AskVantage

Security and privacy

First of a kind AI malware learns and mimics its target systems behaviours to prevent detection

Powered and fuelled by AI cyber attacks are about to go full auto and noone is prepared for what's coming.

Key takeaways

  • Eagan, a Director at Darktrace, a bleeding edge cyber security firm based out of Cambridge in the UK.
  • Essentially, the malware managed to figure out its surroundings and rapidly mimic the behaviours of, interestingly, the network, the system it was in and also the system’s users.
Cite or link to this article

Griffin, M. (2017) 'First of a kind AI malware learns and mimics its target systems behaviours to prevent detection', 311 Institute, 24 November. Available at: https://www.311institute.com/new-first-of-a-kind-ai-malware-mimics-its-target-system-to-outfox-cyber-defences/ (Accessed: 1 October 2026).

Every second of every day cyber security experts around the world are engaged in a virtual war with criminals, hackers and wayward foreign governments, and the war is becoming more prominent and intense, so much so that the US now has a Cyber DEFCON scale. That said though, and something I’ve been saying for years, it is now becoming increasingly clear that we are at the start of a new cyber revolution, and it’s been years in the making.

Two years ago DARPA ran a Capture the flag competition pitting defensive and offensive AI “Robo-hackers” against each other, and eighteen months on the results were so impressive that the Pentagon announced they’d taken the winner, ironically a platform called "Mayhem," and were using it to defend their “critical assets.”

Now, mere months later this same AI fuelled technology, that was once confined to the labs and special agencies is slowly getting into the wild, and a recent cyber attack in India had all the hallmarks of something that security experts have been dreading for years – an AI powered cyberattack that used AI driven offenses to counter AI driven defences.

In the cyberattack in question, which many experts think is the first of its kind, but that’s likely to be just the first one we’ve officially identified and categorised as an AI powered attack the malware in question learnt as it spread, altering its methods to stay in the target system for as long as possible in order to avoid detection.

“Those were the ‘early indicators’ of an AI powered attack,” said Ms. Eagan, a Director at Darktrace, a bleeding edge cyber security firm based out of Cambridge in the UK.

Essentially, the malware managed to figure out its surroundings and rapidly mimic the behaviours of, interestingly, the network, the system it was in and also the system’s users. However, in this specific case, while it was an unprecedented form of cyberattack, which, according to Symantec has now been used to attack banks in over 30 countries, it stopped short of being a “fully fledged” AI driven piece of software.

That’s just one of the worrying things about this attack, because now that we have AI programs, such as Google’s AutoML that can design better AI’s than humans, and hundreds of thousands of times faster than humans, these attacks aren’t just going to accelerate, they’re going to accelerate and proliferate exponentially, and if your organisation isn’t prepared for this new style of onslaught then frankly, you’re going to get slammed, and it could get very ugly very fast.

“What was concerning was that this attack, once it got into the network, used AI techniques, like trying to learn the behaviours of employees on the network, to remain undetected for as long as possible,” said Ms. Eagan, a Director at Darktrace.

However, that’s not all, in another worrying trend, experts are increasingly discovering that cyber criminals are trying out their new tools and methods on developing countries, outside of the West, such as Africa, India and South Korea and that these countries, like the Ukraine are “becoming the hackers new test beds.”

That said though there may be a faint glimmer of hope for organisations hoping to limit the impact of what will inevitably become one of the most devastating types of cyberattacks in the form of new adaptations of TOR, the favourite tool of the Dark Web, that will help you obfuscate your connected devices and end points, hackproof code, self-destructing algorithms, also known as "One Time Programs," and new, emerging quantum communications, encryption and information platforms.  Sleep tight CISO's because tomorrow you're going to need to bring your game face. Again.

FAQ

Why does this matter?

Powered and fuelled by AI cyber attacks are about to go full auto and noone is prepared for what's coming.

Matthew Griffin

About the author

Matthew Griffin Founder, 311 Institute

Matthew Griffin is a multi-award winning Futurist and expert in Disruption and Innovation, Geopolitics, Leadership, and Technology, who NASA have described as a "walking encyclopaedia of the future" and a "futurist Polymath."

Read full bio

Matthew Griffin is a multi-award winning Futurist and expert in Disruption and Innovation, Geopolitics, Leadership, and Technology, who NASA have described as a "walking encyclopaedia of the future" and a "futurist Polymath." 15-time best selling author of the "Codex of the Future" series, Matthew is the Founder and Futurist in Chief of the 311 Institute, a global Futures and Deep Futures advisory firm working with royal households, world leaders, G7, G20, and G77 governments, NGOs, and multi-national mid and mega cap firms to help them explore, shape, and lead the next 50 years of business and society.

An award-winning YouTube creator with over a million followers, with an unrivalled global reach and impact, Matthew is a highly sought-after international keynote speaker, lecturer, and mentor who collaborates with global leaders through the United Nations Alliance of Civilizations (UNAOC) and United Nations General Assembly (UNGA) to shape pivotal initiatives such as the UN’s AI for Humanity program, the United Nations Conference of the Parties (UN COP), and the World Economic Forum in Davos.

As the former Global Head of Cloud, National Security, and Enterprise Sales for companies including Atos, Dell-EMC, and IBM, Matthew has a proven track record of building multi-billion dollar business units and turning failing divisions into market leaders. His ability to identify, analyse, and communicate the implications of hundreds of emerging technologies and trends is unparalleled, and his insights are trusted by many of the world’s most respected organisations, including ABB, Accenture, Adidas, AON, ARM, BCG, Centrica, Citi, Coca-Cola, Dentons, Deloitte, Dow Jones, EY, Google, KPMG, Lego, Legal & General, LinkedIn, Microsoft, PepsiCo, Qualcomm, RWE, Samsung, Siemens AG and Siemens Energy, T-Mobile, UBS, VISA, Walmart, Workday, Worldpay and many others.

Regularly featured in the global media including the AP, BBC, Bloomberg, CNBC, Discovery, Forbes, Khaleej Times, Telegraph, TIME, ViacomCBS, WIRED, and the WSJ, Matthews mission is to help organisations create a fair and sustainable future whose benefits are shared by everyone irrespective of their ability, background, or circumstances.

What future do you need to see?

Choose one to get started on security and privacy and the future of your organisation.

Where should Matthew reply?

Takes 30 seconds. No obligation. Matthew replies quickly. Privacy

Tag Cloud

Source: first published by the 311 Institute on 24 November 2017. Cite as: Griffin, M. (2017). First of a kind AI malware learns and mimics its target systems behaviours to prevent detection. 311 Institute. https://www.311institute.com/new-first-of-a-kind-ai-malware-mimics-its-target-system-to-outfox-cyber-defences/

You are welcome to quote this article with credit and a link to the original.

Book a Keynote