The record
Written from the 1 report below. Nothing here is unsourced.
- The malware operates by querying AI models to decide which malicious task to perform rather than receiving instructions from a central server.
- It specifically targets Windows credentials, browser passwords, and cryptocurrency wallets.
- Attackers use Discord webhooks to monitor the decisions made by the AI and to exfiltrate stolen data.
- This approach marks a novel development in how malware leverages AI services for command-and-control operations.
What to watch next
- Ongoing development of AI-assisted malware C2 mechanisms.
- Further analysis of how attackers might bypass AI service safety filters.
- Adoption of TLS inspection by defenders to detect malicious AI service prompts.
Coverage1
1 report
English national1
All filed from India
Named Ukraine · United States · DeepSeek · Discord · Google · Mistral · Qwen · CAIRN · CERT-UA · Cisco Talos · CLOSEDQUORUM · LAMEHUG
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
