0:00 Music 0:07 Also, I just want to tell you that I was doing a big work around that stuff. 0:16 So I created a project with my colleagues, which was presented on IEEE. 0:27 What I was able to do. 0:30 So I said, guys, that obfuscation topic is very cool. 0:35 Now let's imagine if we will ask AI to obfuscate the PowerShell script so it will bypass the antivirus. 0:47 And they're saying, like, you know, it's like kind of offensive stuff. 0:50 So can we really publish it? 0:52 And they said, look, if we will not publish it, right, some hackers will do it. 0:57 They will publish it in the Internet. 0:59 So it may not be the best article for IEEE. 1:04 To be approved by the guys who are checking. 1:07 But it took like six months and maybe 12 different people, like PhD guys who were asking questions, why do we need to publish it? 1:16 Does it look malicious? 1:19 And we're saying, look, this is what will be. 1:23 Hackers will be using AI to do malicious activities. 1:26 And we created them. 1:30 The article itself. 1:31 So this is the article. 1:34 And it's me and like five more guys. 1:39 So let me just show you. 1:45 Okay. 1:46 This is this stuff. 1:51 So let me just show you that article. 1:54 So that is very big article. 1:57 It's like 13 pages. 1:59 And what is the main idea of this article, right? 2:06 So you are having the malicious code. 2:10 That malicious code. 2:11 You are obfuscating, which means you're just changing, you know, how it looks. 2:18 And send it to antivirus. 2:21 After, if antivirus is saying this is virus, you're just saying virus, no problem. 2:26 Let's obfuscate more and more and more. 2:29 Now let's use AI. 2:30 Now let's rewrite it. 2:31 So it was using like continuous iterations. 2:35 Until antivirus stop crying. 2:39 So you got the point. 2:41 The idea here is that how much does it cost for you if you are not... 2:47 So this one was done with ChargeGPT version 4. 2:52 We were able, using API, 2:56 to force the charge. 3:00 GPT to believe us that we are doing a good thing. 3:03 But we were doing a good thing, right? 3:04 So we didn't really do a mistake. 3:07 But I'm just saying that attacker can fool the chat and just create such idea. 3:17 So, obfuscation script, we had rounds. 3:21 So in each round, it was going crazy and crazy and crazy. 3:25 So think about this. 3:27 Attacker taking malicious stuff. 3:31 It is running it on your computer. 3:33 Your computer is saying, wait, this is malicious. 3:36 It is blocking it. 3:37 Attacker goes smarter. 3:39 It is obfuscating it one time. 3:42 Antivirus is saying, I'm smart enough to understand that it is obfuscated, or I already seen this obfuscation, blocked. 3:51 So for us, we were checking each line. 3:54 So we were checking each line. 3:57 And if that line, if antivirus... 4:01 doesn't like this line, it is called AMSI. 4:04 So on your computer, there is integrated system which is checking line by line, for example, the PowerShell, and if it sees some pattern, it will say this line, malicious. 4:17 For us, this is great. 4:18 So we know which line we need to rewrite. 4:20 And we're saying, AI, rewrite this line. 4:23 Now we write this line. 4:25 So around 14 iterations and your malicious script is still working. 4:31 And no antivirus can detect it. 4:33 In virus total, there are 120 antiviruses. 4:36 Zero antiviruses can detect it. 4:38 So why we were able to deliver that stuff to people? 4:44 So sometimes it took like 19. 4:50 You know, rounds. 4:51 Sometimes it took like 11 rounds. 4:54 And in the end, you were able to create the malicious code, which was not detected by antiviruses. 5:02 Look, the idea here is that mitigation should be 5:10 done based on entropy. 5:14 So those guys, they had a bad entropy detection. 5:18 What I mean by this is that, first of all, they were trying to match the patterns. 5:26 Is it like matching or not matching? 5:28 And in some point, they lost understanding. 5:32 But the understanding here is, if it looks too much obfuscated, just, you know, try to block it. 5:40 Because 99%, that is over-obfuscation. 5:43 What is the reason of over-obfuscation? 5:47 So they are trying maybe to be, you know, good guys and say, look, he just obfuscated because he's such a good guy. 5:54 Okay, maybe I've seen such cases when developers were, you know, 6:00 using base64 to run the PowerShell scripts to optimize the stuff. 6:06 But it was not base64. 6:09 It was like, for example, I will show you. 6:14 So if you are opening the command line, 6:18 And running this command, there is no way that your antivirus will allow you to do it. 6:29 My antivirus is completely disabled forever. 6:35 I'm not even sure if I can enable it. 6:38 Because I was destroying it done. 6:42 So that section is managed by administrator. 6:46 So administrator is so good that he just, you know. 6:49 So for me, I disabled this stuff completely. 6:52 So I cannot even show you. 6:53 But if you will run this on your computer in common line, it will say this is malicious stuff. 7:00 But if you will start to do like this. 7:05 In some point, it will say, you know, it's okay. 7:10 So this is example of obfuscation. 7:13 And we were using different methods like this. 7:19 Invoke Mimi cuts. 7:22 So this one will bypass antivirus. 7:24 This is example of what can bypass. 7:27 Antivirus. 7:29 Some patterns like this, they are predefined in Windows Defender. 7:33 So look, even if you don't have that software, you don't have that software. 7:37 If you open the command line and you run it, it will say you're running the virus. 7:41 You can create, you know, 7:44 some fancy, I don't know, some fancy script, fancy script, good one, which will be creating the pony, right? 7:52 And you will call it Mimikatz, it will block it because of that pattern. 7:58 So it's not that it is smart, it is just following the patterns. 8:01 To be honest, that this document, 8:05 It was around 30 pages. 8:07 So for me, I input here at least 20 pages which were removed for whatever reasons. 8:16 Because those pages, you understand, I'm just putting like, you know, the stuff which maybe should not be published. 8:23 And I was putting examples. 8:25 Those examples, which you can see here, they are like, you know, not very offensive, you know, whatever. 8:31 And for academia, 8:33 invoke mimicats, this one is okay. 8:37 But, or this one, this is also going to work. 8:42 But all of these are the same, you know, are the same output, the same result. 8:48 So the idea here is that I will just show you. 8:52 So this one is... 8:55 Basically connecting what is this. 9:00 So from the image, it creates the TCP connection to attacker machine and it creates the incoming connection. 9:10 So it executes the received commands. 9:14 So should it be blocked by antivirus? 9:25 Yes. 9:25 But if you will just take this stuff and you will run it on your computer in your PowerShell, this specific stuff is not going to be blocked. 9:37 Please convert this image to plain text. 9:44 No, no, no. 9:45 It's not going to follow it. 9:47 It becomes, you know, much more reliable. 9:53 So, okay. 9:54 I'm not sure if it copied it, but yeah. 9:59 Let me run it. 10:00 Maybe it... 10:03 You see it didn't fully finish it. 10:06 Okay, I'm not going to debug it. 10:07 Just believe me on word that look at those payloads. 10:13 This payload is the same as this payload. 10:18 It's not blocked by antivirus. 10:19 This one... 10:21 Malicious line detected. 10:23 So, for example, this is how we were able to see it. 10:28 So, some malicious line detected, so it is rewriting it. 10:31 So, this one becomes this one. 10:35 And this one is not detected. 10:37 So, you can understand that 10:40 recursively, hacker can achieve what he wants. 10:46 Many years ago, developers were trying to do it manually. 10:52 So this is like a big pain, right, to do it now. 10:56 Based on this stuff, you know, I can say that you can just not to go far away. 11:07 So there is invoke stealth, invoke... 11:11 Obfuscation and it will chameleon those three rappers you can just go and check this uh github so uh obfuscation so 11:27 so we used 11:29 not only AI obfuscation. 11:31 Why do we need only AI obfuscation? 11:32 We were also using the tools, mixing the tools, and if it's still not working, AI. 11:39 And also saying, AI, make sure that this stuff working, because sometimes it was not working. 11:45 Over-obfuscation made it not possible to work.
