Skip to content

The ‘first’ AI-run ransomware attack still needed a human

Previously, scientists at cloud security company Sysdig reported the initial recorded instance of “agentic ransomware,” according to reports from last week. It was an operation known as JadePuffer, which entailed the execution of a genuine cyberattack from inception to conclusion, with a machine, as opposed to a person, managing the technological aspects. An intruder compromised a weak server, obtained login details, navigated the target’s network, encrypted documents, and composed a ransom message, adjusting to hurdles as a skilled hacker would. The text stated that the financing operated without any supervision by humans, implying that no person was controlling it. The provided statement isn’t entirely accurate. During a CyberScoop interview on Monday, Michael Clark, Sysdig’s senior director of threat research, emphasized that while a human’s involvement was still present, it did not involve the technical aspects of the process. “An individual established and directed the procedure, and equipped the necessary infrastructure, including the command-and-control server, the staging server for the pilfered data, and selected a target, as per Clark’s statement.” The credentials that were used to gain access to the victim’s database, he stated, were not collected by the AI agent itself; instead, someone else had obtained them through a previous security breach and provided them to the operation. This does not conflict with Sysdig’s initial statement, and the technical aspects of the attack are still impressive – even extraordinary.

 Read More

Leave a Reply

Your email address will not be published. Required fields are marked *