هجمات الذكاء الاصطناعي السيبرانية

Warnings over hackers employing artificial intelligence technologies

Written by

Picture of فريقنا

فريقنا

Communications Consultant

Microsoft has revealed that hackers are relying heavily on artificial intelligence to create fake identities and develop malware. The company called on organizations to strengthen defense systems against evolving threats that lower the technical barriers to breaches.

The software giant and leading computing pioneer Microsoft has issued a highly detailed and concerning report this week on security and cyber threat intelligence, revealing conclusively and with data support that professional cybercriminals and organized network hackers are now increasingly and systematically integrating and exploiting advanced generative artificial intelligence technologies in every stage of their disruptive and breaching operations. This malicious use is not limited to a single step or a simple tool; rather, it extends in a logical sequence starting from initial reconnaissance of target networks, gathering precise information, customized and convincing phishing messages, all the way to developing and programming advanced malware, establishing and securing hidden persistence within systems, and executing dangerous post-breach activities aimed at data theft or financial extortion of major corporations. The tech giant described this modern technology and artificial intelligence in its lengthy report as operating as an exceptional and frightening “force multiplier,” as it reduces and lowers complex technical access barriers and vastly accelerates the pace and rate of execution and attacks for attackers with varying levels of skill and expertise, meaning fewer hackers are capable of causing widespread destruction far beyond what was possible in the very recent past.

North Korean groups and the development of advanced breach tactics

The security report details with notable precision and extensiveness how seasoned cyber threat groups backed directly by the North Korean government—tracked and monitored by agencies under codenames such as “Jasper Sleet” and “Coral Sleet”—are using complex generative AI tools and generators to run and support highly elaborate fake job scam schemes aimed at breaching and stealing from high-value Western companies and institutions. The cunning and trained operatives of the Jasper Sleet group use available AI tools to generate name lists that culturally fit the target community, skillfully craft and design fake resumes to match specific and important job postings, and compose flawless professional communications to maintain their fake jobs and secure their income and long-term remote presence once hired and accepted as undercover spies within those sensitive companies, based on reports by the specialized and trusted site “Cyberscope”.

Exploiting advanced spoofing techniques for impersonation and identity theft

Microsoft’s security teams tracked and documented the Jasper Sleet hacking group using the popular AI application and program “FaceSwap” for digital face swapping, aiming to skillfully and undetectably graft the faces of North Korean IT workers onto stolen identity documents of real people to create polished, professional, and convincing profile pictures used to boost the credibility of fake resumes attached to job applications. This dangerous criminal group also deployed real-time voice-changing technology during virtual video interviews to mask their true original accents, enabling these undercover operatives to impersonate different individuals and project high confidence and professionalism as legitimate Western candidates to gain employee-level access and establish a foothold in target companies, according to a detailed and concerning report published by the prominent British newspaper The Guardian. Microsoft stated in its release: “Jasper Sleet uses AI throughout the entire attack lifecycle to secure employment, maintain the acquired job, and exploit granted access on a very wide scale.”

Rapid and alarming software development and bypassing strong security barriers

Meanwhile, on a parallel threat trajectory, another monitored hacker group known as Coral Sleet demonstrated what Microsoft described in its assessment as “rapid and significant capability growth driven by AI-assisted iterative development.” This organized and active group used modern AI-powered coding and programming tools to continuously create, optimize, and update malicious software components, generate fake corporate websites to trap and deceive victims, build secured remote control digital infrastructure, and conduct very rapid and effective tests on payloads and malware before deployment to uncover and resolve weaknesses. Furthermore, and more alarmingly, the seasoned group jailbroke and bypassed strict restrictions and controls imposed on popular large language models to force them to generate and write malicious code capable of skillfully bypassing embedded safety and security controls, according to Microsoft’s official advisory blog post.

A concerning and accelerating cyber phenomenon across the major tech industry

Microsoft explicitly noted in its report early and highly concerning trials and tests by threat actors and hackers to use agentic and autonomous artificial intelligence, where automated models make iterative decisions independently and execute long disruptive tasks without direct human direction or intervention, although this level of total autonomy has not yet been observed spreading widely in the wild. These alarming, evidence-backed findings echo and mirror similar warnings issued and shared by other major technology companies operating in the sector. Tech giant Google reported last February that it observed threat actors using AI to gather critical information, develop and create tight phishing campaigns, and build malware. Separately, leading company Amazon documented a fierce offensive campaign where a single Russian-speaking attacker used modern generative services to breach and bypass more than 600 FortiGate network firewalls deployed across 55 different countries worldwide within a brief period of just five weeks, demonstrating and proving to everyone how advanced AI enabled an attacker with relatively limited skills to operate and execute massive attacks on a scale that in the recent past would have required a large, qualified, and highly competent team to achieve.

Microsoft’s strategic recommendations for protection, defense, and vulnerability patching

In light of these serious, accelerating, and deeply concerning developments that clearly and undeniably proved how AI empowered attackers to cause widespread destruction and bypass traditional defenses, Microsoft advised all global organizations and security-concerned companies to take proactive and strict measures. The tech giant demanded that AI-backed fake IT worker schemes be treated immediately as severe internal security threats that must be rooted out and handled with the highest degree of caution. It urged an intensive focus on detecting and identifying unusual and suspicious credential and network access usage, strengthening and securing digital identity and authentication systems strictly against increasingly sophisticated phishing attacks, and securing and protecting companies’ own internal AI systems and machine learning models, which can easily become prime, valuable, and direct targets for hackers seeking theft and extortion.

Frequently asked questions

Question: How do hackers and cybercriminals employ artificial intelligence in their attacks today according to the report?

Answer: They integrate and exploit it heavily across all stages of breach and attack, such as generating complex phishing messages, developing and encrypting viruses rapidly to bypass protection, and faking identities to impersonate potential and qualified insider employees at major Western companies.

Question: What does the dangerous North Korean group Jasper Sleet use for camouflage and deception in job interviews?

Answer: They use advanced face-swapping applications like FaceSwap to graft their faces onto stolen and forged identity documents, and they skillfully use real-time voice modification technologies during virtual video interviews to conceal their true accents and pose as Western candidates.

Question: How did the use of artificial intelligence help multiply and amplify cyberattack power and resulting damages?

Answer: It significantly reduced the need for high programming skills and advanced expertise, allowing attackers with limited technical skills to execute and coordinate destructive attacks on a wide global scale in record time compared to what was previously required from large working teams.

Question: What are the primary defensive and preventive measures Microsoft advises major organizations to take?

Answer: It advises companies to treat fake hiring seriously and strictly as a severe internal security threat, immediately focus on monitoring unusual and suspicious network and login account activities, and fortify and strengthen identity verification systems while protecting internal models from compromise.

شارك هذا الموضوع:

شارك هذا الموضوع:

اترك رد

Leave a Reply

الفئات

المنشورات الأخيرة

Discover more from Buzzinga

Subscribe now to keep reading and get access to the full archive.

Continue reading