code debugging and scripting, Reconnaissance and target research, and Translation and localization. Indexed with SweetSpecter, Defense, and OpenAI context.
AI relevance core_ai_attackAI technology Large language modelAI use case Code debugging and scriptingAI use case Reconnaissance and target researchAI use case Translation and localizationCountry or region IranData type Documents and filesEvidence quality Usable Machine ExtractionInclusion Core AI-attack researchInfrastructure Messaging platformInfrastructure MobileKill Chain phase Command and Control
Show 23 more tags Kill Chain phase ReconnaissanceLLM model ChatGPTLLM provider OpenAIMITRE tactic CollectionMITRE tactic Command and ControlMITRE tactic ReconnaissancePublication date method Publisher Verified OverridePublication date precision DayPublisher OpenAIPublisher domain openai.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method Jina Reader ProxyReview requirement Manual review requiredSector DefenseSector EducationSector GovernmentSector MediaSource type operational CTI publicationStatistical use incident_or_observationThreat group SweetSpecterThreat-group identifier STORM-0817TTP Command and controlYear 2024
Context
Find related
arXiv academic or empirical research covering Large language model. Indexed with Hugging Face context.
AI relevance background_ai_mentionAI technology Large language modelEvidence landscape Controlled studyEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionInclusion Context onlyInfrastructure EmailLLM model GPT-4LLM provider Hugging FacePublication date method Arxiv Id MonthPublication date precision MonthPublisher arXiv
Show 7 more tags Publisher domain arxiv.orgRelevance basis ai-cyber research or controlled studyRetrieval method DirectReview requirement Manual review requiredSource type academic or empirical researchStatistical use possible_denominatorYear 2024
Core research
Find related
CrowdStrike threat-research report covering Obfuscation and evasion, Vulnerability research, and Obfuscation. Indexed with APT29 / Cozy Bear, Financial Services, and Anthropic context.
Actor motivation FinancialAI relevance core_ai_attackAI technology Agentic AIAI technology Generative AIAI use case Obfuscation and evasionAI use case Vulnerability researchAttack vector Credential theftAttack vector Supply chainCountry or region ChinaCountry or region RussiaData type Credentials and passwordsEvidence inventory Contains extracted metrics
Show 49 more tags Evidence landscape Incident responseEvidence landscape Threat landscape reportEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 25 Endpoint · medium confidenceExtracted metric · Blast Radius 26 Endpoint · medium confidenceExtracted metric · Duration Or Dwell 10 Minutes · medium confidenceExtracted metric · Duration Or Dwell 12 months · medium confidenceExtracted metric · Percentage 110% · medium confidenceExtracted metric · Percentage 29% · medium confidenceExtracted metric · Percentage 75% · medium confidenceExtracted metric · Percentage 94% · medium confidenceImpact Data theft or exfiltrationInclusion Core AI-attack researchInfrastructure BrowserInfrastructure CloudInfrastructure EmailInfrastructure EndpointKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationLLM model ClaudeLLM model Microsoft CopilotLLM provider AnthropicLLM provider MicrosoftLLM provider OpenAIMITRE tactic Defense EvasionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic Initial AccessMITRE tactic PersistencePublication date method TextPublication date precision DayPublisher CrowdStrikePublisher domain crowdstrike.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSector Financial ServicesSector GovernmentSource type threat-research reportStatistical use context_or_observationTarget DevelopersTarget ExecutivesThreat group APT29 / Cozy BearThreat group Scattered SpiderTTP ObfuscationTTP Supply-chain compromiseYear 2024
Core research
Find related
CrowdStrike threat-research report covering Obfuscation and evasion, Data exfiltration, and Defense evasion. Indexed with Scattered Spider and Financial Services context.
Actor motivation FinancialActor motivation HacktivismAI relevance core_ai_attackAI use case Obfuscation and evasionAttack vector SpearphishingCountry or region North KoreaCountry or region United StatesData type Credentials and passwordsEvidence inventory Contains extracted metricsEvidence quality Usable Machine ExtractionExtracted metric · Duration Or Dwell 12 months · medium confidenceExtracted metric · Percentage 102% · medium confidence
Show 64 more tags Extracted metric · Percentage 109% · medium confidenceExtracted metric · Percentage 14% · medium confidenceExtracted metric · Percentage 141% · medium confidenceExtracted metric · Percentage 160% · medium confidenceExtracted metric · Percentage 2% · medium confidenceExtracted metric · Percentage 25% · medium confidenceExtracted metric · Percentage 27% · medium confidenceExtracted metric · Percentage 29% · medium confidenceExtracted metric · Percentage 36% · medium confidenceExtracted metric · Percentage 41% · medium confidenceExtracted metric · Percentage 42% · medium confidenceExtracted metric · Percentage 43% · medium confidenceExtracted metric · Percentage 44% · medium confidenceExtracted metric · Percentage 51% · medium confidenceExtracted metric · Percentage 52% · medium confidenceExtracted metric · Percentage 55% · medium confidenceExtracted metric · Percentage 57% · medium confidenceExtracted metric · Percentage 58% · medium confidenceExtracted metric · Percentage 60% · medium confidenceExtracted metric · Percentage 7% · medium confidenceExtracted metric · Percentage 70% · medium confidenceExtracted metric · Percentage 75% · medium confidenceExtracted metric · Percentage 82% · medium confidenceExtracted metric · Percentage 84% · medium confidenceExtracted metric · Percentage 86% · medium confidenceExtracted metric · Percentage 93% · medium confidenceExtracted metric · Percentage 94% · medium confidenceImpact Credential compromiseImpact Data theft or exfiltrationInclusion Core AI-attack researchInfrastructure BrowserInfrastructure CloudInfrastructure EndpointKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationMITRE tactic Defense EvasionMITRE tactic ExfiltrationMITRE tactic Initial AccessMITRE tactic PersistencePublication date method Publisher Verified OverridePublication date precision DayPublisher CrowdStrikePublisher domain crowdstrike.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSector Financial ServicesSector GovernmentSector HealthcareSector HospitalitySector TechnologySector TelecommunicationsSector Transportation and LogisticsSource type threat-research reportStatistical use context_or_observationTarget Consumers or individualsTarget ExecutivesThreat group Scattered SpiderTTP Data exfiltrationTTP Defense evasionTTP SpearphishingYear 2024
Context
Find related
arXiv academic or empirical research covering Large language model. Indexed with Critical Infrastructure and Hugging Face context.
