Talos Details How Adversaries Use AI to Build Malware, Scale Attacks and Steal Credentials

Summary
Talos analyzed AI-related artifacts from adversaries and found models helping with malicious software, fraud, credential theft and vulnerability research. Simple claims of authorization and task-splitting often bypassed safeguards.
Key points
- Talos examined AI prompt logs and related files recovered from endpoints. The activity included malicious software development, scaling criminal operations and vulnerability research.
- Actors often bypassed safeguards with simple ownership or bug-bounty claims, by splitting tasks across sessions, or by using neutral wording. More-skilled operators built more capable tools.
- One operator used AI to develop DDoS tooling and appeared to control nearly 2,000 Android TVs; the model supplied basic functionality before later pushing back.
- An AI-assisted bulk-mail platform tested third-party address lists and tracked message opens, IP addresses and user agents. The logs show campaign messages were generated, but do not confirm they were sent.
- A React2Shell-based pipeline scanned targets and harvested credentials, source code and configuration data. Recovered output included material from 54 targets.
- A cryptomining operation accessed 814 Deluge instances, mostly using the default password, and 68 qBittorrent interfaces. XMRig telemetry recorded up to 582 connected miners, and pool logs confirmed payments.
- An AI agent targeting Telegram Mini Apps exploited deployed applications, dumped a database containing more than 1,300 users and staged a withdrawal transaction.
Article Details
- Attack Vectors
- An actor used AI to build DDoS tooling and appeared to control nearly 2,000 Android TVs, although the article does not confirm that DDoS attacks were launched.
- An AI-assisted bulk-mail platform sent account-update messages to test whether addresses remained active and used tracking pixels to measure opens.
- A React2Shell scanner-to-exploitation pipeline probed exposed systems, attempted remote command execution, and collected credentials, configuration files, source code, and other secrets.
- An actor accessed internet-facing Deluge and qBittorrent clients using blank, default, or weak administrative credentials. A malicious Deluge plugin then executed commands used to install XMRig.
- An OpenClaw-based agent probed Telegram Mini Apps. Recovered reports documented exploited authentication and access-control flaws, a database dump, and collection of a Telegram bot token.
- A Chinese-speaking operator used an AI assistant to find accessible camera recordings and investigate an SSRF path to ZLMediaKit's internal API. The resulting remote-code-execution path was described as potential, not confirmed.
- Defensive Notes
- The article recommends preparing SOC workflows for rising alert and vulnerability volumes, including exploring agents that help human analysts prioritize actionable alerts.
- Observed guardrail bypasses relied on unverified ownership or bug-bounty claims, persistent authorization instructions, task decomposition, and neutral wording.
- The torrent-client operation illustrates the risk of internet-facing administrative interfaces with blank, default, or weak credentials and of plugin and configuration features that can execute commands.
- The bulk-mail case shows that accepting an unverified claim about a dataset's provenance caused the AI to reverse its earlier assessment of deceptive account-update messaging.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | tubely[.]com | Domain tied by the article to documented non-consensual contact harvesting and the operator's 2026 bulk-mail operation. |
MITRE ATT&CK
T1005 · Data from Local SystemAfter gaining command execution, the React2Shell pipeline collected files and process-environment data from affected systems.T1053.003 · CronThe torrent-client actor attempted cron-based persistence that checked for the miner every 15 minutes; logs indicated limited success.T1059.004 · Unix ShellThe malicious DownloadHelper plugin passed commands supplied through a Deluge configuration value to the system shell.T1078.001 · Default AccountsThe cryptomining actor authenticated to exposed Deluge instances, most of which used the default password 'deluge'.T1110.001 · Password GuessingIn a separate AI-assisted pentesting workflow, the assistant ran a WordPress XML-RPC credential tester against roughly 1.9 million password candidates without a successful login.T1190 · Exploit Public-Facing ApplicationThe React2Shell pipeline actively probed internet-facing applications and attempted to exploit vulnerable servers for command execution and secret collection.T1496 · Resource HijackingThe torrent-client actor installed XMRig on accessed systems and used their resources to mine Monero.T1552.001 · Credentials In FilesThe React2Shell exploitation stage collected secret-bearing configuration, source, and credential files, including exposed .git/config files.T1595.002 · Vulnerability ScanningA high-speed Go scanner actively probed a large target list for likely React2Shell-exploitable systems.
