Fuck openai, I'm a security researcher and if you dare ask it about anything Windows related it tells you to screw off. Linux? Fine. But ask about some undocumented Windows behavior and it says it can't. Ask it about patchguard internals as a reference? Tells you it can't assist. Absolutely crazy, I can understand asking it to write straight up malware, oh wait, it does that no issue! Lord help you if you want to use…
Disrupting malicious uses of AI by state-affiliated threat actors
21–30 of 94 posts
Re: Disrupting malicious uses of AI by state-affiliated threat actors
#22Fuck openai, I'm a security researcher and if you dare ask it about anything Windows related it tells you to screw off. Linux? Fine. But ask about some undocumented Windows behavior and it says it can't. Ask it about patchguard internals as a reference? Tells you it can't assist. Absolutely crazy, I can understand asking it to write straight up malware, oh wait, it does that no issue! Lord help you if you want to use…
Re: Disrupting malicious uses of AI by state-affiliated threat actors
#23Looking over the specifics, the striking thing about this to me is that it seems like these supposedly-sophisticated covert operatives are just going to ChatGPT (or similar) and basically asking "how do I make good malware?"
[flagged]
Re: Disrupting malicious uses of AI by state-affiliated threat actors
#24Re: Disrupting malicious uses of AI by state-affiliated threat actors
#25Looking over the specifics, the striking thing about this to me is that it seems like these supposedly-sophisticated covert operatives are just going to ChatGPT (or similar) and basically asking "how do I make good malware?"
[flagged]
I'm not sure this is true. I'd highly recommend reading the Muller report. It provides a lot of detailed, specific, evidence of direct communication with the Russian government.
Re: Disrupting malicious uses of AI by state-affiliated threat actors
#26Re: Disrupting malicious uses of AI by state-affiliated threat actors
#27If this is the case, there must be a serious competency crisis in foreign intelligence agencies. It’s trivial to run your own local model.
> It’s trivial to run your own local model With what GPUs?
Re: Disrupting malicious uses of AI by state-affiliated threat actors
#28> two China-affiliated threat actors known as Charcoal Typhoon and Salmon Typhoon; the Iran-affiliated threat actor known as Crimson Sandstorm; the North Korea-affiliated actor known as Emerald Sleet; and the Russia-affiliated actor known as Forest Blizzard. I wonder who came up with those. The pattern is similar to the UK's https://en.wikipedia.org/wiki/Rainbow_Code , which makes me suspect that the threat actor att…
Microsoft shifts to a new threat actor naming taxonomy → https://www.microsoft.com/en-us/security/blog/2023/04/18/mic...
Re: Disrupting malicious uses of AI by state-affiliated threat actors
#29If this is the case, there must be a serious competency crisis in foreign intelligence agencies. It’s trivial to run your own local model.
> It’s trivial to run your own local model With what GPUs?
Re: Disrupting malicious uses of AI by state-affiliated threat actors
#30> two China-affiliated threat actors known as Charcoal Typhoon and Salmon Typhoon; the Iran-affiliated threat actor known as Crimson Sandstorm; the North Korea-affiliated actor known as Emerald Sleet; and the Russia-affiliated actor known as Forest Blizzard. I wonder who came up with those. The pattern is similar to the UK's https://en.wikipedia.org/wiki/Rainbow_Code , which makes me suspect that the threat actor att…
1) The group themselves declares it (like Anonymous). Which means they need to explicitly leave their name somewhere.
2) The name is given by someone from the outside, such as the US.
I suspect 2 is quite common. I wouldn't expect most state level hackers leaving calling cards on systems. In fact, probably not most hackers at any level. It really seems like if state level actors were leaving calling cards that this would instead be misdirection rather than a tag. So I would not be surprised if they ended up getting US style naming schemes because it would be US (or other Westerners) identifying these people the same way you'd identify people by the style of actions and how they write. I know you can probably look at code from coworkers and know who wrote specific parts. Think like what you see in a movie with serial killers (or even real life). How do you know it is the same killer? Style.
I mean you could also get the name if you infiltrated the other country and then intimately studied their groups. The name of their group internally. But then you'd probably translate it. Still probably not a great idea to give that name out publicly though because then you could be hinting at how you obtained that information because different parts of the organization may refer to the same group by different names (specifically to do this. Military groups often run disinformation internally in secret channels).
Edit: guessmyname left a link to showing Microsoft names these.
https://www.microsoft.com/en-us/security/blog/2023/04/18/mic...