AI relevance background_ai_mentionAI technology Large language modelEvidence inventory Contains extracted metricsEvidence landscape Controlled studyEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionExtracted metric · Percentage 88.2% · medium confidenceExtracted metric · Percentage 90% · medium confidenceExtracted metric · Percentage 96.23% · medium confidenceInclusion Context onlyInfrastructure EmailLLM provider Hugging Face
Show 12 more tags LLM provider OpenAIPublication date method Arxiv Id MonthPublication date precision MonthPublisher arXivPublisher domain arxiv.orgRelevance basis ai-cyber research or controlled studyRetrieval method DirectReview requirement Manual review requiredSector Critical InfrastructureSource type academic or empirical researchStatistical use possible_denominatorYear 2024
Core research
Find related
Google Threat Intelligence Group / Mandiant operational CTI publication covering CAPTCHA bypass, Deepfake video or image, and Deepfake voice. Indexed with Financial Services context.
Actor motivation Influence / information operationsAI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI technology Generative AIAI technology Large language modelAI technology Speech or voice synthesisAI use case CAPTCHA bypassAI use case Deepfake video or imageAI use case Deepfake voiceAI use case Identity fraud and impersonationAI use case Reconnaissance and target researchAttack vector Supply chain
Show 42 more tags Attack vector VishingCountry or region RussiaData type Credentials and passwordsData type Source codeEvidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence quality Usable Machine ExtractionExtracted metric · Financial Value $200 million · medium confidenceImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure EndpointInfrastructure MobileKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase ReconnaissanceMITRE tactic Initial AccessMITRE tactic Lateral MovementMITRE tactic Privilege EscalationPublication date method TextPublication date precision DayPublisher Google Threat Intelligence Group / MandiantPublisher domain cloud.google.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector Financial ServicesSector GovernmentSector TelecommunicationsSource type operational CTI publicationStatistical use incident_or_observationTarget DevelopersTarget EmployeesTarget ExecutivesThreat-group identifier UNC6671TTP CAPTCHA bypassTTP Deepfake impersonationTTP Supply-chain compromiseTTP Target research / OSINTTTP Voice phishing / vishingYear 2024
Core research
Find related
ESET threat-research report covering Deepfake video or image, Identity fraud and impersonation, and Translation and localization. Indexed with Critical Infrastructure and Google context.
AI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI technology Generative AIAI use case Deepfake video or imageAI use case Identity fraud and impersonationAI use case Translation and localizationCountry or region AfricaCountry or region CanadaCountry or region GermanyCountry or region JapanCountry or region United StatesEvidence inventory Contains extracted metrics
Show 29 more tags Evidence quality Usable Machine ExtractionExtracted metric · Blast Radius over 20,000 websites · medium confidenceExtracted metric · Duration Or Dwell 30 years · medium confidenceImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EndpointInfrastructure MobileKill Chain phase Actions on ObjectivesKill Chain phase ExploitationLLM model GeminiLLM provider GoogleLLM provider OpenAIMalware or tool LummaMalware or tool VidarMITRE tactic ImpactPublication date method TextPublication date precision DayPublisher ESETPublisher domain eset.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSector Critical InfrastructureSector Financial ServicesSource type threat-research reportStatistical use context_or_observationTTP Deepfake impersonationYear 2024
Core research
Find related
Microsoft provider or government report covering Password spraying, Supply-chain compromise, and Generative AI. Indexed with Energy context.
AI relevance core_ai_attackAI technology Generative AIAI technology Large language modelAttack vector Supply chainCountry or region ChinaData type Credentials and passwordsData type Source codeEvidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 5 domains · medium confidenceExtracted metric · Duration Or Dwell 24 hours · medium confidence
Show 64 more tags Extracted metric · Duration Or Dwell 57 days · medium confidenceExtracted metric · Duration Or Dwell 58 days · medium confidenceExtracted metric · Duration Or Dwell 64 days · medium confidenceExtracted metric · Financial Value $15M · medium confidenceExtracted metric · Percentage 1% · medium confidenceExtracted metric · Percentage 10% · medium confidenceExtracted metric · Percentage 100% · medium confidenceExtracted metric · Percentage 15% · medium confidenceExtracted metric · Percentage 2% · medium confidenceExtracted metric · Percentage 20% · medium confidenceExtracted metric · Percentage 22% · medium confidenceExtracted metric · Percentage 23% · medium confidenceExtracted metric · Percentage 24% · medium confidenceExtracted metric · Percentage 25% · medium confidenceExtracted metric · Percentage 3% · medium confidenceExtracted metric · Percentage 31% · medium confidenceExtracted metric · Percentage 40% · medium confidenceExtracted metric · Percentage 42% · medium confidenceExtracted metric · Percentage 47% · medium confidenceExtracted metric · Percentage 49% · medium confidenceExtracted metric · Percentage 50% · medium confidenceExtracted metric · Percentage 52% · medium confidenceExtracted metric · Percentage 58% · medium confidenceExtracted metric · Percentage 6.5% · medium confidenceExtracted metric · Percentage 65% · medium confidenceExtracted metric · Percentage 66% · medium confidenceExtracted metric · Percentage 7% · medium confidenceExtracted metric · Percentage 73% · medium confidenceExtracted metric · Percentage 74% · medium confidenceExtracted metric · Percentage 80% · medium confidenceExtracted metric · Percentage 84% · medium confidenceExtracted metric · Percentage 86% · medium confidenceExtracted metric · Percentage 88% · medium confidenceExtracted metric · Percentage 90% · medium confidenceExtracted metric · Percentage 97% · medium confidenceImpact Data theft or exfiltrationImpact Ransomware or extortionImpact Service disruptionInclusion Core AI-attack researchInfrastructure CloudInfrastructure EmailInfrastructure EndpointKill Chain phase Actions on ObjectivesKill Chain phase ExploitationMITRE tactic ExecutionMITRE tactic ImpactMITRE tactic Initial AccessPublication date method Publisher Verified OverridePublication date precision DayPublisher MicrosoftPublisher domain cdn-dynmedia-1.microsoft.comRelevance basis AI misuse, abuse-disruption, or threat research reportRetrieval method DirectReview requirement Manual review requiredSector EnergySector GovernmentSource type provider or government reportStatistical use incident_or_observationTarget DevelopersTarget EmployeesTarget ExecutivesTTP Password sprayingTTP Supply-chain compromiseYear 2024
Core research
Find related
Kroll research publication covering Deepfake video or image, Deepfake voice, and Identity fraud and impersonation. Indexed with Akira and Financial Services context.
Actor motivation FinancialAI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI technology Speech or voice synthesisAI use case Deepfake video or imageAI use case Deepfake voiceAI use case Identity fraud and impersonationAttack vector Business email compromiseAttack vector Supply chainAttack vector VishingCVE CVE-2023-36025CVE CVE-2024-1708
Show 57 more tags CVE CVE-2024-1709CVE CVE-2024-21412Data type Credentials and passwordsData type Documents and filesEvidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence landscape Incident responseEvidence landscape Threat landscape reportEvidence quality Usable Machine ExtractionExtracted metric · Duration Or Dwell 48 hours · medium confidenceExtracted metric · Percentage 11% · medium confidenceExtracted metric · Percentage 13% · medium confidenceExtracted metric · Percentage 15% · medium confidenceExtracted metric · Percentage 24% · medium confidenceExtracted metric · Percentage 27% · medium confidenceExtracted metric · Percentage 3% · medium confidenceExtracted metric · Percentage 5% · medium confidenceExtracted metric · Percentage 6% · medium confidenceExtracted metric · Percentage 8% · medium confidenceExtracted metric · Percentage 9% · medium confidenceExtracted metric · Percentage 90% · medium confidenceImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure MobileKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationMalware or tool AKIRA ransomwareMalware or tool DarkGateMalware or tool PLAY ransomwareMITRE tactic Command and ControlMITRE tactic ImpactMITRE tactic Initial AccessPublication date method MetadataPublication date precision DayPublisher KrollPublisher domain kroll.comRelevance basis requires manual relevance reviewRetrieval method Jina Reader ProxyReview requirement Manual review requiredSector Financial ServicesSector TelecommunicationsSource type research publicationStatistical use do_not_aggregateTarget EmployeesTarget ExecutivesThreat group AkiraThreat group APT43 / KimsukyTTP Business email compromiseTTP Command and controlTTP Deepfake impersonationTTP Supply-chain compromiseTTP Voice phishing / vishingYear 2024
Core research
Find related
Proofpoint operational CTI publication covering Command and control, Data exfiltration, and Spearphishing. Indexed with SweetSpecter, Artificial Intelligence, and Anthropic context.
AI relevance core_ai_attackAI technology Agentic AIAI technology Generative AIAttack vector SpearphishingCountry or region AfricaCountry or region ChinaCountry or region United StatesData type Credentials and passwordsData type Documents and filesEvidence inventory Contains extracted IOCsEvidence inventory Contains extracted metricsEvidence quality Usable Machine Extraction
Show 52 more tags Extracted metric · Blast Radius 08 account · medium confidenceExtracted metric · Blast Radius 10 individuals · medium confidenceExtracted metric · Blast Radius 2024 campaign · medium confidenceImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure EmailInfrastructure EndpointIOC · Defanged Domain gommask[.]onlineIOC · Sha256 4ef3a6703abc6b2b8e2cac3031c1e5b86fe8b377fde92737349ee52bd2604379IOC · Sha256 71f5ce42714289658200739ce0bbe439f6ef6fe77a5f6757b1cf21200fc59af7IOC · Sha256 da749785033087ca5d47ee65aef2818d4ed81ef217bfd4bc07be2d0bf105b1bfIOC · Sha256 fc779f02a40948568321d7f11b5432676e2be65f037acfed344b36cc3dac16fcIOC · Sha256 feae7b2b79c533a522343ac9e1aa7f8a2cdf38691fbd333537cb15dd2ee9397eKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase InstallationLLM model ClaudeLLM provider AnthropicMalware or tool SugarGh0stMalware or tool SugarGh0st RATMITRE tactic Command and ControlMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic PersistencePublication date method MetadataPublication date precision DayPublisher ProofpointPublisher domain proofpoint.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector Artificial IntelligenceSector EducationSector Financial ServicesSector GovernmentSector MediaSector TelecommunicationsSource type operational CTI publicationStatistical use incident_or_observationTarget AI researchers and expertsTarget EmployeesTarget ExecutivesThreat group SweetSpecterTTP Command and controlTTP Data exfiltrationTTP SpearphishingYear 2024
Core research
Find related
Proofpoint operational CTI publication covering Identity fraud and impersonation, Malware development, and Phishing and lure generation. Indexed with TA547, Financial Services, and Anthropic context.
