Skip to content
ZDNET·

🚨AI Models Weaponized by Cybercriminals

Your LLM is now a target for hackers

TL;DR

Cybercriminals are exploiting AI tools like large language models (LLMs) to steal data and conduct surveillance. Famous Chollima group uses trusted AI environments to gain entry into companies working in cryptocurrency.

AI models, tools, and workflows are being weaponized by cybercriminals to steal data and conduct surveillance. Organizations expanding their corporate networks with new LLMs create larger attack surfaces. Threat actors use AI to generate phishing material and commands, complicating defenders' efforts to distinguish malicious activity from expected behavior. In one case, a victim's LLM generated nearly 200,000 API requests in two minutes, causing significant financial impact.

AI Models Weaponized by Cybercriminals — ZDNET

Key Points

1

Famous Chollima group uses trusted AI environments to gain entry into companies working in cryptocurrency and blockchain

2

Cordial Spider and Snarky Spider groups use vishing to exfiltrate data from SaaS apps and compromise single sign-on accounts

3

LLMJacking occurs when threat actors access keys or credentials used to access company's AI models, allowing them to steal data

4

Two out of three recently disclosed LPE exploits were discovered by AI-assisted research and quickly incorporated into active operations

5

88% of exploits detected by CrowdStrike launched within 48 hours of a public proof-of-concept code release

Why It Matters

If you're running an LLM in production, monitor for suspicious usage or cost spikes. Threat actors can exploit these models to generate phishing material and commands, making it harder for defenders to distinguish malicious activity from expected behavior.

AICybercrimeLLMsSecurity

Frequently Asked Questions

Why does this matter?

If you're running an LLM in production, monitor for suspicious usage or cost spikes. Threat actors can exploit these models to generate phishing material and commands, making it harder for defenders to distinguish malicious activity from expected behavior.

What happened?

Cybercriminals are exploiting AI tools like large language models (LLMs) to steal data and conduct surveillance. Famous Chollima group uses trusted AI environments to gain entry into companies working in cryptocurrency.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Also get