CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

APT Meets GPT: Targeted Operations with Untamed LLMs

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2105

As cited

Copy frozen at (site build).

threat intel

APT Meets GPT: Targeted Operations with Untamed LLMs

Volexity detected a China-aligned threat actor tracked as UTA0388 conducting sophisticated spear phishing campaigns from June 2025 across North America, Asia, and Europe using fabricated identities and multiple languages. The campaigns employed a malware family called GOVERSHELL delivered through archive files with legitimate executables that load malicious payloads via DLL search order hijacking. Evidence suggests UTA0388 leveraged Large Language Models, including OpenAI's ChatGPT, to assist with campaign development and social engineering, with some campaigns involving extended rapport-building email exchanges before malicious links were sent.

Why it matters: Organizations in North America, Asia, and Europe face targeted spear phishing risk from a China-aligned actor using LLM-assisted social engineering and custom malware; practitioners should enhance email security, implement defenses against DLL hijacking, and monitor for GOVERSHELL variants.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary