Srsly Risky Biz: China's AI-Enabled APT Operations Are Getting Interesting (opens in a new tab)
Why readArgues Chinese APT use of AI on malware development will degrade the code-similarity clustering that threat intel attribution depends on.
Tom Uren and James Wilson discuss evidence that Chinese state groups are applying AI to malware development in a measured, practical way rather than for headline-grabbing autonomy, with the consequence that variant diversity makes clustering activity for attribution harder. They also cover the US disrupting Iranian operators by publicising, in a Treasury sanctions package, that some were hacking Iranian firms, and question whether burning that information in a sanctions document was the right call. Commentary rather than primary research, but the attribution point is worth carrying into intel workflows.