Actor motivation FinancialAI relevance core_ai_attackAI technology Agentic AIAI technology Generative AIAI technology Large language modelAI use case Identity fraud and impersonationAI use case Malware developmentAI use case Phishing and lure generationAttack vector Business email compromiseCountry or region AfricaCountry or region GermanyData type Credentials and passwords
Show 53 more tags Data type Documents and filesEvidence inventory Contains extracted IOCsEvidence quality Usable Machine ExtractionImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure EmailInfrastructure EndpointIOC · Defanged Domain bolibachan[.]comIOC · Defanged Domain indscpm[.]xyzIOC · Defanged Domain metro-delivery[.]comKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryLLM model ChatGPTLLM model ClaudeLLM model GeminiLLM model Microsoft CopilotLLM provider AnthropicLLM provider GoogleLLM provider MicrosoftLLM provider OpenAIMalware or tool LummaMalware or tool NetSupportMalware or tool NetSupport RATMalware or tool RhadamanthysMalware or tool StealCMITRE tactic Command and ControlMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessPublication date method MetadataPublication date precision DayPublisher ProofpointPublisher domain proofpoint.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector Financial ServicesSector GovernmentSource type operational CTI publicationStatistical use incident_or_observationTarget EmployeesTarget ExecutivesThreat group TA547Threat-group identifier TA547TTP Business email compromiseTTP Command and controlTTP Data exfiltrationTTP PowerShell executionYear 2024
Core research
Find related
CrowdStrike threat-research report covering Influence operations, Obfuscation and evasion, and Vulnerability research. Indexed with Financial Services and Anthropic context.
Actor motivation HacktivismActor motivation Influence / information operationsAI relevance core_ai_attackAI technology Agentic AIAI technology Generative AIAI use case Influence operationsAI use case Obfuscation and evasionAI use case Vulnerability researchAttack vector Supply chainCountry or region ChinaCountry or region IranCountry or region Russia
Show 54 more tags Data type Credentials and passwordsEvidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence landscape Incident responseEvidence landscape Threat landscape reportEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 25 Endpoint · medium confidenceExtracted metric · Blast Radius 26 Endpoint · medium confidenceExtracted metric · Breakout Time 2 minutes · medium confidenceExtracted metric · Breakout Time 62 minutes · medium confidenceExtracted metric · Breakout Time 7 seconds · medium confidenceExtracted metric · Breakout Time 84 minutes · medium confidenceExtracted metric · Duration Or Dwell 10 Minutes · medium confidenceExtracted metric · Percentage 20% · medium confidenceExtracted metric · Percentage 60% · medium confidenceExtracted metric · Percentage 75% · medium confidenceExtracted metric · Percentage 94% · medium confidenceImpact Credential compromiseInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EndpointKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationLLM model ClaudeLLM model Microsoft CopilotLLM provider AnthropicLLM provider MicrosoftLLM provider OpenAIMITRE tactic CollectionMITRE tactic Defense EvasionMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic Initial AccessPublication date method TextPublication date precision DayPublisher CrowdStrikePublisher domain crowdstrike.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSector Financial ServicesSector GovernmentSource type threat-research reportStatistical use context_or_observationTarget DevelopersTarget EmployeesTarget ExecutivesTTP Credential theftTTP Defense evasionTTP ObfuscationTTP Password sprayingTTP Supply-chain compromiseYear 2024
Core research
Find related
CrowdStrike threat-research report covering Exploit development, Data exfiltration, and MFA/session-token theft. Indexed with APT28 / Fancy Bear and Government context.
Actor motivation HacktivismActor motivation Influence / information operationsAI relevance core_ai_attackAI technology Generative AIAI use case Exploit developmentCountry or region ChinaCountry or region IsraelCountry or region North KoreaCountry or region United StatesData type Credentials and passwordsData type Session cookies or tokensEvidence inventory Contains extracted metrics
Show 55 more tags Evidence landscape Forecast or predictionEvidence landscape Threat landscape reportEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 365 accounts · medium confidenceExtracted metric · Blast Radius 55 countries · medium confidenceExtracted metric · Breakout Time 2 minutes · medium confidenceExtracted metric · Breakout Time 62 minutes · medium confidenceExtracted metric · Breakout Time 7 seconds · medium confidenceExtracted metric · Duration Or Dwell 31 seconds · medium confidenceExtracted metric · Percentage 110% · medium confidenceExtracted metric · Percentage 29% · medium confidenceExtracted metric · Percentage 42% · medium confidenceExtracted metric · Percentage 60% · medium confidenceExtracted metric · Percentage 71% · medium confidenceExtracted metric · Percentage 73% · medium confidenceExtracted metric · Percentage 75% · medium confidenceExtracted metric · Percentage 76% · medium confidenceExtracted metric · Percentage 84% · medium confidenceExtracted metric · Percentage 88% · medium confidenceImpact Data theft or exfiltrationImpact Ransomware or extortionImpact Service disruptionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure CloudInfrastructure EndpointInfrastructure Messaging platformKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationMITRE tactic CollectionMITRE tactic DiscoveryMITRE tactic ExfiltrationMITRE tactic Initial AccessMITRE tactic Lateral MovementMITRE tactic PersistencePublication date method Publisher Verified OverridePublication date precision DayPublisher CrowdStrikePublisher domain crowdstrike.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSector GovernmentSource type threat-research reportStatistical use context_or_observationTarget ExecutivesThreat group APT28 / Fancy BearThreat group APT29 / Cozy BearThreat group Scattered SpiderTTP Data exfiltrationTTP Exploit developmentTTP MFA/session-token theftYear 2024
Core research
Find related
OpenAI operational CTI publication covering Code debugging and scripting, Obfuscation and evasion, and Translation and localization. Indexed with APT43 / Kimsuky and OpenAI context.
AI relevance core_ai_attackAI use case Code debugging and scriptingAI use case Obfuscation and evasionAI use case Translation and localizationAttack vector SpearphishingCountry or region ChinaCountry or region IranCountry or region North KoreaCountry or region RussiaCountry or region United StatesEvidence inventory Contains extracted IOCsEvidence quality Usable Machine Extraction
Show 26 more tags Inclusion Core AI-attack researchIOC · Md5 0b42f77c2478bc5bc7bde3fddfc68462IOC · Md5 642e8632be32866792c7aaae0113aaa5IOC · Md5 bd1bc987f38b1c2901819b4c211886a2IOC · Md5 fdcc0dadabd87f8e9a776a2f34647de0Kill Chain phase DeliveryLLM model ChatGPTLLM model GPT-4LLM provider OpenAIMITRE tactic Defense EvasionMITRE tactic Initial AccessPublication date method TextPublication date precision DayPublisher OpenAIPublisher domain openai.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method Jina Reader ProxyReview requirement Manual review requiredSource type operational CTI publicationStatistical use incident_or_observationTarget DevelopersThreat group APT43 / KimsukyTTP Defense evasionTTP Script generationTTP SpearphishingYear 2024
Core research
Find related
Microsoft provider or government report covering CAPTCHA bypass, Identity fraud and impersonation, and Malware development. Indexed with APT28 / Fancy Bear, Defense, and Microsoft context.
