HP has blocked an email campaign including a malware is spread by a tool dropper by AI create.
On January 6 in the year 2024, HP has discovered a phishing email content by topic bills downloads and attach an HTML file is encrypted. Patrick Schlapfer, researchers at HP, said: “the attacker was deployed decryption key AES in JavaScript code of the attachment. This is not common and is the main reason why we consider it more closely”.
Open the file attached after decoding will display the interface of a web page that contains script VBScript and malicious code to steal information (computer) publicly available AsyncRAT. VBScript is dropper for payload infostealer. It recorded many different variables to the Registry; save a JavaScript file into the users folder, then the file will be executed as a task is scheduled. A PowerShell command was created and eventually cause the executable payload AsyncRAT.

Notably, “VBScript is structured neatly and all the important commands are annotated. That's unusual”, Schlapfer for more. Malware is often trying to make it hard to understand and do not contain any annotation. This case is the opposite. In addition, it is written in French, not the common language that those who develop malicious software options. These clues led the researchers to think that this script not by people write that due to gene-AI create.
They test this guess using gene-ONE of their own to create a script with the structure and comments are very similar. Although the results are not absolute proof, but the researchers believe that the dropper was created through gene-ONE.
Alex Holland, co-principal research group threat at Schlapfer explained: “...Payload AsyncRAT is provided free of charge. There is no infrastructure, which, in addition to a host C&C to control tools stolen information. This malicious software is very basic and not be concealed.”
This conclusion strengthens the likelihood that attackers are new to using gene-ONE and perhaps because it is new, so the script of WHO created had been so raw and full caption. If no annotations will be nearly impossible to conclude that the script of WHO created it or not.
If this malware was created by a threatening lack of experience has left clues about the use of AI, then AI can be used more widely by the threat experienced than those who will not leave clues so. In fact, it is likely that such – but largely undetectable and can't prove it.
Source: securityweek.com

