Seoul: State-sponsored hackers from North Korea and China are increasingly utilizing artificial intelligence (AI) to uncover previously undetected cybersecurity vulnerabilities, Alphabet's Google revealed in a recent report. The report highlights "significant interest" from hackers associated with the People's Republic of China (PRC) and the Democratic People's Republic of Korea (DPRK) in employing AI for vulnerability detection.
According to Yonhap News Agency, Google's threat intelligence group observed sophisticated methods being used by these hackers, particularly by North Korea's APT45 group, to exploit cybersecurity blind spots. The group has been using AI to send numerous repetitive prompts that analyze potential vulnerabilities recursively.
The report also detailed an incident where AI was used to detect a criminal group's attempt to use a "zero-day exploit" for mass exploitation, which was subsequently blocked. Zero-day exploits are particularly dangerous as they target vulnerabilities unknown to organizations and developers, leaving them unable to respond before an attack occurs.
This marks the first instance where Google has identified attackers using AI on such a scale to find and exploit new vulnerabilities. The findings come amid heightened global cybersecurity concerns, particularly following the introduction of Claude Mythos, a new AI model from U.S. startup Anthropic. This model specializes in detecting software security vulnerabilities but is not being released publicly. Instead, Anthropic has restricted access to a select group of companies and institutions for defense security testing.