Exclusive: AI-written malware helped a hacker cash in on bug bounty programs | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


A hacker used AI-written malware distributed through open-source software packages to compromise companies and hunt for bugs that he then submitted for legitimate bug bounty payments, according to CrowdStrike research shared first with Axios.

Why it matters: The findings offer a striking example of how AI is lowering the technical barriers to cybercrime and allowing relatively unsophisticated hackers to build their own malware.


Driving the news: CrowdStrike researchers say they have high confidence that the financially motivated hacker used a large language model to write the malware behind his attack based on the comments, placeholder code and token-analysis patterns left inside the script.

Advertisement

Advertisement

  • The hacker also posted about collecting bounties from at least nine companies across the technology, retail and hospitality sectors; however, it’s unclear whether the malware, called PhantomRaven, was used to compromise those particular companies or identify the issues behind those bounties.

  • CrowdStrike remediated and responded to multiple incidents involving this malware.

How it works: The hacker published malicious open-source npm packages that delivered the PhantomRaven malware.

  • When developers installed the malicious packages, PhantomRaven executed on their systems and collected information, including credentials and other sensitive development data.

  • CrowdStrike assesses that the hacker used PhantomRaven to compromise company assets and hunt for vulnerabilities.

  • The hacker then used those compromises as leverage to submit bugs to legitimate bug bounty programs and seek payouts.

Between the lines: Turning to bug bounty programs allowed the hacker to establish credibility in the broader hacker community, Adam Meyers, CrowdStrike’s senior vice president of counter adversary operations, told Axios.

Advertisement

Advertisement

  • The researchers also said in the report that they haven’t seen stolen data from this campaign being sold on criminal marketplaces.

The big picture: The case is just the latest example of growing AI adoption among malicious actors, including less-sophisticated actors eager to scale their operations.

  • “We’re seeing it all over the place,” Meyers said. “We have adversaries that are using AI to develop their tooling; we’re seeing it across the spectrum of nation-states and criminal hacktivists.”

Yes, but: The malware used in this campaign is relatively simple, and the attack relied solely on well-known supply-chain techniques.

Advertisement

Advertisement

  • The notable part is that AI appears to have helped a relatively inexperienced hacker build his own functioning malware rather than relying on off-the-shelf tools.

Go deeper: AI’s agent containment problem is getting harder

AI is moving fast. Axios AI+ keeps you ahead. Sign up free at Axios.com.



Click Here For The Original Source.

——————————————————–

..........

.

.