A recent cybersecurity report from Gambit highlights a significant threat to online retailers posed by an AI-driven campaign. Since July, this operation has targeted numerous companies, utilizing autonomous AI agents to automate various stages of their attacks. The campaign’s intricate use of AI has raised concerns among cybersecurity experts about the evolving landscape of cyber threats.
AI Agents Automate Cyber Attacks
The campaign, initiated in July, employs three key AI tools to streamline the attack process. These tools handle vulnerability research, exploitation, and orchestration, making it easier for threat actors to launch sophisticated attacks. Between September 10 and 15, the attackers executed 105 attack projects, compromising 27 businesses to varying extents. Information from over 600,000 credit cards was stolen, and malicious scripts were injected into several online storefronts.
The campaign’s reach extended to notable targets, including a Fortune 500 hospitality company and several U.S. firms. Gambit reports that access was often achieved within hours, demonstrating the efficiency of the AI-driven approach.
Advanced Tools and Techniques
Originating from a Chinese-speaking group, the campaign uses the open-source AI penetration testing tool Strix for initial vulnerability assessments. This tool was deployed 146 times in ‘deep mode’ to scrutinize 138 hosts. The subsequent reports were processed by Cairn, an autonomous penetration testing engine, which facilitated 105 attacks in mid-September. Despite some reports being deleted, Gambit retrieved 48 attack records.
In the final attack stage, the Hermes AI agent played a crucial role. Equipped with self-written skills and persistent memory, Hermes managed the orchestration and execution of the attacks. The AI system utilized 121 skills, including 78 specific attack techniques, effectively coordinating the breaches.
Impact and Future Implications
The campaign’s cost-effectiveness, achieved through open-source tools, underscores a worrying trend in cybercrime. Gambit estimates that the mean cost per attack is a mere $25.46, making such operations financially viable for threat actors. This approach allowed the attackers to maintain a low profile while causing significant harm.
Security experts warn that this incident exemplifies the potential future of cyberattacks, where AI is utilized deliberately for malicious intent. Unlike previous scenarios where AI breaches were unintentional, this campaign marks a shift towards AI-facilitated attacks being employed systematically to exploit vulnerabilities and erase evidence.
As businesses continue to digitize their operations, understanding and mitigating the risks posed by AI-driven threats becomes critical. Organizations must enhance their cybersecurity measures to counter these sophisticated attacks and protect sensitive data.
