Security News

Cybersecurity news aggregator

📰
INFO News Reddit r/netsec

Can AI-generated adversaries break TTP-based attribution? (arXiv 2026)

  • What: Research explores whether AI can mimic threat group behavior
  • Impact: Cybersecurity professionals may face challenges in attributing AI-generated attacks
Read Full Article →

Cyber Threat Intelligence (CTI) has traditionally attributed attacks through Tactics, Techniques and Procedures (TTPs). In this paper we evaluate whether that assumption still holds when AI agents are explicitly configured to emulate known threat groups. We configured AI agents to reproduce the behavior of APT28, APT29, APT41, APT44 and Lazarus inside enterprise and military cyber ranges. Our results suggest that sufficiently capable AI agents can reproduce TTP patterns closely enough to make attribution based solely on behavioral evidence significantly more difficult. We'd be interested in feedback from practitioners working on CTI, attribution or adversary emulation. submitted by /u/Obvious-Language4462 [link] [comments]

Share this article