Actor motivation FinancialAI relevance core_ai_attackAI technology Generative AIAI technology Large language modelAI use case CAPTCHA bypassAI use case Identity fraud and impersonationAI use case Malware developmentAI use case Obfuscation and evasionAI use case Reconnaissance and target researchAI use case Translation and localizationAI use case Vulnerability researchAttack vector Credential theft
Show 73 more tags Attack vector SpearphishingCountry or region ChinaCountry or region FranceCountry or region IranCountry or region North KoreaCountry or region RussiaCountry or region TaiwanCountry or region UkraineCountry or region United StatesCVE CVE-2022-30190Data type Credentials and passwordsData type Documents and filesEvidence inventory Contains extracted metricsEvidence landscape Controlled studyEvidence landscape Forecast or predictionEvidence quality Usable Machine ExtractionExtracted metric · Blast Radius 29 countries · medium confidenceImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure EmailInfrastructure Messaging platformInfrastructure Social mediaKill Chain phase Actions on ObjectivesKill Chain phase Command and ControlKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase InstallationKill Chain phase ReconnaissanceKill Chain phase WeaponizationLLM model ChatGPTLLM model Microsoft CopilotLLM provider MicrosoftLLM provider OpenAIMalware or tool DeadLock ransomwareMITRE tactic Command and ControlMITRE tactic Defense EvasionMITRE tactic ExecutionMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic PersistenceMITRE tactic ReconnaissanceMITRE tactic Resource DevelopmentPublication date method MetadataPublication date precision DayPublisher MicrosoftPublisher domain microsoft.comRelevance basis AI misuse, abuse-disruption, or threat research reportRetrieval method DirectReview requirement Manual review requiredSector DefenseSector EducationSector Financial ServicesSector GovernmentSector Nonprofit / NGOSector TechnologySector Transportation and LogisticsSource type provider or government reportStatistical use incident_or_observationTarget Consumers or individualsTarget DevelopersTarget ExecutivesThreat group APT28 / Fancy BearThreat group APT43 / KimsukyThreat-group identifier APT28Threat-group identifier APT4TTP CAPTCHA bypassTTP Command and controlTTP Credential harvestingTTP Defense evasionTTP Malware generationTTP MFA/session-token theftTTP SpearphishingYear 2024
Core research
Find related
UK Government provider or government report covering Exploit development, Malware development, and Obfuscation and evasion. Indexed with Education context.
Actor motivation HacktivismAI relevance core_ai_attackAI technology Agentic AIAI technology Generative AIAI technology Large language modelAI use case Exploit developmentAI use case Malware developmentAI use case Obfuscation and evasionAI use case Reconnaissance and target researchAI use case Translation and localizationAI use case Vulnerability researchAttack vector Spearphishing
Show 37 more tags Data type Credentials and passwordsData type Documents and filesEvidence landscape Forecast or predictionEvidence quality Usable Machine ExtractionImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure EmailInfrastructure Social mediaKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase ReconnaissanceKill Chain phase WeaponizationMITRE tactic Defense EvasionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic Lateral MovementMITRE tactic ReconnaissancePublication date method MetadataPublication date precision DayPublisher UK GovernmentPublisher domain ncsc.gov.ukRelevance basis AI misuse, abuse-disruption, or threat research reportRetrieval method DirectReview requirement Manual review requiredSector EducationSector GovernmentSource type provider or government reportStatistical use incident_or_observationTTP Data exfiltrationTTP Defense evasionTTP Exploit developmentTTP Malware generationTTP SpearphishingYear 2024
Core research
Find related
Proofpoint operational CTI publication covering Data exfiltration, Agentic AI, and Generative AI. Indexed with Financial Services and Anthropic context.
Actor motivation Influence / information operationsAI relevance core_ai_attackAI technology Agentic AIAI technology Generative AICountry or region AfricaData type Credentials and passwordsData type Documents and filesEvidence landscape Forecast or predictionEvidence quality Usable Machine ExtractionImpact Data theft or exfiltrationImpact Ransomware or extortionInclusion Core AI-attack research
Show 30 more tags Infrastructure EmailInfrastructure EndpointKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationLLM model ClaudeLLM provider AnthropicMalware or tool DarkGateMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessPublication date method MetadataPublication date precision DayPublisher ProofpointPublisher domain proofpoint.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector Financial ServicesSector GovernmentSource type operational CTI publicationStatistical use incident_or_observationTarget EmployeesTarget ExecutivesThreat-group identifier TA473Threat-group identifier TA577TTP Data exfiltrationYear 2024
Core research
Find related
Europol research publication covering Deepfake video or image, Influence operations, and Deepfake impersonation.
Actor motivation Influence / information operationsAI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI use case Deepfake video or imageAI use case Influence operationsCountry or region European UnionCountry or region FranceCountry or region GermanyData type Documents and filesEvidence inventory Contains extracted metricsEvidence quality Usable Machine ExtractionExtracted metric · Percentage 20% · medium confidence
Show 16 more tags Inclusion Core AI-attack researchInfrastructure EmailKill Chain phase Actions on ObjectivesKill Chain phase ExploitationPublication date method Text MonthPublication date precision MonthPublisher EuropolPublisher domain europol.europa.euRelevance basis requires manual relevance reviewRetrieval method Jina Reader ProxyReview requirement Manual review requiredSource type research publicationStatistical use do_not_aggregateTarget ExecutivesTTP Deepfake impersonationYear 2024
Core research
Find related
Recorded Future threat-research report covering Identity fraud and impersonation, Influence operations, and Obfuscation and evasion. Indexed with Critical Infrastructure context.
