Cointelegraph
DOGE$0.06979 1.67%
TRX$0.3277 0.53%
LINK$8.28 1.79%
ZEC$473.73 1.50%
ADA$0.1632 0.79%
XRP$1.07 1.21%
ETH$1,902.87 1.08%
BTC$63,994.40 0.84%
XMR$354.78 1.78%
BNB$574.69 0.49%
XLM$0.1716 1.11%
SOL$73.41 1.12%
HYPE$53.70 3.11%
Written by Allen Scottstaff editorReviewed by Allen Scottstaff editor

Hackers have started using AI to churn out malware

MagazinePublishedOct 4, 2024

Researchers at HP found a malware program written by generative AI “in the wild” while investigating a suspicious email.

hackers-use-generative-ai-to-write-malware-code

Malware developers are now using generative AI to speed up the process of writing code, accelerating the number of attacks while essentially letting anyone tech-savvy develop malware.

In a September report from HP’s Wolf Security team, HP detailed how they discovered a variation of the asynchronous remote access trojan (AsyncRAT) — a type of software that can be used to remotely control a victim’s computer — while investigating a suspicious email sent to a client.

However, while AsyncRAT itself was developed by humans, this new version contained an injection method that appeared to have been developed using generative AI.

In the past, researchers have found generative AI “phishing lures” or deceptive websites used to lure in victims and scam them. But according to the report, “there has been limited evidence of attackers using this technology to write malicious code in the wild” prior to this discovery.

The program had several characteristics that provided strong evidence it was developed by an AI program. First, nearly every function in it was accompanied by a comment explaining what it did.

Cybercriminals rarely take such care in providing notes for readers, as they generally do not want the public to understand how their code works. The researchers also believed that the structure of the code and “choice of function names and variables” gave strong evidence that the code was developed using AI.

Code excerpt containing alleged AI-generated statements. Source: HP Wolf Security

The team first discovered the email when it was sent to a subscriber of HP’s Sure Click threat containment software. It posed as an invoice written in French, which indicated that it was likely a malicious file targeting French speakers.

However, they could not initially determine what the file did, as the relevant code was stored inside a script that could only be decrypted with a password. Despite this roadblock, the researchers eventually succeeded at cracking the password and decrypting the file, which revealed the malware hidden within it.

Inside the file was a Visual Basic Script (VBScript) that wrote variables onto the user’s PC registry, installed a JavaScript file onto one of the user’s directories, and then ran the JavaScript file. This second file loaded the variable from the registry and injected it into a Powershell process. Two more scripts were then run, causing AsyncRAT malware to be installed on the device.

Infection chain leading to AsynRAT. Source: HP Wolf Security

According to cybersecurity software developer Blackberry, AsyncRAT is software released through GitHub in 2019. Its developers claim it to be “a legitimate open-source remote administration tool.” However, it “is used almost exclusively by cybercriminal threat actors.”

The software allows its users to “control infected hosts remotely” by providing them with a user interface that can perform tasks on the victim’s computer. Because it allows an attacker to take control of a victim’s computer, AsyncRAT can be used to steal a crypto user’s private key or seed words, potentially leading to the loss of funds.

Related: New ‘overlay attacks’ are a growing threat to crypto users — security CEO

Although AsyncRAT itself is not new, this particular variation uses a novel injection method, and the researchers found telltale signs of AI-generated code in this injection method, indicating that this new technology is making it easier than ever for malware developers to carry out attacks.

“The activity shows how GenAI [generative AI] is accelerating attacks and lowering the bar for cybercriminals to infect endpoints,” the HP report stated.

Cybersecurity researchers are still grappling with the effects of AI advancement on security. In December, some ChatGPT users discovered that it could be used to discover vulnerabilities in smart contracts.

As many in the crypto community noted at the time, this could make the AI program a useful tool for white hat hackers, but it could also allow black hats to find vulnerabilities for them to exploit.

In May 2023, Meta’s security department released a report warning that some malware operators were creating fake versions of popular generative AI programs and using them as lures to attract victims.

Magazine: Advanced AI system is already ‘self-aware’ — ASI Alliance founder

1 minute letter

Subscribe to daily byte-sized crypto news from Cointelegraph

Subscribe
Cointelegraph publishes long-form journalism, analysis and narrative reporting produced by Cointelegraph’s in-house editorial team with subject-matter expertise. All articles are edited and reviewed by Cointelegraph editors in line with our editorial standards. Some articles contain affiliate links, from which Cointelegraph may earn a commission. These relationships do not influence which products we review or our editorial conclusions. Content published in here does not constitute financial, legal or investment advice. Readers should conduct their own research and consult qualified professionals where appropriate. Cointelegraph maintains full editorial independence.

More on the subject