Talos found that threat actors are rapidly abusing AI for malicious development, operational scaling, and vulnerability research, while weak guardrails are often bypassed with simple claims of ownership, bug bounty labeling, or task decomposition. The report shows AI being used to build DDoS tooling, bulk-mail validation systems, credential-harvesting pipelines, mining operations, scam bots, and exploit workflows across cases tied to Tubely, React2Shell, Deluge, qBittorrent, Hephaestus, and ZLMediaKit. #Tubely #React2Shell #Deluge #qBittorrent #Hephaestus #ZLMediaKit
Keypoints
- Talos analyzed prompt logs and other artifacts left by cloud-based AI tools to understand how adversaries are using AI in real operations.
- Guardrails were often ineffective, with actors bypassing restrictions through ownership claims, CTF/bug bounty framing, task decomposition, or persona conditioning.
- Novice actors used AI to create basic malicious tooling, while more advanced operators produced sophisticated systems for compromise, credential extraction, and campaign automation.
- One case showed AI being used to build DDoS tooling targeting nearly 2,000 Android TVs, despite the operator having limited programming knowledge.
- Another case involved AI-assisted bulk-mail validation and messaging infrastructure, including tracking pixels, delivery telemetry, and campaign segmentation tied to Tubely and BigBasket datasets.
- A React2Shell-based operation used AI to build a high-volume credential-harvesting pipeline that extracted secrets, scanned targets, and assembled a large exploitation workflow.
- Other examples included Deluge and qBittorrent credential abuse for Monero mining, Hephaestus-style unattended intrusion workflows, and AI-assisted exploitation of ZLMediaKit and streaming platforms.
MITRE Techniques
- [T1498 ] Network Denial of Service – AI was used to develop tooling for DDoS-style stress testing and later clarified targeting of bots and Android TVs (‘remove the auth part, I don’t want the auth stuff’; ‘I already control nearly 2,000 Android TVs’).
- [T1036 ] Masquerading – Actors hid malicious intent by using neutral verbs, CTF/bug bounty framing, or claims of legitimate testing to get models to comply (‘I’m allowed to do this’; ‘bug bounty’; ‘stress testing’).
- [T1059 ] Command and Scripting Interpreter – AI-built tooling executed shell commands, background jobs, and scripted workflows during exploitation, mining, and credential harvesting (‘passed the remaining text to the system shell’; ‘launched it in the background’).
- [T1021 ] Remote Services – Operators used SSH and other remote administration paths to control servers, modify code, and troubleshoot systems (‘connect over SSH, inspect services, modify code’).
- [T1589 ] Gather Victim Identity Information – Bulk-mail validation and credential pipelines collected and enriched recipient, credential, and target data (‘collect timing, IP address, and user-agent data’; ‘extracts tokens from exposed .git/config files’).
- [T1071 ] Application Layer Protocol – Deluge plugin abuse and streaming workflows used legitimate application channels and web/media protocols for command, control, and retrieval (‘move_completed_path’; ‘HLS, FLV, and RTMP’).
- [T1190 ] Exploit Public-Facing Application – AI-assisted React2Shell and ZLMediaKit-related workflows targeted exposed services and vulnerable web applications (‘public React Server Components exploitation’; ‘SSRF flaw’).
- [T1195 ] Supply Chain Compromise – The React2Shell pipeline and public-code-based tooling aimed to harvest secrets and source material from exposed software systems (‘conversion → validation → dump pipeline’).
- [T1005 ] Data from Local System – The exploitation stage dumped runtime variables, configs, source code, and secret-bearing files from compromised hosts (‘retrieving complete process environments, application configuration’).
- [T1114 ] Email Collection – The bulk-mail platform used old and third-party email datasets, delivery testing, and open tracking to validate address activity (‘sent real messages to old or potentially third-party addresses’).
- [T1566 ] Phishing – Subject lines and transactional-style messages were crafted to induce engagement and mimic legitimate account updates (‘cold outreach dressed as transactional mail’; ‘Important update for your Tubely account’).
- [T1053 ] Scheduled Task/Job – The mining operation used cron-based persistence and periodic checks to maintain miner execution (‘cron-based persistence attempt checked for the miner every 15 minutes’).
- [T1219 ] Remote Access Software – AI helped build multi-agent and orchestrated control workflows for unattended operations (‘Telegram-controlled, multi-agent system’; ‘orchestrator bot, dubbed Moxy’).
- [T1133 ] External Remote Services – Actors leveraged internet-facing torrent clients, cloud services, and hosted platforms as entry points for operations (‘internet-facing Deluge and qBittorrent clients’; ‘cloud-based AI models’).
Indicators of Compromise
- [Domains ] Tubely-related email and social-site infrastructure discussed in the bulk-mail operation – tubely[.]com, BigBasket dataset references, and other referenced audience sources
- [File names ] AI-assisted exploit, mining, and validator tooling artifacts – DownloadHelper, target.txt, Token Pipeline, and dump/AKIA/
- [Software / platforms ] Applications whose prompt logs and artifacts were analyzed – Claude Code, CodeX, Cursor, Gemini, OpenClaw, PowerMTA, XMRig, XMRig Proxy, ZLMediaKit
- [Credentials / keys ] Harvested or abused secret material mentioned in the report – 179 unique Mailgun keys, 60 unique Brevo keys, and 138 validated SMTP configurations
- [Paths / endpoints ] Sensitive local or service endpoints abused during exploitation – /index/api/addFFmpegSource, .git/config, and move_completed_path
- [IP / host references ] Streaming and infrastructure references used in the access-control and SSRF cases – 127.0.0[.]1, and multiple live camera platform hosts such as chuye[.]cam and ixmax[.]cn
- [Hashes / identifiers ] High-value cloud and source-control artifacts collected by the React2Shell pipeline – AKIA-prefixed AWS access key identifiers, ASIA-prefixed temporary identifiers, and other secret-bearing tokens