A Hacker Used AI-Written PhantomRaven Malware to Seek Bug Bounty Payouts | Ukraine news | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


A routine software installation opened the door to a campaign that blurred the line between cybercrime and legitimate vulnerability research.

A hacker used malware written with the help of artificial intelligence to attack companies through open-source software packages. He then used the access he gained to search for vulnerabilities and subsequently demanded payouts through legitimate bug bounty programs.

As reported by axios.com.

CrowdStrike researchers reached this conclusion. Their analysis demonstrates how artificial intelligence is lowering the technical barrier for cybercriminals and enabling even inexperienced attackers to create their own malicious tools.

How the PhantomRaven scheme worked

CrowdStrike researchers believe with a high degree of confidence that the hacker used a large language model to write the malicious code. Comments, placeholder code fragments, and distinctive token-analysis patterns left in the script point to this conclusion.

The attacker published malicious open-source npm packages. Once installed by developers, these packages deployed the PhantomRaven malware on their systems.

PhantomRaven collected credentials, secrets, and other sensitive information related to software development. According to CrowdStrike, the hacker used the stolen data to gain access to companies’ assets and search for vulnerabilities.

He then submitted the vulnerabilities he found to official bug bounty programs and attempted to receive payouts. The hacker claimed to have collected rewards from at least nine companies in the technology, retail, and hospitality sectors. However, researchers were unable to determine whether PhantomRaven had been used to attack those companies specifically or whether the vulnerabilities had been discovered by other means.

CrowdStrike responded to several incidents linked to the malware and took steps to contain them.

Why the hacker used bug bounty programs

Turning to legitimate bug bounty programs helped the attacker build a reputation and gain trust within the broader hacking community, explained Adam Meyers, CrowdStrike’s senior vice president of counter-adversary operations.

We’re seeing this everywhere. Adversaries are using artificial intelligence to develop their own tools. This is happening across the entire spectrum – from nation-states to cybercriminals and hacktivists.

– Adam Meyers

Researchers also noted that they found no evidence that the data stolen during this campaign had been sold on criminal marketplaces.

Why this case matters

The PhantomRaven case is another example of how attackers are increasingly using artificial intelligence to scale their operations. At the same time, the malware itself was relatively simple, and the attack relied on well-known supply chain compromise techniques.

The most notable aspect was that artificial intelligence apparently helped an inexperienced hacker create functional malware of his own rather than simply use ready-made tools. This suggests that the growing accessibility of such technologies is gradually expanding the pool of people capable of carrying out more sophisticated cyber operations.





Click Here For The Original Source.

——————————————————–

..........

.

.