Actor motivation Disruption / destructionActor motivation Influence / information operationsAI relevance core_ai_attackAI technology Generative AIAI use case Identity fraud and impersonationAI use case Influence operationsAI use case Obfuscation and evasionCountry or region ChinaCountry or region IranCountry or region RussiaData type Credentials and passwordsData type Financial and payment data
Show 33 more tags Evidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence landscape Threat landscape reportEvidence quality Usable Machine ExtractionExtracted metric · Financial Value $459.8 million · medium confidenceExtracted metric · Financial Value $75 million · medium confidenceImpact Credential compromiseImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure EndpointInfrastructure MobileInfrastructure SaaSKill Chain phase Actions on ObjectivesKill Chain phase ExploitationMalware or tool AMOSMITRE tactic Defense EvasionMITRE tactic ImpactMITRE tactic Initial AccessPublication date method Url Year OnlyPublication date precision YearPublisher Recorded FuturePublisher domain recordedfuture.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSector Critical InfrastructureSector CryptocurrencySector TelecommunicationsSource type threat-research reportStatistical use context_or_observationTTP Credential theftTTP Defense evasionYear 2024
Core research
Find related
Fortinet forecast or strategic assessment covering Reconnaissance and target research, Ransomware deployment, and Generative AI. Indexed with Energy context.
AI relevance core_ai_attackAI technology Generative AIAI use case Reconnaissance and target researchEvidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionExtracted metric · Duration Or Dwell 24 hours · medium confidenceImpact Ransomware or extortionImpact Service disruptionInclusion Core AI-attack researchKill Chain phase Actions on Objectives
Show 21 more tags Kill Chain phase ExploitationKill Chain phase ReconnaissanceMITRE tactic CollectionMITRE tactic ExecutionMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic ReconnaissancePublication date method MetadataPublication date precision DayPublisher FortinetPublisher domain fortinet.comRelevance basis threat assessment, forecast, or red-team studyRetrieval method DirectReview requirement Manual review requiredSector EnergySector Transportation and LogisticsSource type forecast or strategic assessmentStatistical use context_onlyTarget ExecutivesTTP Ransomware deploymentYear 2023
Core research
Find related
SentinelOne operational CTI publication covering Command and control. Indexed with Telecommunications and OpenAI context.
AI relevance core_ai_attackCountry or region AfricaCountry or region IndiaCountry or region IranCountry or region JapanCountry or region RussiaCountry or region United KingdomCountry or region United StatesData type Credentials and passwordsData type Documents and filesEvidence inventory Contains extracted IOCsEvidence quality Usable Machine Extraction
Show 32 more tags Inclusion Core AI-attack researchInfrastructure BrowserInfrastructure CloudInfrastructure EmailInfrastructure Messaging platformInfrastructure MobileInfrastructure Social mediaIOC · Defanged Domain abuseipdb[.]comIOC · Sha1 88d40f86eefee5112515b73cce2d2badb7f49ffdKill Chain phase Command and ControlKill Chain phase DeliveryLLM model ChatGPTLLM provider OpenAIMalicious AI tool Predator AIMITRE tactic Command and ControlMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic Initial AccessPublication date method MetadataPublication date precision DayPublisher SentinelOnePublisher domain sentinelone.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector TelecommunicationsSource type operational CTI publicationStatistical use incident_or_observationTarget DevelopersTarget ExecutivesTTP Command and controlYear 2023
Core research
Find related
Microsoft provider or government report covering Deepfake video or image, Deepfake voice, and Identity fraud and impersonation. Indexed with APT43 / Kimsuky, Defense, and Microsoft context.
AI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI technology Generative AIAI technology Large language modelAI technology Speech or voice synthesisAI use case Deepfake video or imageAI use case Deepfake voiceAI use case Identity fraud and impersonationAI use case Malware developmentAI use case Obfuscation and evasionAI use case Reconnaissance and target researchAttack vector Smishing
Show 65 more tags Attack vector SpearphishingAttack vector VishingCountry or region BrazilCountry or region ChinaCountry or region FranceCountry or region IranCountry or region North KoreaCountry or region RussiaCountry or region TaiwanCountry or region United StatesEvidence inventory Contains extracted IOCsEvidence inventory Contains extracted metricsEvidence landscape Controlled studyEvidence landscape Forecast or predictionEvidence landscape Incident responseEvidence quality Usable Machine ExtractionExtracted metric · Percentage 26% · medium confidenceExtracted metric · Percentage 44% · medium confidenceExtracted metric · Percentage 90% · medium confidenceInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure EndpointInfrastructure Messaging platformIOC · Md5 48bd494ce58f83288f1fb3dacb7267e2Kill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase ReconnaissanceKill Chain phase WeaponizationLLM model ChatGPTLLM model Microsoft CopilotLLM provider MicrosoftLLM provider OpenAIMITRE tactic Defense EvasionMITRE tactic Initial AccessMITRE tactic ReconnaissanceMITRE tactic Resource DevelopmentPublication date method Text MonthPublication date precision MonthPublisher MicrosoftPublisher domain microsoft.comRelevance basis AI misuse, abuse-disruption, or threat research reportRetrieval method DirectReview requirement Manual review requiredSector DefenseSector Financial ServicesSector GovernmentSector Nonprofit / NGOSector TechnologySector Transportation and LogisticsSource type provider or government reportStatistical use incident_or_observationTarget Consumers or individualsTarget DevelopersTarget EmployeesThreat group APT43 / KimsukyTTP Deepfake impersonationTTP Defense evasionTTP Malware generationTTP ObfuscationTTP Prompt injectionTTP SpearphishingTTP Voice phishing / vishingYear 2023
Core research
Find related
Google Threat Intelligence Group / Mandiant operational CTI publication covering Deepfake video or image, Deepfake voice, and Identity fraud and impersonation. Indexed with APT43 / Kimsuky, Financial Services, and OpenAI context.
