A report shows how criminal actors are lowering the barriers to entry with sophisticated services, without ethical constraints.
Criminal actors are offering a range of AI-powered hacking tools and related services for sale on underground forums on the dark web,<a href="https://www.trellix.com/blogs/research/weaponized-ai-commoditization-of-cybercrime/” rel=”nofollow noopener” target=”_blank”>according to a report released Wednesdayby cybersecurity firm Trellix.
Researchers found a wide range of AI-based tools being sold through these markets, ranging from reconnaissance tools to credential markets, as well as AI-as-a-service platforms.
The report shows how AI is being monetized to lower the barriers of entry into sophisticated threat activity.
Some of the major services and hacking tools being offered include the following:
- An actor known as Shadowx007 is offering a service called APEX AI, a tool that provides nation-state-level attack planning capabilities. After inputting a target domain, the service provides a complete attack plan to enable ransomware deployment, including step-by-step commands.
- A threat actor known as ImpactSolutions is offering Metamorphic Crypter, a commercial cryptic service. The service, sold on the Exploit forum, is designed to help attackers bypass any signature-based detection technology. The actor claims the service cannot be detected by Windows Defender and most other antivirus products.
- A service called MessiahGPT is being offered on BreachForums. The service claims to be an AI model that includes zero ethical constraints, unlike many of the leading commercial models in the U.S.
Trellix researchers said AI drastically lowers the amount of technical expertise needed for a hacker to launch a successful attack.
“Traditionally, hacking required a deep, manual understanding of how network defenses interact with an exploit,” Jambul Tologonov, security researcher at Trellix, said. “You had to chain vulnerabilities yourself, which required a high level of specialized human knowledge.”
An early-stage hacker can now take a tool like APEX AI and execute the same attack with only a single prompt.
“Someone who wouldn’t know where to begin in a pen test can now get a prioritized attack plan that mirrors [Advanced Persistent Threat actor]-grade tradecraft,” Tologonov said.
MessiahGPT, which is referenced in the Trellix report, was also used by hackers cited by Accenture and Google Cloud, in a presentation earlier this month at Black Hat.
In July, MessiahGPT was advertised in an English-language forum on the dark web, according to researchers at Accenture and Google Cloud. The service was touted as being able to generate exploits, payloads, proof-of-concept code as well as writing and refactoring malware.
Prompt injection
Aseparate report by researchersat Proofpoint showed indirect prompt injection tools designed to manipulate AI agents. Because malicious commands are hidden, the AI interprets the commands as legitimate and executes the commands as if they were part of the correct decision-making process.
The prompts are embedded in PDFs, emails, web pages and calendar invites and are being offered on underground forums for $150 per month.
AI agents at the user level, such as with an employee-deployed agent that processes emails or summarizes calendar invites, could be vulnerable to such an attack.
“If the agent falls for the indirect prompt injection, the adversary could potentially exfiltrate information from the user, steal credentials, or deploy malware on the user’s device,” said Yaniv Miron, director of threat research at Proofpoint.
Activity for now involves attackers exploring and testing which has not yet found evidence of specific attacks based on exploiting these tools
Palo Alto Networkspreviously highlighted howLLMs are processing these malicious requests.
Editor’s note: Updates with additional comment from Trellix, Accenture and Proofpoint.
