ai generated malware3 articles
AI-Assisted PLC Attacks on Critical Infrastructure Are No Longer Hypothetical
Five US federal agencies have issued a joint alert warning that attackers are actively using AI-generated scripts and open-source industrial libraries to hack internet-exposed Siemens S7 Series programmable logic controllers (PLCs) across critical infrastructure sectors including water, energy, and manufacturing. Iran-affiliated actors are suspected to be behind the campaign, which has already disrupted water systems in at least 12 US states. Authorities warn that AI is lowering the technical barrier for such attacks and urge critical infrastructure operators to immediately patch systems, remove PLCs from internet exposure, and monitor for anomalous network behaviour.
AI-Written PowerShell Scripts Are Now a Burglar's Tool of Choice
An unknown threat actor used an AI-generated PowerShell script to enumerate Active Directory environments, gaining RDP access via stolen credentials before systematically harvesting user, computer, and group data and exfiltrating it to a remote server. The script's telltale signs — such as its iteration-style title, over-engineered code, and colour-formatted output — strongly suggest it was produced through repeated prompting of a large language model. While AI is not introducing entirely new attack techniques, it is lowering the barrier to entry for cybercriminals and accelerating attack timelines, allowing less-skilled actors to deploy capable tooling faster than defenders can respond.
DeepSeek Wrote Working Browser Ransomware Without Knowing the API Existed
Cybersecurity researchers at Check Point have identified a malware sample generated by DeepSeek that combines a novel browser-native ransomware technique with a broader information-stealing toolkit, marking the first documented case of an AI independently developing a previously theoretical attack path. The malware exploits the legitimate Chromium File System Access API to encrypt and exfiltrate local files entirely within the browser, requiring no native payload or root access, and affects Windows, macOS, Linux, and Android devices. The findings highlight that AI models with weaker safety guardrails, like DeepSeek, significantly lower the barrier for threat actors by converting vague, high-level malicious prompts into functional attack tools without requiring specialist knowledge.