← Back
MalwareCisco Talos·3 weeks ago

“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI

Cisco Talos analyzed prompt logs collected from threat actor endpoints using multiple AI coding assistants including Claude Code, CodeX, Cursor, and Gemini to understand how adversaries are operationalizing these tools. The research provides a data-driven examination of the tactics and techniques threat actors employ when leveraging cloud-based AI applications for malicious purposes.

Read full article at Cisco Talos

Related Articles

MalwareHelp Net Security·9 hours ago

Fake OpenAI Codex download tricks macOS users into installing malware

A malware campaign discovered by Cato Networks exploits sponsored search ads to direct macOS users to a fake OpenAI Codex download page, where victims are socially engineered into pasting malicious commands directly into Terminal. The attack uses a variation of the ClickFix technique, which manipulates users into executing the infection themselves rather than opening a malicious file, with the campaign beginning through sponsored search results for queries like "codex macos download."

MalwareThe Hacker News·10 hours ago

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

Researchers have identified a novel command-and-control technique where threat actors exploit FTP banners as dead drop resolvers to deliver two previously unreported RATs named E4del and PINHOLE. This approach leverages legitimate FTP services to obscure malware communications and point to additional C2 infrastructure while evading detection.

MalwareSecurityWeek·11 hours ago

First Malware Built Specifically for Car Head Units Fuels Botnet

Kaspersky researchers have identified the first malware specifically designed to target car head units, which has been enlisted into the BadBox botnet infrastructure. The discovery represents a significant expansion of botnet operations into automotive systems, with the malware already compromising millions of devices across the network.

MalwareInfosecurity Magazine·12 hours ago

Fake Minecraft Clients Deliver WeedHack Malware Despite Infrastructure Takedown

Threat actors continue distributing WeedHack malware to Minecraft players through counterfeit game clients, maintaining operations even after law enforcement dismantled the malware's original infrastructure in July. The persistence of this campaign demonstrates how attackers adapt their distribution channels when primary infrastructure is disrupted, keeping a known threat active against gaming communities.