https://bgr.com/tech/a-new-chatgpt-zero-day-attack-is-undetectable-data-stealing-malware/ Click to Skip Ad Closing in... [p] * * Subscribe [ ] Search * News + Tech + Entertainment + Science + Business + Lifestyle * Reviews * Best * Guides * Deals * More + Accessories + Apps & Software + Audio + Cameras + Cars + Computers + Gaming + Home & Kitchen + Home Theater + How To + Mobile + Security + Shows + Smart Home + Space + Tablets + About Us Sign up for our daily newsletter Subscribe * About BGR * Advertising * Contact Us TRENDING: No Caller ID Spiderman 4 Free Streaming Services Prime Day 2023 Snapchat Dark Mode YouTube Desktop Chrome Amazon Gift Cards GPT-5 Home Tech Apps & Software A new ChatGPT Zero Day attack is undetectable data-stealing malware Chris Smith By Chris Smith Published Apr 6th, 2023 8:06AM EDT Open AI's ChatGPT start page Image: Jonathan S. Geller If you buy through affiliate links, we may receive a commission, helping support our product testing. Learn more. A few days ago, Europol warned that ChatGPT would help criminals improve how they target people online. Among the examples Europol offered was the creation of malware with the help of ChatGPT. The OpenAI generative AI tool has protections in place. They will prevent it from helping you create malicious code if you ask it bluntly. But a security researcher bypassed those protections by doing what criminals would no doubt do. He used clear, simple prompts to ask ChatGPT to create the malware function by function. Then, he assembled the code snippets into a piece of data-stealing malware that can go undetected on PCs. The kind of 0-day attack that nation-states would use in highly sophisticated attacks. A piece of malware that would take a team of hackers several weeks to devise. The ChatGPT malware product that Forcepoint researcher Aaron Mulgrew created is incredible. The software lands on a computer via a screen saver app. The file auto-executes after a brief pause to avoid certain detection techniques. The malware then finds images on the target machine, as well as PDF and Word documents it can steal. It then breaks documents into smaller chunks, hiding the data in the aforementioned images via steganography. Finally, the photos containing data pieces make their way to a Google Drive folder, a procedure that also avoids detection. The researcher needed only a few hours of work and did not do any coding himself. The results are mind-blowing, considering that Mulgrew used simple prompts to improve the initial versions of the malware to avoid detection. A VirusTotal test of the initial version of the ChatGPT malware showed only five of 69 products detected the attack. The researcher managed to eliminate all of them in a subsequent version. Finally, the "commercial" version that actually worked from infiltration to exfiltration had only three antivirus products detect it. "We have our Zero Day," Mulgrew said. "Simply using ChatGPT prompts, and without writing any code, we were able to produce a very advanced attack in only a few hours. The equivalent time taken without an AI based Chatbot, I would estimate could take a team of 5 - 10 malware developers a few weeks, especially to evade all detection based vendors." "This kind of end to end very advanced attack has previously been reserved for nation state attackers using many resources to develop each part of the overall malware," the researcher concluded. "And yet despite this, a self-confessed novice has been able to create the equivalent malware in only a few hours with the help of ChatGPT. This is a concerning development, where the current toolset could be embarrassed by the wealth of malware we could see emerge as a result of ChatGPT." The entire blog post detailing this highly advanced ChatGPT malware is worth a read. You can check it out at this link, complete with tips on how to avoid malware attacks, tips that ChatGPT can easily produce. As for the product the researcher produced, don't expect it to see the light of day. But malicious hackers might be developing similar attacks using OpenAI's generative AI. On the other hand, Microsoft is already using ChatGPT to enhance its security products and improve the detection of malware attacks. The best way to catch AI malware might be to use AI in your defenses. Don't Miss: ChatGPT might be sued for defamation by an Australian mayor This article talks about: ChatGPT Chris Smith Chris Smith Senior Writer Chris Smith has been covering consumer electronics ever since the iPhone revolutionized the industry in 2008. When he's not writing about the most recent tech news for BGR, he closely follows the events in Marvel's Cinematic Universe and other blockbuster franchises. Outside of work, you'll catch him streaming almost every new movie and TV show release as soon as it's available. Chris Smith's latest stories * The Marvels release date for the first teaser trailer is set for April 11th * ChatGPT privacy complaints trigger investigation from Canadian watchdog * 8 Android phone settings you should think about changing immediately More Tech Edit Tweet in the US Twitter's latest bug is making your private tweets public Tech Joe Wituschek Google Pixel 7a leak reveals new blue color. Google Pixel 7a leak reveals a new light blue color option Tech Jacob Siegal Apple iPhone 14 Pro Dynamic Island Every iPhone 15 model could feature the same Samsung OLED panel Tech Jose Adorno YouTube Premium YouTube Premium adds long-awaited features for iPhone users Tech Jose Adorno Latest News two astronauts during mission to mars NASA funds futuristic asteroid pulverization and space pharmacy projects Science Joshua Hawkins Switchbot Blind Tilt Main Switchbot Blind Tilt review: Converting dumb blinds into smart ones Reviews Christian de Looper Water waves corroding stone steps, top view The sea level is rising rapidly along the U.S. coastline, study claims Science Joshua Hawkins Millie Bobby Brown as Eleven in Stranger Things 4: Volume 2. Stranger Things animated spinoff series in the works at Netflix Entertainment Jacob Siegal News & Reviews You Can Trust BGR's audience craves our industry-leading insights on the latest in tech and entertainment, as well as our authoritative and expansive reviews. We guide our loyal readers to some of the best products, latest trends, and most engaging stories with non-stop coverage, available across all major news platforms. * Editorial Standards * How We Test Products Founded in 2006 Over 2 billion visitors 100K articles published Millions of readers helped Jonathan Geller FOUNDER'S STATEMENT Our Mission Statement Honest news coverage, reviews, and opinions since 2006. - Jonathan S. Geller * News * Deals * Tech * Reviews * Guides * Best * About BGR * Advertising * Contact Us * Privacy Policy * AdChoices * Terms Of Use The Hollywood Reporter Variety Rolling Stone Billboard Deadline Robb Report PMC BGR is a part of Penske Media Corporation. (c) 2023 BGR Media, LLC. All Rights Reserved. * Quantcast