Just in:
Supreme Court notice to ED on Soren’s plea against arrest // Make Mother’s Day Marvellous in Singapore with Sweet Deals & Premium Gifts on iShopChangi // UAE Firms Eye Kuwaiti Opportunities at Investment Forum // Surprise! Dubai Among Most Budget-Friendly Travel Destinations // Discover the BCCoin (BlackCardCoin) Listing on XT // Abu Dhabi Sovereign Wealth Fund Reports Solid 2023 Performance // Dubai Design Days Unveils Design Spectacle // Dubai Strengthens Primary Care Network with New Al Mizhar Health Centre // ITTF Men’s and Women’s World Cup Macao 2024 Presented by Galaxy Entertainment Group Successfully Concluded with Diversified Extended Activities to Enhance the Atmosphere of “City of Sports” // North Korea’s Lazarus Group Suspected in $200 Million Crypto Laundering Scheme // Why PM Narendra Modi Is Deliberately Distorting Rahul Gandhi’s Comments On Tax On Rich // Sahm, Top Trading App in KSA, Launches Extensive Promotional Campaign // Low Turn Out Of Voters In Kerala On Friday Favours Left Democratic Front // Getting Ready: LUX Helps Female Ex-Offenders Reintegrate Back to Society // Abu Dhabi Luxury Homes See Price Boom Fueled by Foreign Investors // Nakilat Sails into Higher Profits for Q1 2024 // TDRA Celebrates Girls in ICT Day // Innovative Features Making the Ulike Air 10 Superior to the Previous Models // Enjoy Wealth Appreciation and Inheritance with Hong Kong Life’s Wealth Up (Premier) Savings Insurance Plan // UAE and Oman Forge Closer Ties with $129 Billion Investment Pact //

Cybercriminals Leverage AI for Stealthier Attacks

Researchers have uncovered a novel tactic employed by cybercriminals: leveraging Artificial Intelligence (AI) to craft malicious code. The culprit, a threat group known as TA547, is suspected of using AI to develop a PowerShell script designed to deploy malware.

PowerShell is a powerful scripting language commonly used for system administration within Windows environments. Malicious actors often exploit PowerShell to execute commands remotely, allowing them to infiltrate systems and steal sensitive data.

The unique aspect of this case lies in the script’s characteristics, which deviate from the usual human-written code. Security experts at Proofpoint, a cybersecurity firm, identified the script while investigating TA547’s recent campaign. The script, responsible for delivering the Rhadamanthys information stealer malware, exhibited unusual formatting and commenting practices, suggesting potential AI involvement.

While definitive confirmation remains elusive, the script’s peculiarities align with the capabilities of large language models, such as ChatGPT or Copilot. These AI systems possess the ability to generate code based on specific instructions. Security researchers theorize that TA547 might have utilized an AI tool to automate script creation, potentially aiming for increased efficiency and making detection more challenging.

ADVERTISEMENT

The malware distribution campaign involved phishing emails targeting German organizations across various industries. The emails, masquerading as legitimate invoices from Metro, a German cash-and-carry giant, contained a password-protected ZIP archive. Once opened, the archive unleashed a malicious shortcut file (.LNK). Clicking on this file triggered the execution of the AI-suspected PowerShell script, which subsequently downloaded and installed the Rhadamanthys malware.

Rhadamanthys, a malware-as-a-service (MaaS) offering, has been gaining traction within cybercrime circles since its emergence in September 2022. MaaS models essentially provide pre-developed malware to other criminals for a fee, eliminating the technical barrier for aspiring attackers.

The suspected use of AI in crafting the PowerShell script signifies a concerning evolution in cyberattacks. AI-powered tools empower attackers to automate tasks, potentially accelerating their operations and making them more elusive. This development underscores the urgent need for cybersecurity solutions capable of identifying and mitigating threats generated by AI.

Security experts recommend vigilance against phishing attempts, regardless of the sender’s apparent legitimacy. Verifying email authenticity through independent channels and avoiding interaction with suspicious attachments are crucial measures to prevent falling victim to such schemes.

____________________________________

This article first appeared on The WIRE and is brought to you by Hyphen Digital Network


(The content powered by our AI models is produced through sophisticated algorithms, and while we strive for accuracy, it may occasionally contain a few minor issues. We appreciate your understanding that AI-generated content is an evolving technology, and we encourage users to provide feedback if any discrepancies are identified. As this feature is currently in beta testing, your insights play a crucial role in enhancing the overall quality and reliability of our service. We thank you for your collaboration and understanding as we work towards delivering an increasingly refined and accurate user experience.)


Also published on Medium.

ADVERTISEMENT

ADVERTISEMENT
Just in:
UAE Fashion Brand Steps Up for Gaza Relief Efforts // Dubai Design Days Unveils Design Spectacle // Enjoy Wealth Appreciation and Inheritance with Hong Kong Life’s Wealth Up (Premier) Savings Insurance Plan // Supreme Court notice to ED on Soren’s plea against arrest // Make Mother’s Day Marvellous in Singapore with Sweet Deals & Premium Gifts on iShopChangi // Abu Dhabi Luxury Homes See Price Boom Fueled by Foreign Investors // Sahm, Top Trading App in KSA, Launches Extensive Promotional Campaign // Why PM Narendra Modi Is Deliberately Distorting Rahul Gandhi’s Comments On Tax On Rich // Emirates Health Makes Strides in Early Autism Detection // Dubai Attracts Wealthy Families with Business-Friendly Hub // ECOVACS ROBOTICS Teams Up with New Brand Ambassador, South Korean Superstar Jun Ji-hyun, for a Dynamic Journey Ahead // ITTF Men’s and Women’s World Cup Macao 2024 Presented by Galaxy Entertainment Group Successfully Concluded with Diversified Extended Activities to Enhance the Atmosphere of “City of Sports” // Dubai Strengthens Primary Care Network with New Al Mizhar Health Centre // The case for record-breaking rally to resume // FTLife Pre-Announces Name Change to Chow Tai Fook Life Insurance Company Limited // TDRA Celebrates Girls in ICT Day // A World of Stories Opens at the Abu Dhabi International Book Fair // HDBank targets high growth in 2024: $625.5m profits, 30% dividend // Getting Ready: LUX Helps Female Ex-Offenders Reintegrate Back to Society // Nakilat Sails into Higher Profits for Q1 2024 //