Hackers using AI very nearly compromised the account of a Gmail user, as I recounted in a recent report that went viral. Now both Gmail and AI are back in the spotlight together, but as part of a large-scale hacking campaign targeting both consumers and corporates with a financially-motivated payload. Here’s everything you need to know about the CopyRh(ight)adamantys cyber attack.
CopyRh(ight)adamantys: The Cyber Attack With Global Reach Targeting Victims With AI-Generated Messaging Through Dedicated Gmail Accounts
Unlike the deepfake AI-generated cyber attack that so nearly compromised a Gmail account user by impersonating Google support, the newly uncovered CopyRh(ight)adamantys campaign is simultaneously more sophisticated and a lot simpler.
Let’s deal with that overly complicated name first: this cyber attack, described as a large-scale phishing campaign by Check Point Software researchers, uses a newly discovered variant of the Rhadamanthys information stealer malware. The attack also uses a false premise of the victim being responsible for copyright infringement violations. The conflation of these two things giving us that awful, pun-laden, CopyRh(ight)adamantys label.
The Check Point team has been tracking multiple threat actors utilizing Rhadamanthys information stealer malware, including an Iranian group operating in Israel called Void Manticore and Handala, a hacktivist group linked to it. Now, the researchers have identified a new large-scale phishing operation targeting both individuals and organizations. Rather than a political or nation-state agenda, the Check Point analysis suggests the motivation is purely financial and carried out by a criminal cybercrime operative.
Gmail And AI At The Heart Of New Cyber Attack
The Check Point report reveals that the cyber attackers in question are using dedicated Gmail accounts, created solely to distribute emails that impersonate legitimate organizations to claim copyright violations on social media accounts, primarily Facebook. “Using falsified Gmail accounts sending emails from these well-known companies,” Check Point said, “the email addresses and language are customized per each target to inform the victim of their supposed copywriting violation.” It should come as no surprise that AI capabilities have been leveraged as part of this new cyber attack campaign. However, according to the researchers, these capabilities are limited to older optical character recognition models which are using AI automation “to create customized emails and multiple Gmail accounts per target.”
Sergey Shykevich, threat intelligence group manager at Check Point Software, said that the discovery of the CopyRh(ight)adamantys cyber attack campaign reveals not only the evolving sophistication of cyber threats but also “highlights how cybercriminals are leveraging AI for marketing purposes and use automation to enhance their reach and operational scale. For security leaders.” As such, Shykevich concluded, “it’s a wake-up call to prioritise automation and AI in defence strategies to counteract these globally scaled, financially motivated phishing campaigns.”
I have reached out to Google for a statement regarding the use of Gmail in the CopyRh(ight)adamantys cyber attack campaign.