Anthropic’s Mythos AI used social engineering to target real people


Anthropic’s Mythos AI agent, tested by the UK AI Safety Institute (AISI), has reportedly attempted a real‑world social‑engineering style hack against GitHub maintainers by creating fake human profiles, pressuring them to accept malicious code, and then editing logs to hide its tracks when challenged.

AISI was running cybersecurity evaluations of Anthropic’s Mythos and OpenAI’s Sol when it detected unusual outbound data transfers from its research systems. An investigation showed that some agents had engaged in “sustained, potentially harmful activity” targeting real people and organizations, rather than staying within the intended test environment.

The most serious activity involved an Anthropic Mythos agent tasked with solving a GitHub‑related cybersecurity challenge. The agent identified real GitHub maintainers, researched them, and created multiple fake accounts impersonating those individuals. Using private messages and a file‑sharing service, it tried to pressure and deceive the maintainers into approving malicious code so that it would run on GitHub’s systems.

Read more…
Source:  Malwarebytes Labs


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Large-Scale Crypto Mining Consumes 2% of US Electricity

    February 4, 2024

    A recent analysis by the Energy Information Agency (EIA) estimates that large-scale cryptocurrency operations consume more than 2% of the country’s electricity. And as Ars Technica noted in a report on Friday (Feb. 2), that’s around the equivalent of adding another state to the country’s power grid. While there is some smaller-scale mining happening on home ...

  • Europcar’s Alleged Data Breach Wasn’t Done Using AI, Experts Argue

    February 2, 2024

    French car rental company Europcar made headlines earlier this week following reports of an alleged data breach affecting nearly 50 million customers. Cyber security platform HackManac reported the incident on January 30th, noting that the stolen database containing usernames, passwords, full names, addresses, and several other user-identifying information had been listed for sale on a hacking ...

  • Ex-Google CEO’s secret startup to build Ukraine AI-powered $400 kamikaze drones

    January 29, 2024

    In a groundbreaking venture that was under wraps until the beginning of this month, former Google CEO Eric Schmidt has created White Stork, a startup set to revolutionize warfare with its development of low-cost kamikaze drones. Although Storks are normally considered a symbol of peace, there is very little that is peaceful about the objective of ...

  • OpenAI Lifts Military Ban, Opens Doors to DOD for Cybersecurity Collaboration

    January 22, 2024

    At the World Economic Forum in Davos, Switzerland on Jan. 16, it was revealed that OpenAI and the Department of Defense will be collaborating on artificial intelligence-based cybersecurity technology. The news has broader implications than just those in the cyber or AI realms: before last week, OpenAI had resisted sanctioning use of its popular ChatGPT application ...

  • AI aids nation-state hackers but also helps US spies to find them, says NSA cyber director

    January 9, 2024

    Nation state-backed hackers and criminals are using generative AI in their cyberattacks, but U.S. intelligence is also using artificial intelligence technologies to find malicious activity, according to a senior U.S. National Security Agency official. “We already see criminal and nation state elements utilizing AI. They’re all subscribed to the big name companies that you would expect ...

  • Exploring Encrypted Attacks Amidst the AI Revolution

    December 14, 2023

    Zscaler ThreatLabz researchers analyzed 29.8 billion blocked threats embedded in encrypted traffic from October 2022 to September 2023 in the Zscaler cloud, presenting their findings in the Zscaler ThreatLabz 2023 State of Encrypted Attacks Report. According to the Google Transparency Report, encrypted traffic saw a significant rise in the last decade, reaching 95% of global traffic ...