Get Ready for the First Wave of AI Malware

Stu Sjouwerman | Apr 10, 2019
Gunter_Ollmann

This is an excerpt from an article in SecurityWeek by Gunter Ollmann, who is currently the CSO of Microsoft’s Cloud and AI Security division. He is a seasoned information security leader.

With the proliferation of artificial intelligence (AI) technology shaping the digital world at an increasing pace, Gunter Ollmann expects that the first examples of AI-driven malware will emerge in the next two to three years. He outlines 6 different capabilities of AI malware that should be relatively easy to develop:

  1. Automated compromise of systems and networks that does not require frequent communications between the malware and the  command-and-control (C&C) server of the attacker.
  2. Identification of the most valuable data on compromised systems through data labeling and classification, which will involve machine learning (ML).
  3. Employment of conversational AI to participate in email and chat communications on compromised devices while masquerading as targeted users in order to socially engineer coworkers of victims.
  4. Use of AI-driven speech to text translation in order to capture valuable information from the environment that can be recorded with the microphone of a compromised machine.
  5. Use of embedded cognitive AI in order to determine various characteristics of victims and deploy payloads only if victims meet certain criteria.
  6. Creation of a “bio-profile” of users based on their behavioral characteristics in order to bypass advanced behavioral monitoring systems.

Read more: Get Ready for the First Wave of AI Malware

 

Topics: Malware

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.