www.lesswrong.com/posts/gutiw8MBrYDiD2u5z/models-finding-software-vulnerabilitie...
1 correction found
It used to be that the worst thing these people could do was launch DDoS attacks against a particular target, or send spam email, or scrape for crypto and credit cards.
Historical botnets were already used for harms beyond DDoS, spam, cryptomining, and card theft, including credential theft and ransomware delivery.
Full reasoning
This sentence understates what botnet operators were already able to do before the AI scenario the post is discussing.
Official U.S. government sources document older botnets being used for banking-credential theft, broader credential harvesting, data exfiltration, and ransomware delivery — not just DDoS, spam, or scraping for cryptocurrency and credit cards.
Examples:
- In 2014, the FBI said the GameOver Zeus botnet had as its "principal purpose" capturing banking credentials from infected computers, and that those credentials were used to initiate or redirect wire transfers.
- In 2017, the Department of Justice said the Kelihos botnet was used for harvesting login credentials and installing ransomware and other malware.
- In a 2021 joint advisory, CISA and the FBI said TrickBot was originally a banking Trojan and had evolved into malware capable of credential theft, data exfiltration, lateral movement, cryptomining, and dropping ransomware.
Because these documented botnets were already being used for ransomware and credential theft, the claim that the worst historical botnet operators could do was limited to DDoS, spam, or scraping for crypto/credit cards is factually incorrect.
3 sources
- U.S. Leads Multi-National Action Against GameOver Zeus Botnet and Cryptolocker Ransomware, Charges Botnet Administrator — FBI
The principal purpose of the botnet is to capture banking credentials from infected computers. The GameOver Zeus botnet operates silently on victim computers ... and funnel[s] stolen banking credentials back to the criminals who control the botnet.
- Justice Department Announces Actions to Dismantle Kelihos Botnet | United States Department of Justice
The Kelihos botnet ... was used to facilitate malicious activities including harvesting login credentials, distributing hundreds of millions of spam e-mails, and installing ransomware and other malicious software.
- TrickBot Malware | CISA
Originally designed as a banking Trojan to steal financial data, TrickBot has evolved into highly modular, multi-stage malware ... Attackers can use TrickBot to drop other malware, such as Ryuk and Conti ransomware ... steal information, such as login credentials ... [and] data exfiltration over a hardcoded C2 server.