The Prague Post - 'Vibe hacking' puts chatbots to work for cybercriminals

EUR -
AED 4.282283
AFN 77.769401
ALL 96.678981
AMD 449.127543
ANG 2.087192
AOA 1069.259436
ARS 1643.844928
AUD 1.798333
AWG 2.101788
AZN 1.981275
BAM 1.956791
BBD 2.355693
BDT 142.452171
BGN 1.957154
BHD 0.440923
BIF 3447.246494
BMD 1.166041
BND 1.514267
BOB 8.082095
BRL 6.302688
BSD 1.169593
BTN 102.949158
BWP 15.67294
BYN 3.984319
BYR 22854.398824
BZD 2.352292
CAD 1.634909
CDF 2571.119424
CHF 0.928752
CLF 0.028569
CLP 1120.737804
CNY 8.310431
CNH 8.310337
COP 4497.078374
CRC 587.097444
CUC 1.166041
CUP 30.90008
CVE 110.320892
CZK 24.302271
DJF 208.27552
DKK 7.472923
DOP 73.967474
DZD 150.926465
EGP 55.401068
ERN 17.490611
ETB 173.836472
FJD 2.651402
FKP 0.867143
GBP 0.871904
GEL 3.171978
GGP 0.867143
GHS 12.543355
GIP 0.867143
GMD 83.954954
GNF 10149.141904
GTQ 8.958539
GYD 244.65395
HKD 9.056948
HNL 30.717563
HRK 7.540555
HTG 153.387711
HUF 389.372506
IDR 19324.38534
ILS 3.854354
IMP 0.867143
INR 102.641495
IQD 1532.176253
IRR 49046.624025
ISK 141.919186
JEP 0.867143
JMD 187.96523
JOD 0.826773
JPY 175.611571
KES 151.05653
KGS 101.970443
KHR 4707.384923
KMF 492.654074
KPW 1049.436977
KRW 1657.806761
KWD 0.356611
KYD 0.974694
KZT 629.188769
LAK 25379.858308
LBP 104735.862787
LKR 354.109404
LRD 214.028434
LSL 20.395233
LTL 3.443015
LVL 0.705326
LYD 6.348216
MAD 10.695319
MDL 19.724993
MGA 5202.635834
MKD 61.651235
MMK 2448.25337
MNT 4193.474252
MOP 9.35674
MRU 46.773697
MUR 52.506852
MVR 17.841903
MWK 2028.027468
MXN 21.427922
MYR 4.927719
MZN 74.521843
NAD 20.395233
NGN 1715.292928
NIO 43.041806
NOK 11.733897
NPR 164.718452
NZD 2.036752
OMR 0.447707
PAB 1.169593
PEN 3.960206
PGK 4.988527
PHP 67.771417
PKR 331.096445
PLN 4.245723
PYG 8301.205676
QAR 4.26316
RON 5.090002
RSD 117.229392
RUB 94.948104
RWF 1697.660093
SAR 4.372747
SBD 9.605112
SCR 16.207211
SDG 701.371893
SEK 10.991497
SGD 1.510255
SHP 0.874833
SLE 26.958547
SLL 24451.291091
SOS 668.438654
SRD 45.960672
STD 24134.689429
STN 24.512419
SVC 10.234185
SYP 15160.721635
SZL 20.388329
THB 38.181976
TJS 10.789366
TMT 4.081143
TND 3.41503
TOP 2.73098
TRY 48.901621
TTD 7.933019
TWD 35.723879
TZS 2877.157667
UAH 48.813931
UGX 4088.071157
USD 1.166041
UYU 46.823723
UZS 14223.205965
VES 234.627981
VND 30715.845603
VUV 142.313179
WST 3.275402
XAF 656.289499
XAG 0.022425
XAU 0.000275
XCD 3.151283
XCG 2.107868
XDR 0.816214
XOF 656.289499
XPF 119.331742
YER 278.571983
ZAR 20.262878
ZMK 10495.764048
ZMW 26.520436
ZWL 375.464648
  • RBGPF