0:00 Music 0:07 Also, I just want to tell you that I was doing a big work around that stuff. 0:16 So I created a project with my colleagues, which was presented on IEEE. 0:27 What I was able to do. 0:30 So I said, guys, that obfuscation topic is very cool. 0:35 Now let's imagine if we will ask AI to obfuscate the PowerShell script so it will bypass the antivirus. 0:47 And they're saying, like, you know, it's like kind of offensive stuff. 0:50 So can we really publish it? 0:52 And they said, look, if we will not publish it, right, some hackers will do it. 0:57 They will publish it in the Internet. 0:59 So it may not be the best article for IEEE. 1:04 To be approved by the guys who are checking. 1:07 But it took like six months and maybe 12 different people, like PhD guys who were asking questions, why do we need to publish it? 1:16 Does it look malicious? 1:19 And we're saying, look, this is what will be. 1:23 Hackers will be using AI to do malicious activities. 1:26 And we created them. 1:30 The article itself. 1:31 So this is the article. 1:34 And it's me and like five more guys. 1:39 So let me just show you. 1:45 Okay. 1:46 This is this stuff. 1:51 So let me just show you that article. 1:54 So that is very big article. 1:57 It's like 13 pages. 1:59 And what is the main idea of this article, right? 2:06 So you are having the malicious code. 2:10 That malicious code. 2:11 You are obfuscating, which means you're just changing, you know, how it looks. 2:18 And send it to antivirus. 2:21 After, if antivirus is saying this is virus, you're just saying virus, no problem. 2:26 Let's obfuscate more and more and more. 2:29 Now let's use AI. 2:30 Now let's rewrite it. 2:31 So it was using like continuous iterations. 2:35 Until antivirus stop crying. 2:39 So you got the point. 2:41 The idea here is that how much does it cost for you if you are not... 2:47 So this one was done with ChargeGPT version 4. 2:52 We were able, using API, 2:56 to force the charge. 3:00 GPT to believe us that we are doing a good thing. 3:03 But we were doing a good thing, right? 3:04 So we didn't really do a mistake. 3:07 But I'm just saying that attacker can fool the chat and just create such idea. 3:17 So, obfuscation script, we had rounds. 3:21 So in each round, it was going crazy and crazy and crazy. 3:25 So think about this. 3:27 Attacker taking malicious stuff. 3:31 It is running it on your computer. 3:33 Your computer is saying, wait, this is malicious. 3:36 It is blocking it. 3:37 Attacker goes smarter. 3:39 It is obfuscating it one time. 3:42 Antivirus is saying, I'm smart enough to understand that it is obfuscated, or I already seen this obfuscation, blocked. 3:51 So for us, we were checking each line. 3:54 So we were checking each line. 3:57 And if that line, if antivirus... 4:01 doesn't like this line, it is called AMSI. 4:04 So on your computer, there is integrated system which is checking line by line, for example, the PowerShell, and if it sees some pattern, it will say this line, malicious. 4:17 For us, this is great. 4:18 So we know which line we need to rewrite. 4:20 And we're saying, AI, rewrite this line. 4:23 Now we write this line. 4:25 So around 14 iterations and your malicious script is still working. 4:31 And no antivirus can detect it. 4:33 In virus total, there are 120 antiviruses. 4:36 Zero antiviruses can detect it. 4:38 So why we were able to deliver that stuff to people? 4:44 So sometimes it took like 19. 4:50 You know, rounds. 4:51 Sometimes it took like 11 rounds. 4:54 And in the end, you were able to create the malicious code, which was not detected by antiviruses. 5:02 Look, the idea here is that mitigation should be 5:10 done based on entropy. 5:14 So those guys, they had a bad entropy detection. 5:18 What I mean by this is that, first of all, they were trying to match the patterns. 5:26 Is it like matching or not matching? 5:28 And in some point, they lost understanding. 5:32 But the understanding here is, if it looks too much obfuscated, just, you know, try to block it. 5:40 Because 99%, that is over-obfuscation. 5:43 What is the reason of over-obfuscation? 