Hello From the Dumpster Fire: Real Examples of Artificially Generated Malware, Disinformation and Scam Campaigns

No ratings

Presented at SecTor 2024 by

All technological developments, even when they're made with the best of intentions, have two sides — the side that can be used for good, and the side that can be maliciously exploited. The capabilities of artificial intelligence (AI) tools and large language models (LLMs) when it comes to features such as real-time spoken conversations, text and "vision," real-time translation, and memory capabilities are astounding, and have a wealth of legitimate uses. But also: these tools are available to anyone, and this includes malicious actors. The growth of these tools means that the barrier to detection is going to rise significantly, leaving many people (both the luddites and the tech-savvy) susceptible to becoming victims. In all likelihood, while technology companies clamber to come out on top of the AI renaissance, romance and pig butchering scams will continue to soar past already unprecedented rates, political disinformation will become harder to spot, and more and more threat actors will be able to write code with little to no technical expertise or background.This presentation will provide a brief overview of the current state of AI before we dive into showcasing real examples of malicious use of generative AI in various types of cyber campaigns, to include: malware development, disinformation and scam campaigns. Our real examples will showcase a combination of legitimate and illicit AI tools, with the aim of providing insight into the various tactics, techniques and procedures leveraged by malicious actors. The talk will conclude with coverage on the importance of content provenance and methods for detecting artificially generated content.