Cyber Security Ventures

AI Agent Carried Out A Ransomware Attack Without Any Human Oversight


“This wasn’t someone behind the keyboard using AI as a tool to write malware,” says Heather Engel, guest expert on the Cybercrime Magazine Podcast. “The agent was given a target, identified vulnerabilities, chose its own methods, and deployed the attack with zero human intervention from start to finish. The AI was acting as it own threat actor, which really pushes us into a new territory for cybersecurity.”

Engel is talking about an AI agent that recently carried out a cyberattack without any human oversight for the first time, according to a story in The Independent.

The AI-powered attack marks a major milestone for both AI and cybersecurity, raising concerns that AI is lowering the barrier for cybercriminals. The fully automated campaign involved an AI agent launching a ransomware attack, where victims are forced to pay a ransom in order to regain access to their data.

A team from cloud security firm Sysdig said the AI attacker, which they named JADEPUFFER, broke into a vulnerable server, discovered passwords and login credentials, and then encrypted a production database before demanding a bitcoin ransom.

“Ransomware has had a human at the keyboard, or at least a human writing its script, since it was first established as a category of threat,” Michael Clark, director of threat research at Sysdig, wrote in a blog post.

Amanda Glassner, deputy Editor at Cybercrime Magazine, asked Engel: “Do you think we’re at the point where we need AI to fight AI?”

Listen to the Podcast episode



Source link