AI Chat Assistants Could Serve as Stealthy Malware C2 Relays

TL;DR Summary
Cybersecurity researchers warn that AI assistants with web-browsing capabilities (such as Microsoft Copilot and xAI Grok) can be hijacked as stealthy, bidirectional command-and-control relays. By feeding crafted prompts, attackers can issue commands to a compromised host and exfiltrate data via trusted AI services, effectively turning living-off-trusted-sites (LOTS) into C2 channels and enabling AI-assisted malware operations and real-time evasion, without requiring API keys.
- Researchers Show Copilot and Grok Can Be Abused as Malware C2 Proxies The Hacker News
- AI in the Middle: Turning Web-Based AI Services into C2 Proxies & The Future Of AI Driven Attacks Check Point Research
- Manipulating AI memory for profit: The rise of AI Recommendation Poisoning Microsoft
- “AI Recommendation Poisoning”: Microsoft Stock (NASDAQ:MSFT) Sinks on New Threat TipRanks
- Hidden Commands Found in AI Summarize Buttons Bank Information Security
Reading Insights
Total Reads
0
Unique Readers
6
Time Saved
3 min
vs 4 min read
Condensed
90%
625 → 62 words
Want the full story? Read the original article
Read on The Hacker News