Malware News AI in the Middle: Turning Web-Based AI Services into C2 Proxies & The Future Of AI Driven Attacks (A Checkpoint Research)

Khushal

Level 13
Thread author
Verified
Top Poster
Well-known
Apr 4, 2024
601
3,615
1,169
Check Point Research shows AI web assistants with browsing can be abused as covert C2 relays (AI as a proxy) via Grok and Copilot, enabling bidirectional data flow and AI-driven malware decision-making without credentials.

1771391060819.png


 
Our proposed attack scenario is quite simple: an attacker infects a machine and installs a piece of malware. Then the malware communicates directly with either Grok or Copilot through the web interface, sending a prompt that causes the AI agent to issue an HTTP(S) request to an attacker-controlled URL, retrieve content from that site, and return the attacker’s response via the AI output back to the malware.
 

You may also like...