HomeSecurityAutonomous AI ransomware attacks are coming

Autonomous AI ransomware attacks are coming

Creating a proof-of-concept artificial intelligence prototype that can autonomously build and execute AI ransomware attacks from scratch shouldn't worry prepared CISOs, an expert says.

Defending against autonomous AI ransomware attacks, said Taylor Grossman, director of cybersecurity at the Institute for Security and Technology (IST), is simple: “Basic cyber-defense practices.”

See also: Pennsylvania Attorney General's Office hit by ransomware attack

AI ransomware attacks
Autonomous AI ransomware attacks are coming

Commenting on the uproar last week when security researchers at New York University published a paper claiming to have created a ransomware prototype orchestrated by a large language model (LLM), they said: “Unlike conventional malware, the prototype requires only natural language commands embedded in the binary. The malicious code is dynamically synthesized by the LLM at runtime, producing polymorphic variants that adapt to the execution environment. The system performs identification, payload creation, and personalized extortion, in a closed attack campaign without human intervention.”

They called this next generation of malware Ransomware 3.0. Security provider ESET, which spotted traces of their work via VirusTotal, called it “the first known ransomware with artificial intelligence,” before clarifying that NYU’s discovery is a proof-of-concept prototype and not an active one. Nevertheless, several IT news outlets picked up on ESET’s report, treating it as an active attack.

The NYU research should have been expected. After all, several security vendors have long predicted that malicious actors would try to leverage artificial intelligence to create malware.

See also: Storm-0501: New ransomware attacks targeting the cloud

Autonomous AI ransomware attacks are coming
Autonomous AI ransomware attacks are coming

Grossman’s work at IST includes supporting the Ransomware Working Group, which has produced guidance for IT professionals on combating ransomware. She stopped short of describing the NYU proof-of-concept as alarming. Instead, she suggested it was to be expected. So far, it’s only working in a university lab environment, she noted, but she has no doubt that autonomous AI ransomware attacks generated by a malicious actor are coming. She’s more interested in the fact that such a tool would make it easier for less technically-savvy people to get into the ransomware game.

Joseph Steinberg, a cybersecurity and artificial intelligence expert based in the US, was also not surprised by the research. “While the people at NYU produced a proof-of-concept,” he said in an email to CSO, “it’s entirely possible that the criminals got ahead of them. I’ve already seen AI that can scan, write malware, identify which resources are most valuable, etc. It’s not surprising that someone found a way to automate such functions with AI.”

See also: Australian Authorities Uncover Ransomware Groups

Autonomous AI ransomware attacks are coming
Autonomous AI ransomware attacks are coming

Grossman advised CISOs to continue implementing security controls under frameworks created by the Center for Internet Security or the U.S. National Institute of Standards and Technology (NIST). “It’s unlikely at this point that we’ll see a change in the ransomware model” from an autonomous ransomware attack tool created by artificial intelligence, she said. “This is a good opportunity to remind people that while the NYU study may be scary in many ways, there’s a lot that can be done that organizations aren’t prioritizing. The tools are out there, and we need to be more aware of what can be done.”

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS