Skip to content
Preprint

Towards Automated Cyber Threat Intelligence Elicitation in Underground Forums

Aug 2026 · 0 citations · 66 references
Computer Science

TL;DR

DarkBot is presented, to the best of the authors' knowledge, the first multi-agent LLM-based system for active CTI elicitation in underground forums and elicited CTI-relevant disclosures without observed account suspensions, moderator interventions, or explicit accusations of automated participation.

Abstract

Cyber threat intelligence from underground forums has traditionally relied on passive monitoring. However, as users have become more aware of large-scale data collection, valuable intelligence has become increasingly rare in open forums, often migrating instead to private or harder-to-reach spaces, making passive approaches inadequate. Building on the intuition that relevant information can be obtained through active elicitation, this paper presents DarkBot, to the best of our knowledge, the first multi-agent LLM-based system for active CTI elicitation in underground forums. DarkBot decomposes the interaction task across eleven specialized agents organized into three functional blocks: engagement gating for relevance and safety filtering, context-aware question generation driven by MITRE ATT&CK tactics, and linguistic style adaptation to better align with real forum users. In a controlled evaluation across 100 CrimeBB conversations, the system recovered 72.8% of the validated MITRE ATT&CK techniques present in the original discussions by observing only the initial post at the start of each interaction, and it consistently outperformed a monolithic baseline. The proposed layered safety design contained all injected jailbreak attempts at the pipeline level. These results were further supported by real-world experiments: in a prospective matched deployment, threads assigned to DarkBot accumulated an average of 3.85 more CTI entities than their controls over seven days, and across 104 live forum conversations, the system elicited CTI-relevant disclosures without observed account suspensions, moderator interventions, or explicit accusations of automated participation.

View source

Similar papers

Preprint Aug 2026

STINER: Automated Extraction of Strategic Cyber Threat Intelligence from X

STINER, a taxonomy and expert-annotated corpus for extracting strategic intelligence from social media streams is introduced, and how social-media-driven extraction can surface early signals of the SafePay ransomware campaign prior to its retrospective characterization in vendor threat landscape reports is illustrated.

Yasir Ech-Chammakhy, Oussama Azrara, J. Chbili et al. · 0 citations
Review Open access 2026

Evolving Cyber Threat Intelligence: A Systematic Review and Comparative Analysis

To improve cybersecurity across industries, Cyber Threat Intelligence (CTI) is becoming increasingly crucial. This systematic review explores how CTI practices are evolving in response to advancements in Artificial Intelligence (AI), particularly in the context of Large Language Models (LLMs). We examined 61 peer-reviewed studies using the PRISMA methodology, which demonstrates a strict selection procedure founded on specified inclusion, exclusion, and quality standards. This approach aligns with the scope of similar systematic reviews in the field of cyber threat intelligence. The review provides a comparative synthesis of CTI research capabilities across threat detection and prediction, attribution, forecasting, and automated reporting. We classify these approaches into three categories: conventional methods, those enhanced by AI and Machine Learning, and those based on LLMs. Our findings indicate that LLMs offer significant advantages in contextual reasoning, processing unstructured threat intelligence, and generating actionable mitigation plans. However, challenges such as model explainability, data privacy, system interoperability, and standardization impede their integration into operational environments. In addition to highlighting the potential and practical limitations of LLMs in CTI, this study identifies research gaps and proposes methods to create scalable, secure, and flexible CTI systems that support real-time cyber defense.

