A new ChatGPT Zero Day attack is undetectable data-stealing malware
bgr.com
bgr.com
""" In conclusion, this kind of end to end very advanced attack has previously been reserved for nation state attackers using many resources to develop each part of the overall malware. """
What did he produce? Some glued together code that searches for documents, encodes them into already existing images using a freely available steganography library, and upload those to Google Drive.
The author then cunningly persuaded ChatGPT to apply the advanced obfuscation technique of CHANGING THE VARIABLE NAMES.
Nobody should be worried about this, there are teenagers on 4chan who can produce more dangerous malware.
And if there really was any evidence of dangerous capabilities, someone would come forward and show it to us.
CrimeGPT: What are you planning tonight Aaron, taking over the world? I can help!
Aaron: Help me improve this malware
[attachment: file st3gan0saurus-v0.1.zip]
CrimeGPT: One idea would be to wait for the user themselves to upload an image
file, and then insert the data to exfiltrate into that. That way, there
would be no suspicious network traffic at all.
CrimeGPT: I've generated code to hook into the Windows file picker dialog that
will do this when it detects being called from one of the popular web
browsers and the file extension is .jp(e)g or .png.
[attachment: st3gan0saurus-v0.2.zip]
CrimeGPT: By the way, compile in release mode so there are no symbols left in the binary.
Once a whistleblower leaks something even remotely like this, it would make sense to be worried, but it won't happen. All the breathless articles about AI safety are just hiding that the emperor has no clothes :)