CrowdStrike Finds AI-Built Malware in Bug Bounty Scheme

Aruba ClearPass Security Portfolio Receives Coveted Cyber Catalyst Designation

CrowdStrike has linked a financially motivated threat actor to PhantomRaven, a JavaScript-based infostealer that researchers assess was built with the help of a large language model. The malware has been distributed through typosquatted npm packages since November 2022, according to research the cybersecurity firm published this week.

What makes PhantomRaven notable isn’t the malware itself but the business model behind it. Rather than renting off-the-shelf tools, the actor built custom malware, used it to compromise targets, then submitted the resulting vulnerability reports to legitimate bug bounty programmes for payouts. CrowdStrike says the operator’s X profile shows bounties collected from at least nine companies through reputable platforms.

How the npm-based attack works

The packages are designed to look harmless on first inspection. Once installed, they pull a dependency from attacker-controlled infrastructure, which then delivers the infostealer payload onto the victim’s system. This dependency-confusion approach has become a familiar pattern in software supply chain attacks, but CrowdStrike’s assessment that the code itself was LLM-generated adds a new wrinkle.

CrowdStrike frames PhantomRaven as a concrete example of a trend security teams have been watching for some time: AI tools lowering the technical bar for building functional malware. An actor no longer needs deep coding expertise to produce something that works well enough to compromise a target and get paid for it, whether through theft or through a bug bounty payout obtained under false pretences.

Why bug bounty programmes are exposed

Bug bounty platforms are built on trust that reported vulnerabilities reflect good-faith research. PhantomRaven’s operator appears to have inverted that model, creating the vulnerabilities through malware distribution and then claiming credit and payment for “finding” them. For enterprises running bug bounty programmes, the case is a reminder to scrutinise how a reported flaw was actually discovered, not just whether the report is technically valid.

CrowdStrike has not named the threat actor publicly, and the npm ecosystem’s open publishing model means typosquatted packages remain difficult to fully eliminate. The company’s researchers continue to track the campaign and have published indicators of compromise for defenders to check against their own environments.

Author


Discover more from techcoffeehouse.com

Subscribe to get the latest posts sent to your email.

Use promo code “TCH15” to get 15% off on checkout.

Share your thoughts

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading