HomeSecurityMalicious PowerShell that pushes malware appears to be written with AI

Malicious PowerShell that pushes malware appears to be written with AI

A threat actor uses a malicious PowerShell script, likely created with the help of an AI system like ChatGPT , Gemini , or Microsoft's CoPilot, to push malware.

See also: Microsoft: Windows 10 WinRE update with BitLocker fixes

PowerShell malware AI

The malicious user used the script in an email campaign in March, targeting dozens of organizations in Germany to spread the Rhadamanthys malware .

AI-powered PowerShell develops infostealer

Researchers at cybersecurity firm Proofpoint attributed the attack to a malicious actor tracked as TA547, believed to be an initial access broker (IAB).

TA547, also known as Scully Spider, has been active since at least 2017, delivering a variety of malware for Windows (ZLoader/Terdot, Gootkit, Ursnif, Corebot, Panda Banker, Atmos) and Android (Mazar Bot, Red Alert) systems.

Recently, the malicious actor began using the modular stealer Rhadamanthys malware, which it promotes via a PowerShell AI, which is constantly expanding its data collection capabilities (cache, browser, cookies).

Proofpoint has been tracking TA547 since 2017 and said this campaign was the first where the threat actor was observed using Rhadamanthys malware.

See also: DEEP#GOSU malware campaign targets Windows users

The info stealer has been distributed since September 2022 to multiple cybercrime groups under the malware-as-a-service (MaaS).

Malicious PowerShell that pushes malware appears to be written with AI

According to researchers at Proofpoint, TA547 impersonated German cash-and-carry brand Metro in a recent phishing using invoices as a lure for “dozens of organizations across various industries in Germany.”

The messages included a password-protected ZIP file “MAR26,” which contained a malicious shortcut file (.LNK). Accessing the shortcut file enabled AI PowerShell to remotely execute the malware.

The researchers explain that this method allowed the malicious code to execute in memory without touching the disk. The researchers also note that these features are typical of code originating from production AI solutions such as ChatGPT, Gemini, or CoPilot.

While they cannot be absolutely certain that the PowerShell code came from a large language model (LLM) solution, the researchers say that the script content suggests the potential for TA547 to use genetic artificial intelligence to compose or rewrite the PowerShell script.

See also: FBI: More information on AvosLocker ransomware and protection tips

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

What are the techniques for protecting against malware?

One of the most effective ways to protect against malware, such as the AI-generated PowerShell malware, is to use reliable security software. This should include a strong firewall and be able to detect and remove malware. Regularly updating your operating system and applications is another important protection technique. Updates often include security patches that can help protect your system from malware. Using strong and unique passwords is also critical to protecting against malware. Information security training can help you recognize and avoid phishing scams, which are a common method of distributing malware.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS