As cited
Copy frozen at (site build).
threat intel
APT Meets GPT: Targeted Operations with Untamed LLMs
Volexity detected a China-aligned threat actor tracked as UTA0388 conducting sophisticated spear phishing campaigns from June 2025 across North America, Asia, and Europe using fabricated identities and multiple languages. The campaigns employed a malware family called GOVERSHELL delivered through archive files with legitimate executables that load malicious payloads via DLL search order hijacking. Evidence suggests UTA0388 leveraged Large Language Models, including OpenAI's ChatGPT, to assist with campaign development and social engineering, with some campaigns involving extended rapport-building email exchanges before malicious links were sent.
Why it matters: Organizations in North America, Asia, and Europe face targeted spear phishing risk from a China-aligned actor using LLM-assisted social engineering and custom malware; practitioners should enhance email security, implement defenses against DLL hijacking, and monitor for GOVERSHELL variants.
- Source published
- First seen by Cybersecurity Tracker