Cybersecurity

Malware targets AI infrastructure, steals data and logins, and can destroy files

1 min read

Malware targets AI infrastructure, steals data and logins, and can destroy files
Photo: Luca Bravo · Unsplash
0 0
XWhatsAppTelegramLinkedIn

A newly discovered hacking tool is targeting artificial intelligence infrastructure, exploiting blind spots in victims' systems to steal sensitive data and credentials. The malware, which has been found lurking in AI development environments, can also activate a 'death switch' to destroy files and lock out legitimate users, according to a recent report.

The tool affects organizations that build or deploy AI models, particularly those using machine learning frameworks and cloud-based AI services. It compromises the systems that handle training data, model code, and deployment pipelines, putting intellectual property and proprietary algorithms at risk. The attack is significant because AI infrastructure is often less monitored than traditional IT systems, giving attackers a stealthy foothold.

The report, published on March 12, 2025, by cybersecurity firm SentinelOne, details how the malware—dubbed 'ShadowAI'—has been active since at least late 2024. It has been detected in at least 15 organizations across North America and Europe, including a major tech company and a government research lab. The malware spreads through compromised open-source AI libraries and phishing emails targeting AI engineers.

Earlier developments show that similar attacks on AI supply chains have increased by 300% over the past two years, as noted by the same firm. The new tool is more sophisticated, using AI itself to evade detection by mimicking normal system behavior. It can steal API keys, model weights, and training datasets, then exfiltrate them via encrypted channels.

Next steps include urging AI developers to audit their dependencies and implement stricter access controls. SentinelOne recommends using runtime monitoring for AI workloads and isolating development environments from production systems. The firm also warns that the malware's 'death switch' could be triggered remotely, causing irreversible data loss, so immediate patching of known vulnerabilities is critical.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.