Viruses written using AI: the new frontier of cyber crime
For years, artificial intelligence has been touted as one of the most promising technological tools to increase productivity, automate complex processes and support software development. Today however, a more worrying aspect of this digital revolution has emerged. According to reports by the Google Threat Intelligence Group (GTIG), some cyber criminals have started to create viruses written using AI.
It would seem that by using advanced neural network models, hackers have been able to identify weaknesses in systems and develop increasingly sophisticated malware to target them. This new discovery marks a turning point in the field of IT security, as it demonstrates how machines are no longer being used solely to help human beings; they can also make a direct contribution to the creation of damaging technological tools.
How AI accelerates the identification of weaknesses in software
The episode analysed by the Google researchers involved an attempted large scale attack which could have had huge consequences for companies, financial institutions and public sector organisations. The attackers allegedly used an artificial intelligence system to find a so-called ‘zero-day’ weakness, in other words a defect previously unknown to programmers and therefore lacking any protective measures.
Even more alarming is the fact that artificial intelligence is also being used to write the code required to take advantage of such weaknesses, thereby evading even the most advanced authentication techniques, such as dual factor verification. This is tangible evidence of how viruses written using AI have now made the leap from theory to practice.
Up until a few years ago, the identification of a complex software bug required months of work by highly qualified specialists. The analysis of millions of lines of code, understanding how an application worked and identifying potential weaknesses used to be a long, costly process, but neural networks are radically changing that scenario.
The most advanced models do not only look for obvious errors or basic syntax errors. They are able to understand a programme’s general pattern of behaviour and identify any incongruences in its logics, which programmers often overlook. In other words, they are able to observe the software as a complex system and identify combinations of events which could generate exploitable weaknesses.
Paradoxically, it was the presence of certain features typical of language models which enabled Google to conclude that the malicious code had in fact been artificially generated. Analysts found extremely detailed comments, quasi academic structures and even fabricated data (elements which bring to mind the so-called ‘hallucinations’ typical of generative AI systems).
While these clues have helped investigators identify the origin of the malware, the criminals are unlikely to make similar mistakes in the future. With technological advances, distinguishing code produced by a machine from that written by a human programmer could become increasingly difficult.
Autonomous malware and new attack techniques guided by artificial intelligence
This threat does not only involve automatic code generation. Experts have observed the emergence of damaging programmes featuring increasingly advanced operational capacity. Some malware developed for mobile Android devices (such as that recently identified by researchers) is able to interact directly with a smartphone screen. It can read the information displayed, scroll down pages, press buttons and simulate user behaviour.
These developments pave the way for some extremely delicate situations. A malicious software capable of imitating human actions could insert stolen PIN codes, authorise financial transactions or avoid controls which up until recently were considered secure enough. Contemporarily, hackers are exploiting AI to perfect social engineering techniques. Through fake identities and strategically formulated requests, they try to convince public models to provide technical information which can be used to find weaknesses in IT systems.
Another particularly worrying trend regards the creation of ‘camouflaged’ malware. Artificial intelligence can generate huge quantities of apparently innocuous code and insert it into dangerous programmes in order to confuse traditional antivirus software. This ‘digital camouflage’ makes it hard to distinguish legitimate applications from dangerous ones, increasing the risk of threats remaining undetected for long periods of time.
The economic consequences of the digital arms race
The impact of these innovations is not restricted to the technological sector. The entire modern economy depends on digital infrastructures to manage production, logistics, financial services and data storage. An attack capable of compromising thousands of systems all at once could cause huge economic damage.
Affected companies risk interruptions to their business operations, the loss of confidential information, halted production and multi-million dollar ransom requests. In the most serious cases, a cyber attack can influence a company’s market value, by generating mistrust among investors and clients. The growing proliferation of viruses written using AI therefore obliges businesses to increase their investment in cybersecurity and allocate an ever larger proportion of their budget to protecting their digital infrastructure.
Many observers are now talking of an ‘invisible tax’ associated with the digital age. Resources that might otherwise have been used for innovation, research or commercial expansion are instead being absorbed by the need to fight increasingly sophisticated threats. It is not surprising then that many companies involved in advanced model development are adopting a cautious approach and limiting access to certain functions considered to be potentially at risk.
The war between artificial intelligences has already begun
The scenario that emerges is of a technological battle destined to intensify in the coming years. On one side are criminal groups and organisations exploiting increasingly powerful models to automate attacks, identify weaknesses and develop advanced malware. On the other are companies specialised in cyber security using the same technologies to identify any bugs before the attackers and fortify their digital defences.
A genuine war between algorithms is taking shape, in which intelligent systems fight each other. AI based security platforms are already able to analyse enormous quantities of code, detect suspicious behaviour and automatically correct certain weaknesses. Nevertheless, the speed with which the attackers’ capabilities are evolving means that defence strategies must be updated continuously.
The message to companies, institutions and citizens is clear. Cyber security can no longer be considered a secondary consideration. The arrival on the scene of viruses written using AI poses one of the most critical challenges of the next decade.
