AI-Powered Cyber Attacks: Deepfakes, Bots, and Beyond
黑客利用深度伪造技术模仿公司CFO的声音和形象,在视频会议中诱骗转账2500万美元。攻击者通过公开视频训练AI克隆声音和面部表情,绕过防火墙和多因素认证系统。最终仅追回部分资金,其余被用于非法活动。 2025-8-12 06:6:6 Author: infosecwriteups.com(查看原文) 阅读量:14 收藏

How a Deepfake CFO Stole $25M from My Company — And Why Your Firewalls Are Useless

Aj

Press enter or click to view image in full size

Photo by Bermix Studio on Unsplash

The video call froze. Our CFO, Maria, stared coldly from the screen. “Authorize the $25M transfer now. The acquisition depends on it.” Her lip twitched — a micro-expression I’d never seen. Thirty seconds later, the money vanished. The real Maria? On vacation, phone off. We’d been deepfaked by AI clones trained on her TED Talk.

Welcome to the terrifying new era of cyber warfare.

The Attack:
Hackers scraped 37 minutes of Maria’s public videos. Used tools like OpenAI’s VASA-1 to:

  1. Clone her voice (tone, pauses, accent)
  2. Animate her face with real-time lip sync
  3. Inject “urgent” vocal stress patterns

Why it worked:

  • No malware. No phishing links. Just psychological warfare.
  • Our $500K MFA system? Useless against “trusted” human faces.

The Aftermath:
We recovered $9M. The rest funded a North Korean crypto-mining operation.


文章来源: https://infosecwriteups.com/ai-powered-cyber-attacks-deepfakes-bots-and-beyond-7330bbb0cfff?source=rss----7b722bfd1b8d---4
如有侵权请联系:admin#unsafe.sh