Large language models (LLMs) that power tools can be exploited to develop malware capable of bypassing YARA rules and carrying out cyberattacks.
See also: What are the most common cyberattacks in recent years?

Recorded Future reported in a report shared with The Hacker News that Genetic Artificial Intelligence can be used to circumvent YARA's string-based rules, effectively reducing detection rates.
The findings come from a red teaming exercise, which was designed to uncover malicious uses of AI technologies, which are already being used by malicious actors to create malware snippets, create phishing , and carry out cyberattacks.
The cybersecurity firm said it provided an LLM with a recognized piece of malware known as STEELHOOK , which is associated with the APT28. Under YARA rules, the firm asked LLM to adapt the source code in a way that would bypass detection, ensuring that the original functionality remains intact and the resulting source code is free of bugs.
Equipped with this feedback mechanism, the modified malware created by LLM was able to evade detection for simple string-based YARA rules.
There are limitations to this approach, the most obvious being the amount of text a model can process as input at a time, which makes it difficult to operate on larger code bases.
See also: Educational sector: Cyberattacks and ways to protect
In addition to modifying malware to go unnoticed, such AI tools could be used to create deepfakes that impersonate senior managers and leaders and to conduct cyberattacks that mimic large-scale legitimate websites.

Furthermore, it is expected that genetic artificial intelligence will accelerate the ability of perpetrators to conduct reconnaissance of critical infrastructure facilities and obtain information that could be crucial for future attacks.
Indeed, last month Microsoft and OpenAI warned that APT28 used LLMs to “understand satellite communication protocols, radar image technologies, and specific technical parameters,” indicating efforts to “gain deeper knowledge about satellite capabilities.”
Organizations are advised to review publicly accessible images and videos depicting sensitive equipment and de-mutilate them, if necessary, in order to reduce the risks posed by such threats.
See also: Telecommunications companies: Cyberattacks and ways to protect
What are the techniques for preventing cyberattacks?
One of the key techniques for preventing AI cyberattacks is staff training. Users should be aware of the risks and tactics used by attackers, such as phishing and malware. Installing and updating antivirus software is another important technique, as it provides a first line of defense against the most common forms of cyberattacks. Using firewalls and other security systems can help protect systems from intruders. These tools can control incoming and outgoing traffic and block intrusion attempts. Finally, regularly backing up important data is crucial.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: thehackernews