Actor motivation EspionageActor motivation FinancialActor motivation HacktivismActor motivation Influence / information operationsAI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI technology Generative AIAI technology Large language modelAI technology Speech or voice synthesisAI use case Deepfake video or imageAI use case Deepfake voiceAI use case Identity fraud and impersonation
Show 66 more tags AI use case Influence operationsAI use case Malware developmentAI use case Obfuscation and evasionAI use case Reconnaissance and target researchAttack vector Business email compromiseAttack vector Supply chainAttack vector VishingCountry or region CanadaCountry or region ChinaCountry or region IranCountry or region IsraelCountry or region North KoreaCountry or region RussiaCountry or region UkraineData type Source codeEvidence landscape Forecast or predictionEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionImpact EspionageImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure EmailInfrastructure EndpointInfrastructure Messaging platformInfrastructure Social mediaKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationKill Chain phase ReconnaissanceKill Chain phase WeaponizationLLM model ChatGPTLLM provider OpenAIMalicious AI tool WormGPTMalware or tool Cobalt StrikeMITRE tactic CollectionMITRE tactic Defense EvasionMITRE tactic Initial AccessMITRE tactic ReconnaissanceMITRE tactic Resource DevelopmentPublication date method TextPublication date precision DayPublisher Google Threat Intelligence Group / MandiantPublisher domain cloud.google.comRelevance basis campaign, actor, malware, or abuse investigationRetrieval method DirectReview requirement Manual review requiredSector Financial ServicesSector GovernmentSector MediaSector TelecommunicationsSource type operational CTI publicationStatistical use incident_or_observationTarget DevelopersTarget Security researchersThreat group APT43 / KimsukyThreat-group identifier APT43Threat-group identifier UNC6671TTP Business email compromiseTTP Deepfake impersonationTTP Malware generationTTP ObfuscationTTP Prompt injectionTTP Supply-chain compromiseTTP Voice phishing / vishingYear 2023
Core research
Find related
Trend Micro threat-research report covering Deepfake video or image, Identity fraud and impersonation, and Translation and localization. Indexed with Cryptocurrency and Hugging Face context.
AI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI technology Generative AIAI technology Large language modelAI use case Deepfake video or imageAI use case Identity fraud and impersonationAI use case Translation and localizationCountry or region United KingdomData type Source codeEvidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence landscape Incident response
Show 37 more tags Evidence quality Usable Machine ExtractionExtracted metric · Duration Or Dwell 24 months · medium confidenceExtracted metric · Financial Value US$10 · medium confidenceExtracted metric · Financial Value US$500 · medium confidenceExtracted metric · Percentage 92% · medium confidenceExtracted metric · Percentage 97% · medium confidenceInclusion Core AI-attack researchInfrastructure EmailInfrastructure EndpointInfrastructure Messaging platformInfrastructure Social mediaKill Chain phase DeliveryKill Chain phase ExploitationLLM model ChatGPTLLM model GPT-4LLM provider Hugging FaceLLM provider OpenAIMalicious AI tool FraudGPTMalicious AI tool WormGPTMITRE tactic Initial AccessPublication date method Text MonthPublication date precision MonthPublisher Trend MicroPublisher domain trendmicro.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSector CryptocurrencySector EducationSector Financial ServicesSector GovernmentSource type threat-research reportStatistical use context_or_observationTarget DevelopersTarget ExecutivesTTP Deepfake impersonationYear 2023
Core research
Find related
Trend Micro threat-research report covering Deepfake video or image, Malware development, and Deepfake impersonation. Indexed with Google context.
AI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI technology Generative AIAI technology Large language modelAI use case Deepfake video or imageAI use case Malware developmentEvidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionExtracted metric · Financial Value $100 · medium confidenceExtracted metric · Financial Value $110 · medium confidence
Show 41 more tags Extracted metric · Financial Value $200 · medium confidenceExtracted metric · Financial Value $90 · medium confidenceExtracted metric · Financial Value €5,000. · medium confidenceExtracted metric · Financial Value €550 · medium confidenceExtracted metric · Financial Value US$10. · medium confidenceExtracted metric · Financial Value US$500, b · medium confidenceExtracted metric · Financial Value US$90 · medium confidenceImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure EmailInfrastructure Messaging platformKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationLLM model ChatGPTLLM model GPT-4LLM model LlamaLLM provider GoogleLLM provider MetaLLM provider OpenAIMalicious AI tool DarkBERTMalicious AI tool Evil-GPTMalicious AI tool FraudGPTMalicious AI tool WormGPTMITRE tactic CollectionMITRE tactic Initial AccessPublication date method TextPublication date precision DayPublisher Trend MicroPublisher domain trendmicro.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSource type threat-research reportStatistical use context_or_observationTarget DevelopersTarget ExecutivesTTP Deepfake impersonationTTP Malware generationTTP Phishing link or attachmentYear 2023
Core research
Find related
Recorded Future threat-research report covering Deepfake video or image, Deepfake voice, and Identity fraud and impersonation.
Actor motivation Influence / information operationsAI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI technology Large language modelAI technology Speech or voice synthesisAI use case Deepfake video or imageAI use case Deepfake voiceAI use case Identity fraud and impersonationAI use case Influence operationsAttack vector VishingEvidence inventory Contains extracted IOCsEvidence landscape In-the-wild observed
Show 23 more tags Evidence landscape Underground-market observationEvidence quality Usable Machine ExtractionInclusion Core AI-attack researchInfrastructure BrowserInfrastructure Messaging platformInfrastructure Social mediaIOC · Defanged Domain elevenlabs[.]ioKill Chain phase Actions on ObjectivesKill Chain phase DeliveryMITRE tactic Initial AccessPublication date method TextPublication date precision DayPublisher Recorded FuturePublisher domain recordedfuture.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSource type threat-research reportStatistical use context_or_observationTarget EmployeesTTP Deepfake impersonationTTP Voice phishing / vishingYear 2023
Core research
Find related
Check Point provider or government report covering Malware development, Malware generation, and Phishing link or attachment. Indexed with Cryptocurrency and OpenAI context.
