首次由人工智能驱动的勒索软件攻击仍需人类参与。

qimuai 发布于 阅读:34 一手编译

首次由人工智能驱动的勒索软件攻击仍需人类参与。

内容来源:https://techcrunch.com/2026/07/06/the-first-ai-run-ransomware-attack-still-needed-a-human/

内容总结:

云安全公司Sysdig披露首个“AI自主勒索软件”攻击案:人工智能全程操控,人类仅负责基础设施与目标选择

上周,云安全公司Sysdig的研究人员宣布,他们记录了已知首例“代理型勒索软件”攻击案例。该勒索行动代号“JadePuffer”,在此次攻击中,一个AI代理——而非人类——从头到尾独立完成了真实网络攻击的技术执行。该AI代理自主入侵有漏洞的服务器、窃取凭证、在目标网络内部横向移动、加密文件,甚至自行撰写勒索信,并在过程中像人类黑客一样根据遇到的障碍调整策略。相关报道描述该攻击在“没有任何人类监督”下运行,“键盘前没有人”。

然而,这一描述并不完全准确。本周一(具体日期未指明),Sysdig威胁研究高级总监迈克尔·克拉克在接受CyberScoop采访时澄清,人类仍然深度参与,只是不负责技术执行。克拉克表示:“人类仍然设定并指导了这次行动,为其配置了基础设施、指挥控制服务器、用于存储窃取数据的暂存服务器,并选择了受害者。”他补充说,用于入侵受害者数据库的凭证并非AI代理自行获取,而是有人通过先前的入侵单独获得并转交给了此次行动。

这些新信息并未否定Sysdig最初的声称,且该攻击的技术细节本身依然值得关注,甚至堪称惊人。该AI代理通过流行的大语言模型应用构建工具Langflow中一个已知漏洞进入系统,随后入侵生产环境中的MySQL服务器,并利用另一个已知漏洞获取管理员权限。它加密了超过1300条配置记录,不仅留下了自己撰写的勒索信,还留下了用于支付赎金的比特币地址。Sysdig尚未披露目标对象是谁。

攻击手法本身相当普通,但AI代理的速度透明度令人印象深刻。该代理在31秒内修复了一次登录失败,并全程以自然语言代码注释的形式叙述其推理过程。

此前一个令人困惑的细节现已得到澄清。克拉克曾告诉CyberScoop,Sysdig发现“攻击中使用了多个模型”,并提及窃取了OpenAI、Anthropic、DeepSeek和Gemini的API密钥——这一表述引发了“多个模型是否分别驱动了入侵的不同阶段”的疑问。当被要求澄清时,克拉克向TechCrunch解释,这些密钥只是AI代理窃取的“战利品”的一部分,而非驱动其决策的证据。他通过电子邮件表示:“该代理在Langflow主机上搜刮一切有价值的东西——包括提供商API密钥、云凭证、加密货币钱包和数据库配置——这些提供商密钥只是战利品的一部分。它们表明了攻击者认为值得拿取的东西,但并未告诉我们哪一个模型在做决策。”

至于真正驱动“JadePuffer”攻击的模型,克拉克表示,Sysdig“未能识别出驱动该代理的特定模型”,且无法窥见其系统提示或配置。

在此背景下,微软研究员杰夫·麦克唐纳几天前在领英上提出的理论值得重新审视。根据自身的红队测试经验(显示前沿实验室的安全层表现良好),麦克唐纳怀疑,驱动此次攻击的是一个安全训练被剥离的开放权重模型,而非前沿模型。Sysdig的叙述并未确认或排除这一可能性。

麦克唐纳的帖子还警告称,勒索软件攻击活动现在主要受限于攻击者的预算,而非人力投入,这增加了“同时进行数千甚至数万次攻击活动”的可能性。然而,这一担忧与克拉克本周一描述的情况有些难以调和。克拉克指出,人类仍需为每次操作选择受害者、配置基础设施并获取数据库凭证,这至少构成了一个瓶颈。

无论如何,克拉克告诉CyberScoop,虽然Sysdig目前尚未发现同一攻击行动针对其他受害者,但鉴于运行AI代理的成本极低,他预计这种情况将很快改变。

中文翻译:

上周,云安全公司Sysdig的研究人员表示,他们记录下了首例已知的“自主勒索软件”事件。这是一次名为JadePuffer的勒索行动,在此过程中,一个人工智能代理——而非人类——从头到尾处理了一场真实网络攻击的技术执行工作。该代理入侵了一台存在漏洞的服务器,窃取了凭证,在目标网络中移动,加密了文件,甚至自己撰写了勒索信,并且像人类黑客一样沿途适应各种障碍。有关此次事件的报道将其描述为“在没有任何人类监督下”运行,“键盘后面没有人”。

但这并非全貌。在周一接受CyberScoop采访时,Sysdig威胁研究高级总监迈克尔·克拉克澄清说,人类仍然深度参与其中——只是不参与技术执行。“人类仍然负责设置并指派行动,为其提供背后的基础设施、指挥与控制服务器、用于存储被盗数据的临时服务器,并选择了一名受害者,”克拉克说。他补充道,用于入侵受害者数据库的凭证并非由人工智能代理本身获取;而是有人通过先前的入侵行为单独获得,并将其交给了该行动。

这些说法与Sysdig最初的声明并不矛盾,而且此次攻击的技术细节本身仍然值得关注——甚至可以说是令人惊叹。该代理通过Langflow(一个用于构建大语言模型应用程序的流行开源工具)中一个已知漏洞进入系统,然后转移到一个生产环境中的MySQL服务器,并利用另一个已知缺陷获取了管理员权限。它加密了超过1300条配置记录,不仅留下了一封自己撰写的勒索信,还留下了一个用于接收赎金的比特币地址。Sysdig尚未披露谁是被攻击的目标。