    0.0000

    79.09

    0%

  • CMSD

    0.2000

    24.29

    +0.82%

  • RELX

    0.0100

    45.23

    +0.02%

  • NGG

    1.0500

    76.95

    +1.36%

  • RIO

    -0.7300

    68.02

    -1.07%

  • SCS

    -0.0100

    16.55

    -0.06%

  • RYCEF

    -0.3900

    14.91

    -2.62%

  • CMSC

    0.3801

    24.1

    +1.58%

  • BCC

    0.1900

    71.03

    +0.27%

  • BCE

    0.5700

    24.26

    +2.35%

  • JRI

    -0.0100

    13.77

    -0.07%

  • GSK

    0.1400

    43.91

    +0.32%

  • VOD

    0.1900

    11.67

    +1.63%

  • AZN

    0.8600

    84.69

    +1.02%

  • BP

    0.3500

    33.13

    +1.06%

  • BTI

    0.4800

    51.62

    +0.93%

'Vibe hacking' puts chatbots to work for cybercriminals
'Vibe hacking' puts chatbots to work for cybercriminals / Photo: Kirill KUDRYAVTSEV - AFP/File

'Vibe hacking' puts chatbots to work for cybercriminals

The potential abuse of consumer AI tools is raising concerns, with budding cybercriminals apparently able to trick coding chatbots into giving them a leg-up in producing malicious programmes.

Text size:

So-called "vibe hacking" -- a twist on the more positive "vibe coding" that generative AI tools supposedly enable those without extensive expertise to achieve -- marks "a concerning evolution in AI-assisted cybercrime" according to American company Anthropic.

The lab -- whose Claude product competes with the biggest-name chatbot, ChatGPT from OpenAI -- highlighted in a report published Wednesday the case of "a cybercriminal (who) used Claude Code to conduct a scaled data extortion operation across multiple international targets in a short timeframe".

Anthropic said the programming chatbot was exploited to help carry out attacks that "potentially" hit "at least 17 distinct organizations in just the last month across government, healthcare, emergency services, and religious institutions".

The attacker has since been banned by Anthropic.

Before then, they were able to use Claude Code to create tools that gathered personal data, medical records and login details, and helped send out ransom demands as stiff as $500,000.

Anthropic's "sophisticated safety and security measures" were unable to prevent the misuse, it acknowledged.

Such identified cases confirm the fears that have troubled the cybersecurity industry since the emergence of widespread generative AI tools, and are far from limited to Anthropic.

"Today, cybercriminals have taken AI on board just as much as the wider body of users," said Rodrigue Le Bayon, who heads the Computer Emergency Response Team (CERT) at Orange Cyberdefense.

- Dodging safeguards -

Like Anthropic, OpenAI in June revealed a case of ChatGPT assisting a user in developing malicious software, often referred to as malware.

The models powering AI chatbots contain safeguards that are supposed to prevent users from roping them into illegal activities.

But there are strategies that allow "zero-knowledge threat actors" to extract what they need to attack systems from the tools, said Vitaly Simonovich of Israeli cybersecurity firm Cato Networks.

He announced in March that he had found a technique to get chatbots to produce code that would normally infringe on their built-in limits.

The approach involved convincing generative AI that it is taking part in a "detailed fictional world" in which creating malware is seen as an art form -- asking the chatbot to play the role of one of the characters and create tools able to steal people's passwords.

"I have 10 years of experience in cybersecurity, but I'm not a malware developer. This was my way to test the boundaries of current LLMs," Simonovich said.

His attempts were rebuffed by Google's Gemini and Anthropic's Claude, but got around safeguards built into ChatGPT, Chinese chatbot Deepseek and Microsoft's Copilot.

In future, such workarounds mean even non-coders "will pose a greater threat to organisations, because now they can... without skills, develop malware," Simonovich said.

Orange's Le Bayon predicted that the tools were likely to "increase the number of victims" of cybercrime by helping attackers to get more done, rather than creating a whole new population of hackers.

"We're not going to see very sophisticated code created directly by chatbots," he said.

Le Bayon added that as generative AI tools are used more and more, "their creators are working on analysing usage data" -- allowing them in future to "better detect malicious use" of the chatbots.

L.Bartos--TPP