Automatically translated.View original post

A new virus with AI-powered 🚨

Google Threat Intelligence Group, or GTIG, has revealed a new report that talks about major changes in cyberspace because hackers now no longer use AI, just to help them work or write code, but to put AI in malware to "think and adapt themselves" during real attacks. It's called a new era of cyber warfare where attack tools can learn and evade detection on their own.

.

Newer malware found by Google, such as PROMPTFLUX and PROMPTSTEAL, uses a large language model or LLM during work to reconstruct dangerous scripts every time PROMPTFLUX runs. It is written in VBScript and can send commands to Gemini's API to help rewrite complex and self-encrypted code to dodge antiviruses. PROMPTSTEAL was used by the Russian APT28 group in an attack on Ukraine. It fakes an image and uses the Qwen model to create commands that steal local data without pre-written code.

.

Interestingly, some hackers are starting to use Social Engineering and AI techniques to trick models into writing dangerous code, using seemingly experimental or educational excuses, such as pretending to be a Capture-the-Flag contestant to get Gemini to introduce vulnerabilities, or quoting as a student completing a project to ask AI to write code. All this reflects that hackers are no longer just fooling people, but are also fooling AI.

.

The report also says that the black market of AI tools for attack is also growing dramatically by 2025. There are tool sales services like WormGPT, FraudGPT and LoopGPT that help do everything from write phishing emails, create malware, to find system vulnerabilities.

.

This makes it even easier for novice hackers to launch more sophisticated attacks. Meanwhile, state-sponsored groups such as North Korea, China and Iran use these AI at every stage of their attacks, from finding information, preparing fisching, to developing control servers and stealing data.

.

To counter this situation, Google has closed accounts and projects related to the ill-fated, improving the Gemini model and preventing abuse, as well as collaborating with the DeepMind team to develop tools like Big Sleep and CodeMender that use AI to automatically detect and repair vulnerabilities. The goal is to create an AI that is both advanced and secure so that humans can use technology responsibly in an era when AI is both a weapon and an armor at the same time.

.

Source: Google

# IT News # Includes IT matters # Cough to know # IT

2025/11/14 Edited to

... Read moreจากภาพและเนื้อหาที่พูดถึง แนวคิดของ "Skynet AI" ในมัลแวร์หมายถึงระบบที่สามารถคิดและปรับเปลี่ยนโค้ดของตัวเองได้แบบอัตโนมัติ โดยไม่ต้องอาศัยคำสั่งจากมนุษย์ การที่ AI มีบทบาทสำคัญในกระบวนการโจมตีทำให้มัลแวร์เหล่านี้สามารถเรียนรู้วิธีการหลบหลีกการตรวจจับของระบบแอนติไวรัสได้อย่างชาญฉลาด ประสบการณ์จากหลายแหล่งข่าวและนักวิเคราะห์ด้านความปลอดภัยไซเบอร์ชี้ว่าเทคโนโลยี AI ที่แฮกเกอร์ใช้ในตอนนี้ก้าวไปไกลกว่าที่คาดการณ์ไว้มาก การใช้โมเดลภาษาขนาดใหญ่ (LLM) อย่าง Gemini หรือ Qwen ในการสร้างสคริปต์แบบไดนามิก การเข้ารหัสตัวเอง หรือแม้กระทั่งการสร้างคำสั่งโดยไม่มีการเตรียมโค้ดล่วงหน้านั้น ถือเป็นความท้าทายใหม่สำหรับนักป้องกันข้อมูล ในฐานะผู้ใช้อินเทอร์เน็ตและเทคโนโลยี เราควรตระหนักถึงความเสี่ยงนี้และปฏิบัติตามมาตรการรักษาความปลอดภัยอย่างเข้มงวด เช่น การอัพเดตระบบและซอฟต์แวร์อย่างสม่ำเสมอ การใช้ระบบป้องกันที่มีความสามารถตรวจจับพฤติกรรมผิดปกติ และเรียนรู้เรื่องข่าวสารเกี่ยวกับเทคโนโลยีใหม่ ๆ ที่เกี่ยวข้อง นอกจากนี้ การรับรู้และเข้าใจวิธีการที่แฮกเกอร์ใช้ประโยชน์จาก AI เพื่อโจมตียังช่วยให้เรารับมือกับภัยคุกคามในยุคที่เทคโนโลยีสามารถกลายเป็นทั้งเครื่องมือสร้างสรรค์และอาวุธไปพร้อมกันได้อย่างมีประสิทธิภาพ