AI Used to Create Malware, WithSecure Observes

Alarm bells continue to ring in the cybersecurity world about the potential threat posed by AI in the hands of threat actors. In particular, malware created through ChatGPT seems to be a reality.

WithSecure’s CEO confirmed: Information security The company announced that it has observed malware samples generated by ChatGPT.

“Because of ChatGPT’s ability to provide different answers to the same question, it can also be used to generate different variations, or mutations, of malware samples. It becomes difficult,” said WithSecure CEO Juhani Hintikka. Information security.

Tim West, head of threat intelligence at WithSecure, added that the fact that malware created using ChatGPT is polymorphic will make it difficult for defenders.

“Traditionally, AI has been used by defenders in this industry, including us, and attackers have been manually attacking, but I think that is changing now,” Hintikka said. I was.

Malicious actors are already using legitimate software, such as remote access tools, so it makes sense for them to start using readily available AI.

“For better or worse, ChatGPT supports software engineering, enables malware development, and lowers the barrier to entry for threat actors,” said West.

When it comes to phishing emails, it’s clear that AI and large language models can be used to craft compelling email campaigns, social media messages, and targeted text.

“So far, humans have been able to discern what is suspicious and what is not, but I think it will be much more difficult in the future,” Hintikka said.

Efficient driving in the criminal world

According to Stephen Robinson, Senior Threat Intelligence Analyst at WithSecure, cybercriminals and cybercriminals are now evolving to reflect legitimate business.

Because ransomware is such a lucrative business, these villains can invest in efficiencies by outsourcing operations to suppliers, “akin to the gig economy,” Robinson said.

This investment is also likely to go into understanding AI and its capabilities, and in discussing the use of AI by threat actors, Hintikka said, “Unfortunately, as criminal groups have grown, they have invested in I have the means,” he said.

Looking to the future, Hintikka said, “This is going to be a game between good AI and bad AI.”

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *