Exclusive: Bug bounty programs tricked with AI
Add Axios as your preferred source to
see more of our stories on Google.

Illustration: Aïda Amer/Axios
A hacker used AI-written malware distributed through open-source software packages to compromise companies and hunt for bugs that he then submitted for legitimate bug bounty payments, according to CrowdStrike research shared first with Axios.
Why it matters: The findings offer a striking example of how AI is lowering the technical barriers to cybercrime and allowing relatively unsophisticated hackers to build their own malware.
Driving the news: CrowdStrike researchers say they have high confidence that the financially motivated hacker used a large language model to write the malware behind his attack based on the comments, placeholder code and token-analysis patterns left inside the script.
- The hacker also posted about collecting bounties from at least nine companies across the technology, retail and hospitality sectors; however, it's unclear whether the malware, called PhantomRaven, was used to compromise those particular companies or identify the issues behind those bounties.
- CrowdStrike remediated and responded to multiple incidents involving this malware.
How it works: The hacker published malicious open-source npm packages that delivered the PhantomRaven malware.
- When developers installed the malicious packages, PhantomRaven executed on their systems and collected information, including credentials and other sensitive development data.
- CrowdStrike assesses that the hacker used PhantomRaven to compromise company assets and hunt for vulnerabilities.
- The hacker then used those compromises as leverage to submit bugs to legitimate bug bounty programs and seek payouts.
Between the lines: Turning to bug bounty programs allowed the hacker to establish credibility in the broader hacker community, Adam Meyers, CrowdStrike's senior vice president of counter adversary operations, told Axios.
- The researchers also said in the report that they haven't seen stolen data from this campaign being sold on criminal marketplaces.
The big picture: The case is just the latest example of growing AI adoption among malicious actors, including less-sophisticated actors eager to scale their operations.
- "We're seeing it all over the place," Meyers said. "We have adversaries that are using AI to develop their tooling; we're seeing it across the spectrum of nation-states and criminal hacktivists."
Yes, but: The malware used in this campaign is relatively simple, and the attack relied solely on well-known supply-chain techniques.
- The notable part is that AI appears to have helped a relatively inexperienced hacker build his own functioning malware rather than relying on off-the-shelf tools.