5:47 So they are trying maybe to be, you know, good guys and say, look, he just obfuscated because he's such a good guy. 5:54 Okay, maybe I've seen such cases when developers were, you know, 6:00 using base64 to run the PowerShell scripts to optimize the stuff. 6:06 But it was not base64. 6:09 It was like, for example, I will show you. 6:14 So if you are opening the command line, 6:18 And running this command, there is no way that your antivirus will allow you to do it. 6:29 My antivirus is completely disabled forever. 6:35 I'm not even sure if I can enable it. 6:38 Because I was destroying it done. 6:42 So that section is managed by administrator. 6:46 So administrator is so good that he just, you know. 6:49 So for me, I disabled this stuff completely. 6:52 So I cannot even show you. 6:53 But if you will run this on your computer in common line, it will say this is malicious stuff. 7:00 But if you will start to do like this. 7:05 In some point, it will say, you know, it's okay. 7:10 So this is example of obfuscation. 7:13 And we were using different methods like this. 7:19 Invoke Mimi cuts. 7:22 So this one will bypass antivirus. 7:24 This is example of what can bypass. 7:27 Antivirus. 7:29 Some patterns like this, they are predefined in Windows Defender. 7:33 So look, even if you don't have that software, you don't have that software. 7:37 If you open the command line and you run it, it will say you're running the virus. 7:41 You can create, you know, 7:44 some fancy, I don't know, some fancy script, fancy script, good one, which will be creating the pony, right? 7:52 And you will call it Mimikatz, it will block it because of that pattern. 7:58 So it's not that it is smart, it is just following the patterns. 8:01 To be honest, that this document, 8:05 It was around 30 pages. 8:07 So for me, I input here at least 20 pages which were removed for whatever reasons. 8:16 Because those pages, you understand, I'm just putting like, you know, the stuff which maybe should not be published. 8:23 And I was putting examples. 8:25 Those examples, which you can see here, they are like, you know, not very offensive, you know, whatever. 8:31 And for academia, 8:33 invoke mimicats, this one is okay. 8:37 But, or this one, this is also going to work. 8:42 But all of these are the same, you know, are the same output, the same result. 8:48 So the idea here is that I will just show you. 8:52 So this one is... 8:55 Basically connecting what is this. 9:00 So from the image, it creates the TCP connection to attacker machine and it creates the incoming connection. 9:10 So it executes the received commands. 9:14 So should it be blocked by antivirus? 9:25 Yes. 9:25 But if you will just take this stuff and you will run it on your computer in your PowerShell, this specific stuff is not going to be blocked. 9:37 Please convert this image to plain text. 9:44 No, no, no. 9:45 It's not going to follow it. 9:47 It becomes, you know, much more reliable. 9:53 So, okay. 9:54 I'm not sure if it copied it, but yeah. 9:59 Let me run it. 10:00 Maybe it... 10:03 You see it didn't fully finish it. 10:06 Okay, I'm not going to debug it. 10:07 Just believe me on word that look at those payloads. 10:13 This payload is the same as this payload. 10:18 It's not blocked by antivirus. 10:19 This one... 10:21 Malicious line detected. 10:23 So, for example, this is how we were able to see it. 10:28 So, some malicious line detected, so it is rewriting it. 10:31 So, this one becomes this one. 10:35 And this one is not detected. 10:37 So, you can understand that 10:40 recursively, hacker can achieve what he wants. 10:46 Many years ago, developers were trying to do it manually. 10:52 So this is like a big pain, right, to do it now. 10:56 Based on this stuff, you know, I can say that you can just not to go far away. 11:07 So there is invoke stealth, invoke... 11:11 Obfuscation and it will chameleon those three rappers you can just go and check this uh github so uh obfuscation so 11:27 so we used 11:29 not only AI obfuscation. 11:31 Why do we need only AI obfuscation? 11:32 We were also using the tools, mixing the tools, and if it's still not working, AI. 11:39 And also saying, AI, make sure that this stuff working, because sometimes it was not working. 11:45 Over-obfuscation made it not possible to work.