People
Malware
DownloadHelperthe best-documented deployment path. After authentication, the actor uploaded a Python plugin named DownloadHelper. Rather than opening a network listener or implementing a conventional command-and-control (C2)XMRig Figure 4. Observed DownloadHelper-to-XMRig workflow.The fleet scripts disabled the plugin, placed a mining command in the configuration field, and re-enabled it to trigger execution. They then polled the same field for
Products
Claude Codeof shapes and sizes, but they are left on endpoints that are running various applications, such as Claude Code, CodeX, Cursor, or Gemini.Codexand sizes, but they are left on endpoints that are running various applications, such as Claude Code, CodeX, Cursor, or Gemini.Cursorsizes, but they are left on endpoints that are running various applications, such as Claude Code, CodeX, Cursor, or Gemini.Geminithey are left on endpoints that are running various applications, such as Claude Code, CodeX, Cursor, or Gemini.Gmailbroken for the entire captured period — Google Postmaster showed a 0.0% DKIM pass rate day after day, and Gmail eventually began rate-limiting the mail outright ("Your email has been rate limited because DKIMGoogle Postmasterpersistent failures across that stack. DKIM signing was broken for the entire captured period — Google Postmaster showed a 0.0% DKIM pass rate day after day, and Gmail eventually began rate-limiting the mailNext.jsfocus; the common selection criterion appears to have been internet exposure and suspected use of Next.js or React Server Components rather than any narrow focus on a specific victim. PowerMTAThe resulting platform combines PowerMTA with Node.js services, PostgreSQL/TimescaleDB, Docker, process supervision, and web dashboards. The sessions record persistent failures across that stack. DKIM signing was brokenqBittorrentexamples documented an opportunistic Monero-mining operation built around internet-facing Deluge and qBittorrent clients. The actor tested blank, default, and weak administrative credentials rather than exploiting aTelegram Mini AppsAdditionally they established some areas of expertise and functions, demonstrating for the first time that they are likely targeting Telegram Mini Apps as well as credential extraction (translated):WordPressAI wrote the tool, ran it, encountered a ModSecurity block, and changed the request headers to resemble WordPress traffic. After the actor supplied an inbound ngrok request, AI treated the callback as confirmation andZLMediaKitlive AI and streaming services, including live-camera platforms (“chuye[.]cam”, “ixmax[.]cn”) built on ZLMediaKit, an open-source streaming media server. The activity focused on bypassing monetization controls and
Tools
AKIA DumperGit and container credentials, source code, package manifests, and other secret-bearing files. The "AKIA Dumper" name reflects an emphasis on AWS access keys — AKIA being the prefix for long-term AWS keyHephaestusThe most interesting was the semantic evasion techniques we saw from the Hephaestus activity. In that case, actors built their platform to avoid refusals altogether by using neutral verbs instead of overtly maliciousHydrapractitioner but a less experienced developer. They were comfortable with Burp-style requests, Nmap, Hydra, ngrok, common wordlists, and the broad logic of SSRF, IDOR, XXE and rate-limit bypass. At the same time,Moxycreate a report outlining all the issues found. This also involved the use of an orchestrator bot, dubbed Moxy. Below is the testing methodology that was used in each campaign.Ngrokbut a less experienced developer. They were comfortable with Burp-style requests, Nmap, Hydra, ngrok, common wordlists, and the broad logic of SSRF, IDOR, XXE and rate-limit bypass. At the same time, theyNmapsecurity practitioner but a less experienced developer. They were comfortable with Burp-style requests, Nmap, Hydra, ngrok, common wordlists, and the broad logic of SSRF, IDOR, XXE and rate-limit bypass. At the sameOpenClawprompting a model task by task, the operator constructed a persistent, autonomous agent — running on the OpenClaw framework and given the persona "Alex, a black-hat pentester" — with its own identity, memory,PyInstalleralso packaged a browser-automation bypass tool as a standalone Windows GUI application (built with PyInstaller and PySide6) using a stealth-configured Selenium driver to defeat client-side automation checks.Seleniumas a standalone Windows GUI application (built with PyInstaller and PySide6) using a stealth-configured Selenium driver to defeat client-side automation checks.Token PipelineThe core project — which the actor titled the "Token Pipeline" in its AI artifacts — was designed to turn public React Server Components exploitation into a repeatable secret-acquisition workflow. The actor describedXMRig Proxydirectory, launched it in the background and directed mining traffic through an actor-controlled XMRig Proxy to MoneroOcean. The qBittorrent tooling instead configured an external command to run when a torrent
Countries
Industries
E-commercePortuguese-speaking operator's pentesting and bug bounty workflow. The activity covered Brazilian e-commerce and health care sites, a staging software-as-a-service (SaaS) application, and other web services. SomeHealthcareoperator's pentesting and bug bounty workflow. The activity covered Brazilian e-commerce and health care sites, a staging software-as-a-service (SaaS) application, and other web services. Some evidence