A Deceptive Tool That Targets AI Architectures Covers Victims’ Blind Spots


As AI tools become more and more sophisticated deeply rooted in programming around the world, new research from the cybersecurity company Crowdstrike shows how attackers are fast-tracking AI tools to steal access information, gain deep access to target sites, extract sensitive information, and even destroy target files and systems – all while finding new ways to block their tracks.

The researchers found the worm in the wild while investigating the security of AI software. Adam Meyers, CrowdStrike’s senior vice president of anti-malware operations, says the company has yet to say whether the operation was carried out by another player, but that it coincides with a major shift in attackers’ preferences. TeamPCP (which Crowdstrike tracks as “Altered Spider”) and North Korean groups looking for a way to deliver AI software.

“This is one of the campaigns that we’ve seen that shows that it’s an up-and-coming movement,” Meyers told WIRED. “As AI coding becomes the standard of development, product companies’ threats are growing to use trust relationships. For the first time we are seeing how much AI and AI toolchains are working in technology.”

Worm CrowdStrike detected works slowly. First, it conducts research to evaluate the location you are interested in. It then looks for access codes and other information, such as cryptographic keys and server access information that it can provide to attackers. When the malware gains access, it releases itself and continues to capture information, especially the “npm” credentials that provide access to package management servers and other development services such as pull requests.

The deeper the malware gets into the system, the more sensitive data it can capture. At this point, malware can also use its destructive power, or what Meyers calls “dead modification,” to destroy files or restrict access to malware.

However, the most important thing is that most of the malicious activities of this worm occur in blind areas, because most of its activities are based on legitimate activities. “It’s like a needle in a haystack except this is a needle in a needle stack,” Meyers says. “This seems like a lot of automation organizations are using to code, so it’s hard to figure it out.”

Meyers adds that in these AI software pipelines, it’s difficult to collect the data that security cameras and analytics tools routinely use to identify suspicious activity.

“There’s a lot of telemetry that’s connected because the official AI system is working the same way as this worm, so it’s hard to tell from the telemetry you have on you what’s legitimate and what’s not,” says Meyers.

In order to hide it more cleverly, the authors of the worm included a time delay in which different possibilities will hold for hours or days after the foundation is laid, which makes it very difficult for the defenders to establish the cause and effect of certain events that lead to other consequences.

Meyers says that Crowdstrike has been working to connect many dots, but emphasizes that as the development of AI software explodes, there is a greater need for all players to collaborate on solutions.

“It’s a very limited area of ​​detection because a lot of this work is going to generate any kind of telemetry that we can see,” says Meyers, “so it’s very difficult to know what is acceptable and what isn’t.”



Source link

اترك ردّاً

لن يتم نشر عنوان بريدك الإلكتروني. الحقول الإلزامية مشار إليها بـ *