Threats Tagged 'chatgpt'
View all threats tagged with 'chatgpt'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'chatgpt'
Click on any threat for detailed analysis and mitigation recommendations
A sophisticated malware campaign exploits user trust in AI platforms to deliver the AMOS stealer. Attackers use SEO poisoning to surface malicious ChatGPT and Grok conversations offering 'helpful' macOS disk cleanup advice. These conversations contain Terminal commands that, when executed, deploy AMOS, a multi-stage malware that harvests credentials, escalates privileges, and establishes persistence. The attack bypasses traditional security measures by leveraging legitimate platforms and user behavior, making it particularly insidious. AMOS targets cryptocurrency wallets, browser data, and system information, exfiltrating sensitive data to attacker-controlled servers. This campaign represents a significant evolution in social engineering techniques, exploiting the growing reliance on AI assistants for technical guidance. Join the discussion | AlienVault OTX General | 12/10/2025, 12:06:40 UTC Added: 12/10/2025, 14:37:52 UTC |
This report describes how generative AI techniques were utilized to accelerate the reverse engineering of XLoader malware, specifically version 8.0. By combining cloud-based static analysis of IDA exported data with dynamic checks, researchers rapidly unpacked encrypted code, deobfuscated API calls, and decrypted strings and domain names. The analysis uncovered three distinct function encryption schemes and a complex domain generation algorithm used by XLoader. The AI-assisted approach significantly reduced analysis time from days to hours, enabling faster extraction of indicators of compromise (IoCs). Despite AI's assistance, human expertise remained essential for overcoming the most sophisticated protections. The report highlights that generative AI can serve as a force multiplier for malware analysis, though malware authors may adapt their techniques in response. The threat is assessed as medium severity, with no known exploits in the wild currently. Several IoCs including hashes and suspicious domains are provided for detection and blocking. Join the discussion | AlienVault OTX General | 11/03/2025, 14:28:33 UTC Added: 11/03/2025, 20:00:46 UTC |
The Kimsuky APT group has launched a sophisticated spear-phishing campaign using AI-generated deepfake military ID cards to target South Korean defense institutions. The attack impersonates military employee ID issuance processes and exploits ChatGPT to create convincing fake ID images. The malware employs obfuscated batch files and AutoIt scripts to evade detection, connecting to command and control servers for further payload deployment. The campaign demonstrates the evolving tactics of state-sponsored threat actors in leveraging AI technologies for cyber espionage. Analysis reveals connections to previous Kimsuky operations targeting unification researchers and government agencies, highlighting the persistent nature of the threat. Join the discussion | AlienVault OTX General | 09/15/2025, 08:00:48 UTC Added: 09/15/2025, 09:34:09 UTC |
Showing 1 to 3 of 3 results