The Anatomy of a Next-level Phishing Attack with AI

By Frederic Farcy, President and CIO, TNTMAX, LLC

Why is it so important to understand the impact of AI and what happens when it is used against us by “Hackers”? This new level of cyberthreats is better, more difficult to recognize and lethal! In the article \”Hackers Obfuscated Malware With Verbose AI Code\” from Data Breach Today, we see how bad actors (Hackers) used AI to obfuscate the content of the malware, so it was more difficult for security control tools (Antivirus, Malware Detection, Ransom Ware Detection, EDR, XDR) to detect the attacks. In this post we will explain and break down the attack so that our readers can be educated and better prepared for the next wave of cyberattacks that are on the way.

Below is an explanation of what is taking place using the article. This is what you must watch out for. Learning about it is one of the best tools to try  to stay ahead of cyber threats.

STEP1 – Hacker hides the malicious payload, like in a trojan horse. This this case, the Hacker used AI to Hide Malware Payload. Hacker hid the malicious code by obfuscating (obfuscating is to be evasive, unclear, or confusing) in excessively large useless code that allow the malware to remain hidden and bypass technical controls used to detect such attacks. The code, once analyzed, was attributed to AI.

STEP 2 – Hacker uses email manipulation to hide themselves in the email header. The report says the attackers used a “self-address” trick – meaning the email’s From and To fields showed the same address, while the real intended recipients were placed in the BCC field. In other words, the visible headers made the message look like it was from (and to) the same person, but hidden recipients were actually getting the message.

STEP 3 – Hacker payloads the bad stuff. The payload contains a file-sharing notification look-a-like, with attachments named \”23mb – PDF- 6 pages.svg\” designed to appear as legitimate PDF documents. However, it uses a SVG (Scalable Vector Graphics) extension. SVG files are generally safe, but a hacker can embed bad scripts.

You can not only depend on technical security controls to ensure your business’ safety online today. This is a must, but we need to do more. At  TNTMAX, we implement defense in depth, with multiple layers of defense making bad actors’ job more difficult, but we need our clients to perform cybersecurity awareness training on a yearly basis so they can also assist us in minimizing cybersecurity threats. You must go the extra step and educate yourself on the latest threat techniques and what you need to avoid doing. In this case, not clicking on the attachment is the defense against that attack.

Stop, think and verify before clicking on anything.

more News