Beyond Flesh, Beyond Code: LLM based attack lifecycle with self-guided agent

No ratings

Presented at DeepSec 2024 by

Large Language Models (LLMs) are rapidly evolving, and their capabilities are attracting the attention of threat actors. This presentation explores how malicious actors are utilizing LLMs to enhance their cyber operations, and showcasing available tools based on LLM, as well as an advanced stealer managed by AI. Cyber Security is a very dynamic field, but there are still a few basic things that haven’t changed for a while, one of them is the attack lifecycle. A full attack lifecycle can be enchased using LLM – and threat actors already use it. There are risks and potential usage in the future. LLM-based tools can play a significant role in various stages of the cyber attack lifecycle. In this talk I will show how threat actors weaponizing LLM based chats, as well as LLM based chats that were built specifically for threat actors and hackers and how these operate, including smart LLM obfuscation of malware to avoid AV detection. Finally, I will present an undetected - fully LLM operated C2 and Stealer POC.