{"id":293499,"date":"2024-12-25T08:40:07","date_gmt":"2024-12-25T16:40:07","guid":{"rendered":"https:\/\/sftarticles.wpenginepowered.com\/es\/?p=346239"},"modified":"2025-07-01T15:35:47","modified_gmt":"2025-07-01T22:35:47","slug":"researchers-warn-about-the-use-of-generative-ai-to-evade-malware-detection","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/researchers-warn-about-the-use-of-generative-ai-to-evade-malware-detection\/","title":{"rendered":"Researchers warn about the use of generative AI to evade malware detection"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A recent analysis by <strong>Unit 42<\/strong> of <strong>Palo Alto Networks<\/strong> has revealed that language models like <strong>ChatGPT<\/strong> can be used to modify malware in JavaScript, making it more difficult to detect. Although these models do not generate malware from scratch, <strong>cybercriminals can ask them to rewrite or obfuscate existing malicious code<\/strong>. \u201cThese transformations are more natural, which complicates the identification of malware,\u201d <a href=\"https:\/\/unit42.paloaltonetworks.com\/using-llms-obfuscate-malicious-javascript\/\" target=\"_blank\" rel=\"noopener nofollow\" title=\"\">state<\/a> cybersecurity experts. This approach could degrade malware classification systems by <strong>confusing them into labeling malicious code as harmless<\/strong>.<\/p>\n\n\n<div class=\"sc-card-starred-link\">\r\n  <div class=\"sc-card-starred-link__body\">\r\n    <div class=\"sc-card-starred-link__row clearfix\">\r\n      <div class=\"sc-card-starred-link__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-starred-link__img\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2024\/09\/newsletter.png?GoogleAccessId=wp-stateless%40kubertonic.iam.gserviceaccount.com&Expires=1790595278&Signature=BykoBH0n1fF3z7NlQrcP%2BkB05QRHOf9lJFfKA%2FEMF9SxvN9lUjU6DFJmAqh8lGSktFDtNesD%2BO8Wz5pNxsBKtxfNQhY2JTyMV69%2BkOT3jJTIYxxnCIq475i580YTGWmqje4z%2B%2FqPQ9WOOmtAuS9lpLBDjv7oWHaza8f5s76cFJ4X3bye7mejvJSF0p%2FRJS0dAOmqiVuiBuZIrhMfTJtenjBOCecY5EsjqBGZ005y84GD5B2AhduhCwgHWTsFRjvJx9GU5QIlVGNLrE%2Fm84NfuG8VZQZvq6yq2yNlYzHpZpE1SN12zPXopVg7o4MjWqF0yQJRVmHWN1L2Q6Jw9KCvCg%3D%3D\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-starred-link__col-title\">\r\n        <p class=\"sc-card-starred-link__title\">Subscribe to the Softonic newsletter and get the latest in tech, gaming, entertainment and deals right in your inbox.<\/p>\r\n        <a class=\"sc-card-starred-link__button\" href=\"https:\/\/softonic.beehiiv.com\/subscribe\" target=\"_blank\" rel=\"noopener noreferrer sponsored\">Subscribe (it's FREE) \u25ba<\/a>\r\n      <\/div>\r\n    <\/div>\r\n    <a class=\"sc-card-starred-link__link\" href=\"https:\/\/softonic.beehiiv.com\/subscribe\" target=\"_blank\" rel=\"noopener noreferrer sponsored\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Despite the security restrictions implemented by providers like <strong>OpenAI<\/strong>, tools like <a href=\"https:\/\/www.softonic.com\/articulos\/asi-es-el-gemelo-malvado-de-chatgpt-que-ayuda-a-los-cibercriminales\" title=\"\"><strong>WormGPT<\/strong><\/a> are being used to create more convincing phishing emails and new types of malware. In October 2024, <strong>OpenAI blocked more than 20 malicious networks seeking to exploit its platform<\/strong>. In tests, Unit 42 managed to generate 10,000 variants of malicious JavaScript, maintaining its functionality but decreasing its detection scores in models like <strong>Innocent Until Proven Guilty<\/strong>. Among the techniques used are changes in variable names, insertion of junk code, and complete script rewriting.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Additionally, <strong>machine learning algorithms can be tricked into classifying these variants as benign in 88% of cases<\/strong>, according to Unit 42. Even the most popular tools, such as <a href=\"https:\/\/www.virustotal.com\/gui\/home\/upload\" target=\"_blank\" rel=\"noopener nofollow\" title=\"\"><strong>VirusTotal<\/strong><\/a><strong>,<\/strong> struggle to detect these codes. Researchers warn that these AI-based rewrites are harder to track than those generated by libraries like <a href=\"https:\/\/obfuscator.io\/\" target=\"_blank\" rel=\"noopener nofollow\" title=\"\"><strong>obfuscator.io<\/strong><\/a>. However, they suggest that these same techniques could improve detection models by generating more robust training data.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img decoding=\"async\" src=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/2\/2024\/12\/VirusTotal-problemas-deteccion-codigo-malicioso-IA.jpg\" alt=\"\" class=\"wp-image-346243\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">On another front, researchers from the <strong>North Carolina State University<\/strong> <a href=\"https:\/\/tches.iacr.org\/index.php\/TCHES\/article\/view\/11923\" target=\"_blank\" rel=\"noopener nofollow\" title=\"\">discovered<\/a> an attack called <strong>TPUXtract<\/strong>, which allows stealing AI models run on <strong>Google<\/strong>&#8216;s <strong>Edge<\/strong> TPUs through electromagnetic signals. However, although the technique is notable for its precision, <strong>it requires physical access to the device and specialized equipment<\/strong>, which fortunately limits its scope.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Additionally, <strong>Morphisec<\/strong> has <a href=\"https:\/\/blog.morphisec.com\/exploiting-trusted-systems-how-adversarial-attacks-can-manipulate-epss\" target=\"_blank\" rel=\"noopener nofollow\" title=\"\">demonstrated<\/a> that the <strong>Exploit Prediction Scoring System (EPSS)<\/strong>, used to assess vulnerabilities, can be manipulated with fake social media posts and empty repositories on GitHub. According to <strong>Ido Ikar<\/strong>, this technique <strong>allows \u201cinflating indicators\u201d and deceiving organizations<\/strong> by altering cyber risk management priorities.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"NordVPN\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/8713ac42-12d5-11e7-b114-c399bbcf470c\/3632015789\/nordvpn-logo\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">NordVPN<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/nordvpn.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/nordvpn.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A recent analysis by Unit 42 of Palo Alto Networks has revealed that language models like ChatGPT can be used to modify malware in JavaScript, making it more difficult to detect. Although these models do not generate malware from scratch, cybercriminals can ask them to rewrite or obfuscate existing malicious code. &#8220;These transformations are more natural, which complicates the identification of malware,&#8221; cybersecurity experts state. This approach could degrade malware classification systems by confusing them into labeling malicious code as harmless. Despite the security restrictions implemented by providers like OpenAI, tools [&hellip;]<\/p>\n","protected":false},"author":9256,"featured_media":283070,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":1},"categories":[1015],"tags":[],"usertag":[],"vertical":[],"content-category":[6771],"class_list":["post-293499","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","content-category-ai"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/293499","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9256"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=293499"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/293499\/revisions"}],"predecessor-version":[{"id":310341,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/293499\/revisions\/310341"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/283070"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=293499"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=293499"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=293499"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=293499"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=293499"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=293499"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}