Home AIA sneaky hacking tool targeting AI infrastructure lurks in victims’ blind spots

A sneaky hacking tool targeting AI infrastructure lurks in victims’ blind spots

by OmarAli
A sneaky hacking tool targeting AI infrastructure lurks in victims' blind spots

As AI tools become more widespread and deeply embedded in software development worldwide, new research from cybersecurity firm CrowdStrike shows how attackers are actively targeting the AI ​​toolchain to steal credentials, gain deeper access to a target environment, exfiltrate sensitive data, and even destroy target files and systems – all while finding new ways to cover their tracks.

Researchers discovered a worm in the wild while investigating attacks on the AI ​​software supply chain. Adam Meyers, senior vice president of counter adversary work at CrowdStrike, says the company has not yet attributed the activity to a specific actor, but that it fits into larger developments as attackers like TeamPCP (which CrowdStrike calls the “Altered Spider”) and North Korean groups target the AI ​​software supply chain.

“This is one of the campaigns we’ve seen that shows this is a new class of attack,” Meyers tells WIRED. “As AI programming agents become the development standard, supply chain threats are evolving to exploit these trust relationships. For the first time, we are seeing how much of a role AI and the AI ​​toolchain have played in the broader technology ecosystem.”

The worm identified by CrowdStrike works in phases. First, reconnaissance is conducted to assess the target environment. It then looks for access tokens and other sensitive data such as cryptographic keys and server credentials that it can pass on to attackers. As the malware gains privileges, it continues to unpack and grab credentials, particularly “npm” tokens, which provide access to key software package management servers and other development functions such as pull requests.

The deeper the malware penetrates the system, the more sensitive data it can capture. At this point, the malware can also use its destructive capability, or what Meyers calls a “death switch,” to destroy files or block legitimate access to the compromised infrastructure.

The key takeaway, however, is that much of the worm’s malicious activity essentially occurs in blind spots, as much of its behavior mimics legitimate actions. “It’s like a needle in a haystack, except this is a needle in a stack of needles,” Meyers says. “This is very similar to the automation that many organizations use to create code, so it is very difficult to detect.”

Meyers also adds that in these AI software development pipelines, it is more difficult to collect the data points that security scanners and analytics tools traditionally use to detect potentially suspicious activity.

“There is a lot of telemetry overlap because legitimate AI coding systems work the same way as this worm, so it becomes very difficult to distinguish what is legitimate and what is illegitimate based on the telemetry available to you,” says Meyers.

To make it even more insidious, the worm’s authors have incorporated time delays where various functions are executed hours or even days after the groundbreaking, making it even more difficult for defenders to determine the cause and effect of certain events that lead to certain outcomes.

Meyers says CrowdStrike has been working on strategies to connect more dots, but emphasizes that with the explosion in AI software development, there is an urgent need for all stakeholders to collaborate on structural solutions.

“It’s a limited detection area because only a limited portion of that activity actually produces a telemetry signal that we can look at,” Meyers says, “so it becomes extremely laborious to determine what is legitimate behavior and what is illegitimate behavior.”

https://www.wired.com/story/a-sneaky-hacking-tool-targeting-ai-infrastructure-is-lurking-in-victims-blind-spots/

Viral Trends

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More