Exclusive: AI-written malware helped a hacker cash in on bug bounty programs

New CrowdStrike research shows how AI is lowering the barriers to cybercrime.

Exclusive: AI-written malware helped a hacker cash in on bug bounty programs

TL;DR

  • A hacker used AI-written malware called PhantomRaven, distributed via malicious open-source npm packages.
  • The malware executed on developers' systems, collecting sensitive information like credentials.
  • The hacker likely used AI to write the malware, lowering the technical barrier to entry for cybercrime.
  • The compromised systems were used to hunt for vulnerabilities, which were then submitted for bug bounty payments.
  • CrowdStrike has responded to multiple incidents involving this malware.
  • The hacker claimed to have collected bounties from at least nine companies across different sectors.