Skip to main content

Watch out - ChatGPT is being used to create malware

Web Hosting & Remote IT Support

The world's most popular chatbot, ChatGPT, is having its powers harnessed by threat actors to create new strains of malware.

Cybersecurity firm WithSecure has confirmed that it found examples of malware created by the notorious AI writer in the wild. What makes ChatGPT particularly dangerous is that it can generate countless variations of malware, which makes them difficult to detect. 

Bad actors can simply give ChatGPT examples of existing malware code, and instruct it to make new strains based on them, making it possible to perpetuate malware without requiring nearly the same level of time, effort and expertise as before. 

For good and for evil

The news comes as talk of regulating AI abounds, to prevent it from being used for malicious purposes. There was essentially no regulation governing ChatGPT's use when it launched to a frenzy in November last year, and within a month, it was already hijacked to write malicioius emails and files. 

There are certain safeguards in place internally within the model that are meant to stop nefarious prompts from being carried out, but there are ways threat actors can bypass these.

Juhani Hintikka, CEO at WithSecure, told Infosecurity that AI has usually been used by cybersecurity defenders to find and weed out malware created manually by threat actors. 

It seems that now, however, with the free availability of powerful AI tools like ChatGPT, the tables are turning. Remote access tools have been used for illicit purposes, and now so too is AI. 

Tim West, head of threat intelligence at WithSecure added that “ChatGPT will support software engineering for good and bad and it is an enabler and lowers the barrier for entry for the threat actors to develop malware.”

And the phishing emails that ChatGPT can pen are usually spotted by humans, as LLMs become more advanced, it may become more difficult to prevent falling for such scams in the neat future, according to Hintikka.

What's more, with the success of ransomware attacks increasing at a worrying rate, threat actors are reinvesting and becoming more organized, expanding operations by outsourcing and further developing their understanding of AI to launch more successful attacks.

Hintikka concluded that, looking at the cybersecurity landscape ahead, "This will be a game of good AI versus bad AI."



via Hosting & Support

Comments

Popular posts from this blog

Windows 10 update is causing lots of problems – including nasty crashes

Web Hosting & Remote IT Support Windows 10 users are suffering at the hands of some fresh bugs introduced by the latest update for the OS from Microsoft. That would be KB5026361, the cumulative update for Windows 10 for May, which was released a couple of weeks back, and appears to be causing a bunch of glitches and more serious problems. In the serious category we can file some Reddit users who are complaining on two counts of the patch ‘bricking’ their PC, and also reports of Blue Screen of Death (BSoD) crashes post-update. Some of those BSoDs offer up an error that reads ‘Process1 Initialization Failed’ and as Neowin , which spotted this, explains, this seemingly occurs due to the Bootcat.cache file becoming corrupted (or its size having changed since the last time the PC booted). Other Windows 10 users are encountering a problem that’ll sound familiar, no doubt – the failure to install the update, often accompanied with a meaningless error code (such as ‘0x800f0922’ whi...

Google Dork: Find Linux Servers with the /etc/config Directory Shared & ...