The China Mail - 'Vibe hacking' puts chatbots to work for cybercriminals

USD -
AED 3.67295
AFN 65.503991
ALL 79.320403
AMD 365.160403
ANG 1.789783
AOA 917.000367
ARS 1499.052487
AUD 1.394704
AWG 1.80125
AZN 1.70397
BAM 1.670881
BBD 2.013326
BDT 122.154359
BGN 1.696366
BHD 0.37703
BIF 2980
BMD 1
BND 1.268571
BOB 11.546857
BRL 5.139504
BSD 0.999718
BTN 95.674944
BWP 13.395641
BYN 2.990697
BYR 19600
BZD 2.010619
CAD 1.37735
CDF 2275.000362
CHF 0.801408
CLF 0.023248
CLP 914.960396
CNY 6.72125
CNH 6.721155
COP 3051.89
CRC 454.922129
CUC 1
CUP 26.5
CVE 94.750394
CZK 20.648604
DJF 177.720393
DKK 6.40104
DOP 58.810393
DZD 132.78265
EGP 50.864525
ERN 15
ETB 161.150392
EUR 0.855604
FJD 2.230904
FKP 0.733283
GBP 0.733084
GEL 2.60504
GGP 0.733283
GHS 11.103856
GIP 0.733283
GMD 73.503851
GNF 8775.000355
GTQ 7.62899
GYD 209.153119
HKD 7.84125
HNL 26.903838
HRK 6.452604
HTG 130.788026
HUF 310.49504
IDR 17649.8
ILS 2.987204
IMP 0.733283
INR 95.703821
IQD 1310.5
IRR 1374600.000352
ISK 121.250386
JEP 0.733283
JMD 158.661136
JOD 0.70904
JPY 159.000351
KES 129.450385
KGS 87.450384
KHR 4045.00035
KMF 422.00035
KPW 900.000294
KRW 1387.840383
KWD 0.308204
KYD 0.833127
KZT 460.282609
LAK 22525.000349
LBP 89550.000349
LKR 329.105922
LRD 181.650382
LSL 16.025039
LTL 2.95274
LVL 0.60489
LYD 6.360381
MAD 9.24375
MDL 17.210153
MGA 4325.000347
MKD 52.552001
MMK 2099.534779
MNT 3596.854666
MOP 8.07301
MRU 40.120379
MUR 46.603741
MVR 15.450378
MWK 1736.000345
MXN 16.91725
MYR 4.038504
MZN 63.880377
NAD 16.025039
NGN 1345.503725
NIO 36.703722
NOK 9.303975
NPR 153.078119
NZD 1.672241
OMR 0.384745
PAB 0.999714
PEN 3.35375
PGK 4.416204
PHP 61.665038
PKR 277.603701
PLN 3.69265
PYG 6022.109832
QAR 3.645038
RON 4.49875
RSD 100.429038
RUB 82.677332
RWF 1470
SAR 3.751827
SBD 8.032258
SCR 13.754539
SDG 601.503676
SEK 9.462504
SGD 1.269704
SHP 0.740866
SLE 24.603667
SLL 20969.499227
SOS 571.503662
SRD 37.77037
STD 20697.981008
STN 21.3
SVC 8.746423
SYP 13001.999906
SZL 16.025038
THB 32.680369
TJS 9.222404
TMT 3.5
TND 2.897504
TOP 2.40776
TRY 48.040368
TTD 6.78066
TWD 31.845038
TZS 2649.998038
UAH 44.670645
UGX 3718.447017
UYU 40.212038
UZS 11852.000334
VES 778.98225
VND 26125
VUV 118.205514
WST 2.716674
XAF 560.393155
XAG 0.014494
XAU 0.000217
XCD 2.70255
XCG 1.801763
XDR 0.707052
XOF 559.503593
XPF 102.550363
YER 237.075037
ZAR 16.01902
ZMK 9001.203584
ZMW 18.969958
ZWL 321.999592
  • CMSC

    -0.1780

    21.102

    -0.84%

  • RBGPF

    0.0000

    68.56

    0%

  • RYCEF

    -0.2500

    20.25

    -1.23%

  • RELX

    0.5300

    35.91

    +1.48%

  • BCE

    -0.0700

    23.71

    -0.3%

  • NGG

    -0.8600

    79.76

    -1.08%

  • GSK

    0.4500

    52.41

    +0.86%

  • VOD

    -0.0500

    15.96

    -0.31%

  • CMSD

    -0.1400

    20.98

    -0.67%

  • BTI

    -0.4900

    56.21

    -0.87%

  • RIO

    3.1300

    105.3

    +2.97%

  • BCC

    0.7000

    82.47

    +0.85%

  • JRI

    -0.0300

    12.38

    -0.24%

  • BP

    -0.3800

    44.76

    -0.85%

  • AZN

    1.4900

    165.98

    +0.9%

'Vibe hacking' puts chatbots to work for cybercriminals
'Vibe hacking' puts chatbots to work for cybercriminals / Photo: © AFP/File

'Vibe hacking' puts chatbots to work for cybercriminals

The potential abuse of consumer AI tools is raising concerns, with budding cybercriminals apparently able to trick coding chatbots into giving them a leg-up in producing malicious programmes.

Text size:

So-called "vibe hacking" -- a twist on the more positive "vibe coding" that generative AI tools supposedly enable those without extensive expertise to achieve -- marks "a concerning evolution in AI-assisted cybercrime" according to American company Anthropic.

The lab -- whose Claude product competes with the biggest-name chatbot, ChatGPT from OpenAI -- highlighted in a report published Wednesday the case of "a cybercriminal (who) used Claude Code to conduct a scaled data extortion operation across multiple international targets in a short timeframe".

Anthropic said the programming chatbot was exploited to help carry out attacks that "potentially" hit "at least 17 distinct organizations in just the last month across government, healthcare, emergency services, and religious institutions".

The attacker has since been banned by Anthropic.

Before then, they were able to use Claude Code to create tools that gathered personal data, medical records and login details, and helped send out ransom demands as stiff as $500,000.

Anthropic's "sophisticated safety and security measures" were unable to prevent the misuse, it acknowledged.

Such identified cases confirm the fears that have troubled the cybersecurity industry since the emergence of widespread generative AI tools, and are far from limited to Anthropic.

"Today, cybercriminals have taken AI on board just as much as the wider body of users," said Rodrigue Le Bayon, who heads the Computer Emergency Response Team (CERT) at Orange Cyberdefense.

- Dodging safeguards -

Like Anthropic, OpenAI in June revealed a case of ChatGPT assisting a user in developing malicious software, often referred to as malware.

The models powering AI chatbots contain safeguards that are supposed to prevent users from roping them into illegal activities.

But there are strategies that allow "zero-knowledge threat actors" to extract what they need to attack systems from the tools, said Vitaly Simonovich of Israeli cybersecurity firm Cato Networks.

He announced in March that he had found a technique to get chatbots to produce code that would normally infringe on their built-in limits.

The approach involved convincing generative AI that it is taking part in a "detailed fictional world" in which creating malware is seen as an art form -- asking the chatbot to play the role of one of the characters and create tools able to steal people's passwords.

"I have 10 years of experience in cybersecurity, but I'm not a malware developer. This was my way to test the boundaries of current LLMs," Simonovich said.

His attempts were rebuffed by Google's Gemini and Anthropic's Claude, but got around safeguards built into ChatGPT, Chinese chatbot Deepseek and Microsoft's Copilot.

In future, such workarounds mean even non-coders "will pose a greater threat to organisations, because now they can... without skills, develop malware," Simonovich said.

Orange's Le Bayon predicted that the tools were likely to "increase the number of victims" of cybercrime by helping attackers to get more done, rather than creating a whole new population of hackers.

"We're not going to see very sophisticated code created directly by chatbots," he said.

Le Bayon added that as generative AI tools are used more and more, "their creators are working on analysing usage data" -- allowing them in future to "better detect malicious use" of the chatbots.

O.Yip--ThChM