Back to Resources

SentinelOne VS BlackMamba ChatGPT Polymorphic Malware

Learn how to defend against BlackMamba-style attacks in this informative video. A BlackMamba-style attack involves requesting code generation from ChatGPT, followed by the packaging of that code for delivery and execution on a target. This type of attack is used to evade modern EDR/XDR detection systems.

In this demo, we take a similar approach by having ChatGPT generate keylogging+VSS removal code (in Python). We then manually walk through the steps of submitting the ‘malicious’ request to ChatGPT and moving that code to an actual Python script. We use the auto-py-to-exe tool to convert our code to an .EXE file ready for execution.

However, when we launch the threat, it is detected and terminated by SentinelOne Singularity™ Endpoint. At the end of the day, malicious code is malicious code. Regardless of the source, SentinelOne Singularity™ Endpoint is able to detect and prevent BlackMamba-style attacks.

지금 읽기

세계에서 가장 앞선 사이버 보안 플랫폼 경험하기

지능적인 자율형 사이버 보안 플랫폼이 현재와 미래의 조직을 어떻게 보호할 수 있는지 알아보세요.