Threat Actors Leverage AI Tools for Enhanced Malware Capabilities
The Google Threat Intelligence Group (GTIG) has identified a significant shift in the threat landscape, with adversaries increasingly utilizing artificial intelligence (AI) tools to enhance their malware capabilities. This marks a new operational phase of AI abuse, involving the use of novel AI-enabled malware in active operations. The threat actors are no longer limited to using AI for productivity gains but are now deploying AI-enabled malware that can dynamically alter its behavior mid-execution. The scale of impact is substantial, with government-backed threat actors and cyber criminals integrating and experimenting with AI across the industry throughout the entire attack lifecycle. The affected parties include various organizations and individuals who are vulnerable to these advanced threats.
The technical explanation of the attack vector involves the use of Large Language Models (LLMs) during malware execution. Malware families such as PROMPTFLUX and PROMPTSTEAL use LLMs to dynamically generate malicious scripts, obfuscate their own code to evade detection, and leverage AI models to create malicious functions on demand. The delivery method involves the use of social engineering-like pretexts to bypass AI safety guardrails. The exploitation chain includes the use of AI tools to support phishing, malware development, and vulnerability research, lowering the barrier to entry for less sophisticated actors. The underground marketplace for illicit AI tools has matured, providing threat actors with access to multifunctional tools designed to enhance their operations.
The strategic implications of this threat are significant, with state-sponsored actors and cyber criminals continuing to misuse AI to enhance all stages of their operations. The current exploitation status indicates that these threats are actively being used in the wild, with various organizations and individuals being targeted. The recommendations include the need for organizations to develop AI responsibly and take proactive steps to disrupt malicious activity. This can be achieved by disabling projects and accounts associated with bad actors, continuously improving models to make them less susceptible to misuse, and proactively sharing industry best practices to arm defenders and enable stronger protections across the ecosystem.
Attack Surface
Endpoint, Web Application
Tactics
Initial Access, Execution, Privilege Escalation, Defense Evasion
Techniques
- T1204 – User Execution
- T1055 – Process Injection
- T1005 – Data from Local System
SuperPRO's Threat Countermeasures Procedures
- Implement robust security measures to detect and prevent AI-enabled malware
- Develop AI responsibly and take proactive steps to disrupt malicious activity
- Continuously improve models to make them less susceptible to misuse
- Proactively share industry best practices to arm defenders and enable stronger protections across the ecosystem
- Use threat intelligence to stay informed about the latest threats and trends
- Implement a defense-in-depth approach to protect against various types of threats
- Regularly update and patch systems to prevent exploitation of known vulnerabilities