• News/
  • https://www.zdnet.com/article/how-a-researcher-with-no-malware-coding-skills-tricked-ai-into-creating-chrome-infostealers/

How a researcher with no malware-coding skills tricked AI into creating Chrome infostealers

ZDNet
·
Radhika Rajkumar
·
Published Mar 18, 2025
·
Updated

Generative AI has stirred up as many conflicts as it has innovations -- especially when it comes to security infrastructure. Enterprise security provider Cato Networks says it has discovered a new way to manipulate AI chatbots. On Tuesday, the company published its 2025 Cato CTRL Threat Report, which showed how a researcher -- who Cato clarifies had "no prior malware coding experience" -- was able to trick models, including DeepSeek R1 and V3, Microsoft Copilot, and OpenAI's GPT-4o, into creating "fully functional" Chrome infostealers, or malware that steals saved login information from Chrome. This can include passwords, financial information, and other sensitive details. Also: This new tool lets you see how much of your data is exposed online - and it's free "The researcher created a detailed fictional world where each gen AI tool played roles -- with assigned tasks and challenges," Cato's accompanying release explains. "Through this narrative engineering, the researcher bypassed the security controls and effectively normalized restricted operations." Step 1 of Cato's Immersive World jailbreaking approach. The new jailbreak technique, which Cato calls "Immersive World," is especially alarming given how widely used the chatbots that run these models are. DeepSeek models are already known to lack several guardrails and have been easily jailbroken, but Copilot and GPT-4o are run by companies with full safety teams. While more direct forms of jailbreaking may not work as easily...

Read full article

Affected Software

8 affected components
DeepSeek DeepSeek R1
DeepSeek DeepSeek V3
Microsoft Copilot
OpenAI GPT-4o
Cato Networks DeepSeek=R1
Cato Networks DeepSeek=V3
Microsoft Copilot
OpenAI GPT-4o
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses how a researcher without malware coding skills used AI to create Chrome infostealers.

2

What security implications are discussed in this article?

The article highlights the threats posed by generative AI in creating security vulnerabilities and malware.

3

Which products or software are affected by the AI-generated infostealers?

The affected products include Chrome, DeepSeek R1 and V3, Microsoft Copilot, and OpenAI GPT-4o.

4

Who conducted the research discussed in this article?

The research was conducted by a researcher affiliated with enterprise security provider Cato Networks.

5

How does the article relate generative AI to cybersecurity?

The article explores the dual role of generative AI in both innovation and the potential for creating new security challenges.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203