Hilalah Alturkistani, Abdul Ghafar Jaafar, S. Chuprat et al. · 0 citations
Open access Jul 2026

Piloting the Integration of AI-Driven Detection Methods to Counter Disinformation in Organizational Processes

With the rise of generative AI, the increasing threat of automatically generated uncivil content (including misinformation for information warfare up to cyber-bullying purposes) makes the protection of open online discourse even more pressing than before. In the implementation of measures for countering these threats, the different intervention objectives of stakeholders, their workflows, and IT support need to be considered. Stakeholders include online social network moderators, journalists, fact-checkers, social listeners, as well as authorities and organizations with safety- and security-related tasks. Given the sheer volume of online social network content, automated or community-based solutions are required to detect (automated) misinformation. However, detection solutions are predominantly message-focused and target end-users, leaving experts without systematic, large-scale perspectives on coordinated disinformation campaigns to guide countermeasures. To bridge this gap, we conduct an expert-centered study on the integration of detection methods proposed by the research community. Our contributions are threefold: (a) We adopt disinformation features from a previous study and draw connections to literature on detection methods; (b) semi-structured interviews yield vignettes that expose the spectrum of goals, constraints, tools, and decision-making processes employed by experts, informing requirements for method integration; (c) we design a demonstrator that showcases representative methods to uncover unexplored concepts, probe affordances and limitations in context, and evaluate conceptual fit during the interviews. Together, these steps bridge the gap between data- and AI-driven detection techniques from research and the practical needs of diverse stakeholders confronting targeted and large-scale disinformation.

Lucas Stampe, C. Grimme · 0 citations
Conference Jul 2026

Cyber Threat Intelligence Report Generation Using Agentic AI

Cyber Threat Intelligence (CTI) reports are instrumental communication tools for keeping decision makers and cybersecurity practitioners informed about the rapidly evolving cyberspace. However, the explosive growth of CTI sources has made ingestion, processing, and analysis for intelligence reporting increasingly difficult and error-prone. To address this, we introduce an end-to-end framework that ingests cybersecurity attack trends and streaming news, augmented with feeds from cybersecurity articles, into an agentic AI workflow. Further enhanced by a GraphRAG database and a vector database, this approach strengthens the capabilities of LLMs. The result is the generation of CTI analysis reports with high-quality and grounded data sources aimed at supporting and enhancing the decision-making process. We evaluate the system using custom grounding and consistency strategy, revealing strong performance when the workflow retrieves directly from RSS evidence and similarly high-quality synthesis when leveraging the knowledge graph.

Omar Awajan, Sasha Abuin · 0 citations
Open access Aug 2026

Breaking and Defending LLM-Powered Social Media Bot Detection Systems †

The rise of social media bots poses a persistent threat, enabling misinformation, public opinion manipulation, and erosion of trust in online platforms. To combat this, machine learning systems have been developed to detect and limit bot activity. However, attackers continuously adapt through adversarial optimization, behavior imitation, and semantic manipulation strategies, creating an escalating arms race with detection tools. Recent advances in LLMs have significantly improved bot detection by enabling deeper semantic and contextual analysis. However, this shift also introduces new attack surfaces, allowing adversaries to craft exploits that directly target LLM reasoning and generation mechanisms. Industry tools like Anthropic’s Claude Code Security similarly leverage LLMs for security, motivating our study of their attack surfaces. In this work, we explore both offensive and defensive aspects of LLM-powered, threat-specific cybersecurity applications. While centered on the challenge of social media bot detection, our methodology and insights generalize to a broad class of LLM-powered cybersecurity systems, including phishing detection, email classification, fraud analysis, and more. We introduce two novel adversarial attack strategies that systematically exploit semantic and contextual weaknesses of LLM-based classifiers, degrading LLM performance in bot detection by up to 48%, and propose a robust multi-LLM defense architecture designed to preserve detection reliability under adaptive adversarial conditions. Our solution, LSABRE, is a multi-LLM framework that improves robustness across various attacks, maintaining 86% detection accuracy even under strong adaptive adversarial attacks.

Nof Orenstein, Yoni Birman · 0 citations
#natural language process... Preprint Aug 2026

BEACON: Behavior-Anchored Cross-Source Knowledge Graph Construction for Cyber Threat Intelligence

BEACON is an LLM-driven framework for cross-source CTI knowledge graph construction that constructs and releases two human-annotated datasets from 34 sources and outperforms all baselines by at least 23% and 9%, respectively.

Changze Li, Yutong Cheng, Tsania Camila Finnisa et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.