Darin Smith

Darin Smith

Leader, Security Research, Cisco Talos

Walnut Creek, California, United States

Actions

Darin is a manager for threat research at Cisco focused on detection engineering, AI and cloud security. Previous affiliations include Amazon and the US Department of Justice, along with UC Davis and King's College London.

Area of Expertise

  • Information & Communications Technology

Topics

  • Detection Engineering
  • Cloud Security
  • Threat Hunting
  • Cybersecurity leadership

Evading Detection with Dynamic AI Mimicry

Threat actors are increasingly leveraging large language models (LLMs) to create adaptive malware that evades traditional detection methods. This research introduces a novel AI-assisted malware prototype that enhances stealth by intelligently adapting to target environments. Our cloud provider discovery framework enumerates systems for evidence of AWS, Azure, or GCP usage, enabling malware to select the most appropriate cloud service for command and control operations. We demonstrate this capability through a novel agentic framework for macOS that dynamically leverages enterprise cloud AI services (AWS Bedrock, Azure OpenAI, or GCP Vertex AI) to blend malicious traffic with legitimate enterprise activity. This approach significantly complicates detection by mimicking authorized cloud usage patterns. We provide actionable defensive recommendations including comprehensive AI service monitoring, strict access controls, and prohibition of unauthorized AI platforms, while outlining future research into embedded models and novel detection methodologies.

Darin Smith

Leader, Security Research, Cisco Talos

Walnut Creek, California, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top