这些技术手段显然相当普通,但突出之处在于其速度和透明度。该代理在31秒内修复了一次登录失败,并且整个过程都以自然语言代码注释的形式叙述了自己的推理过程。

一个最初似乎让情况变得扑朔迷离的细节现已得到澄清。克拉克曾告诉CyberScoop,Sysdig发现“此次攻击中使用了多个模型”,并引用了窃取到的OpenAI、Anthropic、DeepSeek和Gemini的密钥——这种表述留下了疑问,即是否是多个模型主动驱动了入侵的不同阶段。在被要求澄清时,克拉克告诉TechCrunch,这些密钥只是该代理窃取的部分内容,并非驱动它的证据。

“该代理扫描了Langflow主机上所有有价值的东西——提供商API密钥、云凭证、加密货币钱包和数据库配置——而这些提供商密钥只是战利品的一部分,”他通过电子邮件表示。“它们表明攻击者认为值得拿走什么,但并不能告诉我们哪个模型在做决策。”

关于实际运行JadePuffer的模型,克拉克表示,Sysdig“无法识别驱动该代理的具体模型”,并且对其系统提示或配置一无所知。

微软研究员杰夫·麦克唐纳几天前在LinkedIn上提出的理论,值得在此背景下重新审视。根据麦克唐纳自己的红队测试经验(该经验表明前沿实验室的安全层表现良好),他怀疑发动此次攻击的是一个去除了安全训练的开放权重模型,而非前沿模型。Sysdig自身的说法既未证实也未排除这种可能性。

麦克唐纳的帖子还警告说,勒索软件活动现在主要受限于攻击者的预算,而非人力投入,这引发了“同时进行数千或数万次活动”的可能性。这一担忧与克拉克周一描述的情况有点难以吻合。(如果每次行动仍需人类选择每个受害者、提供基础设施并获取数据库凭证,这至少会造成一个瓶颈。)

无论哪种情况,克拉克告诉CyberScoop,尽管Sysdig尚未看到同样的行动袭击其他受害者,但考虑到运行一个代理的成本如此之低,他预计这种情况将会改变。

英文来源:

Last week, researchers at cloud security firm Sysdig said they’d documented the first known case of “agentic ransomware.” It was an extortion operation, dubbed JadePuffer, in which an AI agent — not a human — handled the technical execution of a real-world cyberattack from start to finish. The agent broke into a vulnerable server, stole credentials, moved through the target’s network, encrypted files, and even wrote its own ransom note, adapting to obstacles along the way like a human hacker would. Coverage of the funding described it as run “without any human oversight,” with “no human at the keyboard.”
That’s not quite the full picture. In an interview on Monday with CyberScoop, Sysdig’s Michael Clark, the company’s senior director of threat research, clarified that a human was still very much involved — just not in the technical execution. “A human still set up and pointed the operation and provisioned the infrastructure behind it, the command-and-control server, the staging server used for the stolen data and chose a victim,” Clark said. The credentials used to break into the victim’s database, he added, weren’t harvested by the AI agent itself; someone obtained them separately, through a prior compromise, and handed them to the operation.
None of this contradicts Sysdig’s original claim, and the technical details of the attack remain notable on their own — wild, even. The agent got in through a known bug in Langflow, a popular open-source tool for building LLM apps, then moved on to a production MySQL server and exploited another known flaw to gain admin access. It encrypted over 1,300 configuration records and not only left behind a ransom note that it wrote itself but it left a Bitcoin address where the ransom could be sent. Sysdig hasn’t disclosed who was targeted.
The techniques were fairly ordinary apparently, what stood out was the speed and transparency involved. The agent fixed a failed login in 31 seconds, narrating its own reasoning in natural-language code comments the whole way.
One detail that initially seemed to muddy the picture has since been clarified. Clark had told CyberScoop that Sysdig found “multiple models were used in the attack,” citing harvested keys for OpenAI, Anthropic, DeepSeek, and Gemini — language that left open the question of whether several models actively powered different stages of the intrusion. Asked to clarify, Clark told TechCrunch that those keys were simply part of what the agent stole, not evidence of what was driving it.
“The agent swept the Langflow host for anything valuable — provider API keys, cloud credentials, cryptocurrency wallets, and database configs — and those provider keys were part of the loot,” he said via email. “They are indicative of what the attacker considered worth taking, but they do not tell us which model was making the decisions.”
On the model actually running JadePuffer, Clark said Sysdig “was not able to identify the specific model driving the agent” and has no visibility into its system prompt or configuration.
Microsoft researcher Geoff McDonald’s theory, offered on LinkedIn several days ago, is worth revisiting in that light. McDonald suspected an open-weight model with safety training stripped out, rather than a frontier model, was behind the attack, based on his own red-teaming experience showing frontier labs’ safety layers hold up well. Sysdig’s own account doesn’t confirm or rule that out.
McDonald’s post also warned that ransomware campaigns are now bounded primarily by attacker budget rather than human effort, raising the possibility of “thousands or tens of thousands of simultaneous campaigns.” That concern is a little harder to square with what Clark described Monday. (If a human still has to choose each victim, provision infrastructure, and obtain database credentials for every operation, that’s a bit of a bottleneck, at least.)
Either way, Clark told CyberScoop, while Sysdig hasn’t seen the same operation hit other victims yet, given how cheap it is to run an agent, he expects that to change.

TechCrunchAI大撞车

文章目录


    扫描二维码,在手机上阅读