The groundbreaking keylogging attack “BlackMamba”, which leverages Artificial Intelligence, is able to bypass the protection of even the most advanced Endpoint Detection and Response (EDR) security solutions.
See also: Akamai successfully thwarted a massive 900Gbps DDoS attack

An AI-powered cyberattack that dynamically changes its code can evade the most advanced automated security detection frameworks, demonstrating the ability to create unstoppable malware.
Researchers from HYAS Labs demonstrated a proof-of-concept attack, which they call BlackMamba, which exploits a large language model (LLM) — the technology behind ChatGPT — to compose a polymorphic keylogger function. The attack is “truly polymorphic” because each time BlackMamba executes, it recomposes its keylogging capability, the researchers wrote.
The BlackMamba attack demonstrates how artificial intelligence can give malware the ability to modify benign code while running without a command and control (C2) infrastructure. This allows it to bypass existing automated security systems that are trained to detect such activity and identify attacks.
See also: Blackbaud fined for concealing full extent of ransomware attack
After running their attack against a leading EDR system, they discovered that it typically produced zero alerts or detections – a remarkable feat.
Using its native keylogging functionality, BlackMamba has the ability to record and collect confidential information from any device – including usernames, passwords and credit card numbers. Once this stolen data is retrieved by the malware, it will be sent directly to a malicious Teams channel via a trusted collaboration platform, such as Microsoft Teams. Attackers can use this sensitive data for their own criminal purposes: sell it on dark web or use it in more attacks, according to researchers at HYAS Labs.
Additionally, since BlackMamba is based on an open-source Python package, developers can easily port Python scripts to individual executable files that are compatible with Windows, macOS , and Linux.

What does this mean for modern security?
As cybercriminals perfect the use of polymorphic malware, incorporating cutting-edge technologies like ChatGPT and LLM into their insidious designs, the threat landscape is changing. Security teams must now prepare for this new era of AI attacks by ensuring that automated security technology can evolve to address these increasingly sophisticated threats.
Organizations that use EDR and other automated security tools as part of their modernized security stack assume they are doing everything they can to detect and prevent malicious activity. However, with the development of artificial intelligence, it is now being proven that they are “not infallible,” say researchers at HYAS Labs.
See also: Cerebral shared patient data with Meta, Google, TikTok
As AI-based attacks become increasingly sophisticated, the existing security landscape must adapt to fend them off. To ensure your organization is properly secured against future threats, it is vital to remain vigilant and keep up with current research on cybersecurity measures. Operational implementation of cutting-edge techniques will serve as a key layer of defense for any business facing this increased level of threat.
Source of information: darkreading.com
