APromptRiskDBThreat intelligence atlas
AI Case Study

VirusTotal Poisoning - AI Case Study

McAfee Advanced Threat Research noticed an increase in reports of a certain ransomware family that was out of the ordinary. Case investigation revealed that many samples of that particular ransomware family were submitted through a popular virus-sharing platform within a short amount of time. Further investigation revealed that based on string similarity the samples were all equivalent, and based on code similarit...

IncidentVirusTotalUnknownResource DevelopmentAI Attack StagingInitial Access

Overview

Case steps4Steps described in the case record.
Techniques4Attack methods mentioned in the case steps.
Linked CVEs0Known vulnerabilities mentioned in the record.

Risk patterns

Patterns found in the case record and its linked vulnerabilities.

  • 1Dominant ATLAS tactic. Resource Development appears in 1 case steps.
  • 2Multiple attack methods. The case connects to 4 unique AI attack methods.

Procedure timeline

Search the case steps or filter them by attacker goal.

Resource Development1AI Attack Staging1Initial Access1Persistence1
  1. Persistence

    Several vendors started to classify the files as the ransomware family even though most of them won't run. The "mutant" samples poisoned the dataset the ML model(s) use to identify and classify this ransomware family.

Mitigations

Defenses connected to the attack methods in this case.

Sources

Original public records and references for this case.