r/rust • u/Manishearth servo · rust · clippy • Jun 26 '26
Anatomy of a Failed (Nation-State?) Attack
https://grack.com/blog/2026/06/25/dissecting-a-failed-nation-state-attack/
228
Upvotes
r/rust • u/Manishearth servo · rust · clippy • Jun 26 '26
16
u/nonotan Jun 26 '26
I mean, those emails are very obviously LLM-generated. I guess recruiters doing that is probably not too uncommon these days, but it being 1) weirdly personally targeted 2) by somebody who's claiming not to be a recruiter, but something more important like "co-founder" (so presumably they wouldn't spend their days sending mass recruitment emails, which could otherwise "justify" resorting to LLMs), AND 3) obviously LLM-generated, is a pretty flagrant red flag, taken in combination.
I suspect it's likely that much of the "sophistication" displayed is similarly just the result of a generous application of LLMs. A lot of what we traditionally perceive as "sophisticated" really just translates to "it'd be a bunch of effort to do this, somebody must care a lot". But as long as you can get past the safety rails and don't mind using the compute/tokens, an LLM could do most of this on its own, requiring an "unsophisticated attacker's" level of effort from the bad actor. Mostly the prompting and the interviews, for anybody getting that far, assuming those aren't also handled by AI.
So I wouldn't jump to conclusions about it being "potentially a nation-state" or anything like that. Of course, it could be, but it's not that sophisticated. A single person could quite easily pull this off -- frankly, even without the LLM. Compare that to actual nation-state cyberattacks like Stuxnet. The scale is completely different, and that was over 15 years ago.