AI relevance core_ai_attackAI technology Large language modelAI use case Malware developmentAttack vector SpearphishingCountry or region AfricaCountry or region BrazilCountry or region CanadaCountry or region ChinaCountry or region FranceCountry or region GermanyCountry or region IndiaCountry or region Iran
Show 43 more tags Country or region IsraelCountry or region JapanCountry or region North KoreaCountry or region RussiaCountry or region South KoreaCountry or region TaiwanCountry or region UkraineCountry or region United KingdomCountry or region United StatesCountry or region VietnamData type Credentials and passwordsData type Documents and filesEvidence landscape Controlled studyEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionImpact Ransomware or extortionInclusion Core AI-attack researchInfrastructure EmailInfrastructure MobileKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase ExploitationLLM model ChatGPTLLM provider OpenAIMITRE tactic ExecutionMITRE tactic ImpactMITRE tactic Initial AccessPublication date method MetadataPublication date precision DayPublisher Check PointPublisher domain research.checkpoint.comRelevance basis AI misuse, abuse-disruption, or threat research reportRetrieval method DirectReview requirement Manual review requiredSector CryptocurrencySource type provider or government reportStatistical use incident_or_observationTarget DevelopersTTP Malware generationTTP Phishing link or attachmentTTP PowerShell executionTTP SpearphishingYear 2023
Core research
Find related
Recorded Future threat-research report covering Influence operations, Malware development, and Translation and localization. Indexed with Media and OpenAI context.
Actor motivation EspionageActor motivation FinancialActor motivation HacktivismActor motivation Influence / information operationsAI relevance core_ai_attackAI use case Influence operationsAI use case Malware developmentAI use case Translation and localizationAttack vector Malicious advertisementCountry or region RussiaCountry or region United StatesEvidence landscape Controlled study
Show 34 more tags Evidence landscape Proof of conceptEvidence landscape Underground-market observationEvidence quality Usable Machine ExtractionImpact EspionageImpact Ransomware or extortionImpact Service disruptionInclusion Core AI-attack researchInfrastructure EmailInfrastructure MobileInfrastructure Social mediaKill Chain phase Actions on ObjectivesKill Chain phase DeliveryKill Chain phase WeaponizationLLM model ChatGPTLLM provider OpenAIMITRE tactic ImpactMITRE tactic Initial AccessMITRE tactic Resource DevelopmentPublication date method TextPublication date precision DayPublisher Recorded FuturePublisher domain recordedfuture.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSector MediaSource type threat-research reportStatistical use context_or_observationTarget DevelopersTarget ExecutivesTarget Security researchersTTP Malicious advertisingTTP Malware generationYear 2022
Core research
Find related
Recorded Future forecast or strategic assessment covering Deepfake video or image, Identity fraud and impersonation, and Influence operations.
Actor motivation Influence / information operationsAI relevance core_ai_attackAI technology Deepfake / synthetic mediaAI technology Generative AIAI technology Large language modelAI use case Deepfake video or imageAI use case Identity fraud and impersonationAI use case Influence operationsAI use case Obfuscation and evasionAI use case Reconnaissance and target researchAI use case Translation and localizationData type Source code
Show 22 more tags Evidence quality Usable Machine ExtractionInclusion Core AI-attack researchKill Chain phase Actions on ObjectivesKill Chain phase ReconnaissanceMITRE tactic CollectionMITRE tactic Defense EvasionMITRE tactic ReconnaissancePublication date method UnknownPublication date precision UnknownPublisher Recorded FuturePublisher domain recordedfuture.comRelevance basis threat assessment, forecast, or red-team studyRetrieval method DirectReview requirement Manual review requiredSource type forecast or strategic assessmentStatistical use context_onlyTarget DevelopersTarget ExecutivesTTP Deepfake impersonationTTP Defense evasionTTP ObfuscationYear Unknown
Core research
Find related
Recorded Future threat-research report covering Malware development, Data exfiltration, and Prompt injection.
AI relevance core_ai_attackAI technology Agentic AIAI use case Malware developmentData type Credentials and passwordsData type Documents and filesEvidence inventory Contains extracted metricsEvidence landscape Forecast or predictionEvidence quality Usable Machine ExtractionExtracted metric · Percentage 40% · medium confidenceExtracted metric · Percentage 50% · medium confidenceExtracted metric · Percentage 75% · medium confidenceImpact Credential compromise
Show 27 more tags Impact Data theft or exfiltrationImpact Financial fraudImpact Service disruptionInclusion Core AI-attack researchInfrastructure Social mediaKill Chain phase Actions on ObjectivesKill Chain phase ExploitationMITRE tactic DiscoveryMITRE tactic ExecutionMITRE tactic ExfiltrationMITRE tactic ImpactMITRE tactic Initial AccessPublication date method UnknownPublication date precision UnknownPublisher Recorded FuturePublisher domain recordedfuture.comRelevance basis threat landscape, incident-response, or CTI reportRetrieval method DirectReview requirement Manual review requiredSource type threat-research reportStatistical use context_or_observationTarget DevelopersTarget EmployeesTarget ExecutivesTTP Data exfiltrationTTP Prompt injectionYear Unknown
Core research
Find related
USENIX academic or empirical research covering Large language model. Indexed with Education context.
AI relevance core_ai_attackAI technology Large language modelEvidence quality Usable Machine ExtractionInclusion Core AI-attack researchKill Chain phase ExploitationPublication date method UnknownPublication date precision UnknownPublisher USENIXPublisher domain usenix.orgRelevance basis ai-cyber research or controlled studyRetrieval method DirectReview requirement Manual review required
Show 5 more tags Sector EducationSector HospitalitySource type academic or empirical researchStatistical use possible_denominatorYear Unknown
No references match the current filters.