xCruzo
|
Axios

Exclusive: AI-written malware helped a hacker cash in on bug bounty programs

✦ xCruzo 🇺🇸🇪🇸
📄 Read Article
Exclusive: AI-written malware helped a hacker cash in on bug bounty programs
Browse hubs:CarsAviationMarineMoneySportsTech
xCruzo Brief

CrowdStrike researchers report that a financially motivated hacker used a large language model to help write malware for attacks that leveraged bug bounty programs. The malware, dubbed PhantomRaven, was delivered through malicious open-source npm packages. After developers installed the packages, PhantomRaven executed on their systems to collect information, including credentials and other sensitive development data. CrowdStrike assesses the hacker used it to compromise company assets and hunt for vulnerabilities, then used those findings to submit bugs to legitimate programs for payouts. The attacker also posted about collecting bounties from at least nine companies, though the report says it’s unclear which were actually compromised. CrowdStrike said it has not seen stolen data from the campaign sold on criminal marketplaces.

xCruzo quick-read summary • Source: Axios • Read the full article for complete information.
📄 Read Full Article →
xCruzo xCruzo
See your VIN Report in 15 seconds — Free
1 in 5 cars has an open recall. Is yours one of them?
Not the dealer’s report. Yours.
Choose your detail level — free to full.
For the price of a coffee.
Check My VIN — Free
Free · No credit card · Instant results
Link copied ✓