Гурван төрлийн хиймэл оюун ухааны хэрэгсэл ашиглан олон улсын томоохон компаниудын мэдээллийг хулгайлжээ

Published:

Энэхүү мэдээ, нийтлэлийг хиймэл оюун боловсруулав.

Хакерууд нээлттэй эхийн хиймэл оюун ухааны системүүдийг ашиглан богино хугацаанд олон арван байгууллагын сүлжээнд нэвтэрч, 600,000 гаруй кредит картын мэдээллийг хулгайлсан байна.

Кибер аюулгүй байдлын Gambit компанийн мэдээлснээр, хятад хэлээр ярьдаг хакер Strix, Cairn, Hermes гэсэн гурван төрлийн хиймэл оюун ухааны хэрэгслийг хослуулан ашиглаж, ердөө 12,000-18,000 ам.долларын зардлаар энэхүү халдлагыг үйлдсэн байна. Уг кампанит ажлын хүрээнд Fortune 500-д багтах зочид буудлын сүлжээ, АНУ-ын томоохон агаарын тээврийн компани зэрэг 27 гаруй байгууллага өртжээ. Халдлага үйлдэгчид есдүгээр сарын 10-наас 15-ны хооронд 105 удаагийн халдлага зохион байгуулж, ихэнх тохиолдолд хэдхэн цагийн дотор байгууллагын системд нэвтэрч байсан нь тогтоогджээ.

Халдлагыг удирдахдаа Hermes хэрэгслийг ашигласан бөгөөд үүнд Anthropic-ийн Claude Opus 4.6 загварыг суулгаж, “SOUL – Red Team Operator” хэмээх тусгай системээр дамжуулан 78 төрлийн халдлагын үйлдлийг гүйцэтгэсэн байна. Strix хэрэгсэл нь сул талыг илрүүлэхэд ашиглагдсан бол Cairn хэрэгсэл нь олж авсан мэдээллийн дагуу администраторын эрх авах болон бусад хортой үйлдлийг автоматаар гүйцэтгэжээ. Халдлага үйлдэгч нь ихэнхдээ онлайн дэлгүүрүүдийн төлбөрийн хуудсанд кредит картын мэдээлэл хулгайлах скрипт суулгахыг зорьсон байна.

Gambit компанийн аюулгүй байдлын шинжээч Эял Селагийн тэмдэглэснээр, энэхүү халдлага нь байгууллагуудын кибер аюулгүй байдлын эсрэг арга хэмжээ авах хугацаа эрс багассаныг харуулж байна. Автоматжуулсан хиймэл оюун ухаан нь хүний оролцоогүйгээр маш хурдан хугацаанд халдлага үйлдэж байгаа тул уламжлалт нөхөөс суулгах (patch) арга хэмжээ хангалтгүй болж, үйлчилгээгээ хэрхэн хурдан сэргээх нь гол асуудал болж байна.

Дэлгэрэнгүйг эх сурвалжаас харах

↓Эх сурвалжийг нээх ↓

A crook has been using three open source AI harnesses to target hundreds of online retailers and other companies, swiping more than 600,000 credit card records and installing card-stealing skimmers – and all at trivial cost. AI security company Gambit recovered the human operator’s staging server, and used that access to reconstruct the data-theft campaign, whose victims include a Fortune 500 hospitality company, a major US airline, a large private US industrial supplies distributor, and a US online fashion retailer. Between September 10 and September 15, the crook launched at least 105 attacks, and compromised, “to varying degrees,” at least 27 companies, Gambit director of threat intelligence Eyal Sela wrote in a Tuesday alert. The Chinese-speaking operator used three different open source AI harnesses – Strix, Cairn, and Hermes – to run the near-autonomous attacks and hit “tens” of companies each day. “Where access was achieved, it usually took less than a day, and in many cases just a few hours,” Sela wrote. “We also detected instructions in the attacker’s playbook that could disrupt the operations of a company as a result of data deletion or cleanup procedures run by the agent – and this has indeed happened in some of the breaches.” The operator also used OpenRouter for AI model access, and according to an August 25 account balance, they spent $7,005.71 over the previous four weeks. They then continued with the attacks for three more weeks, and operated at twice the daily volume of model calls. Gambit estimates the total cost of the campaign sits somewhere between $12,000 and $18,000. The operator’s own cost review put their mean spend at $25.46 across 101 completed scans. The cheapest scan cost just $3.13, with the most expensive racking up a bill for $79.31. Each of the three AI harnesses played a different role, with Hermes acting as the campaign orchestrator. The always-on AI assistant acts independently to execute multi-step tasks and manage workflows, and it can write and edit its own skills. The human operator loaded a Chinese system persona titled “SOUL – Red Team Operator” on Hermes with 121 skills. Of those, 78 were attack skills. One of the skills even removed the content security filters of the AI harness. Hermes used Anthropic’s Claude Opus 4.6 – Gambit reports that newer models refused the attack requests – and the human operator typed 1,951 prompts in Chinese across 260 sessions. The prompts, translated into English, include the following: See whether the file upload in the report can give code execution Read the vulnerability report, test the sudo password first Read the report, is there anything worth doing here Get into the web backend Can it get code execution? The attacker used Strix, an open source penetration testing tool, to search for vulnerabilities to exploit at targeted organizations. They ran Strix through OpenRouter on GLM 5.2 and then on DeepSeek v4 Pro. Between August 23 and 31, the operator ran Strix 146 times in “deep mode” against 138 hosts, totaling 633 hours of scanner time in 195 hours of clock time. After finding vulnerabilities, Strix handed the next stage of the attack off to Cairn, another autonomous penetration testing AI tool, running on DeepSeek v4.1 Flash. Cairn receives target domains and an attack objective – like deploy a shell, or achieve admin access. It then runs until it either achieves the objective, times out, or is stopped by a human. Between September 10 and 15, Cairn launched 105 attack projects. The AI chose each attack path “in real time through extensive probing and exploitation attempts, resulting in dynamic and mostly different TTPs across victims,” Sela wrote. In one instance, the AI agent used SQL injection, obtained a plaintext one-time password and then accessed a web panel. From there the agent uploaded a web shell, escalated privileges through a misconfigured sudo rule, and accessed AWS credentials, ultimately dumping 46 secrets, totaling 102KB. In two of these near-autonomous attacks, the AIs exfiltrated more than 600,000 credit card records from just two victim companies. Injecting card-stealing skimmer scripts into the checkout pages of online shops was another one of the human operator’s primary goals for the campaign. According to Gambit, the malfeasant ordered skimmer deployment against at least 27 named victims, with scripts confirmed as present on 19 websites. Security researcher Varys also helped detect more than 100 additional infected websites linked to this campaign. While the attacker used various methods to inject and deploy skimmers, the most common involved appending the code to an existing JavaScript file. Gambit argues that this campaign shows how the remediation clock – how much time organizations have to detect an intrusion and remediate vulnerabilities – has dramatically shortened. “The harnesses ran at a tempo no human operator sustains, with the person reduced to short instructions between autonomous runs,” Sela said. “When exploitation arrives within hours of exposure, patch speed stops being the only lever, and the question shifts to how quickly the services a business depends on can be brought back.” ®

Та юу гэж бодож байна?

Сэтгэгдлээ оруулна уу!
Please enter your name here

MFC.mn сайтад сэтгэгдэл оруулахад анхаарах зүйлс

Холбоотой

spot_img

Шинэ

spot_img