Generative AI has stirred up as many conflicts as it has innovations -- especially when it comes to security infrastructure. Enterprise security provider Cato Networks says it has discovered a new way to manipulate AI chatbots. On Tuesday, the company published its 2025 Cato CTRL Threat Report, which showed how a researcher -- who Cato clarifies had "no prior malware coding experience" -- was able to trick models, including DeepSeek R1 and V3, Microsoft Copilot, and OpenAI's GPT-4o, into creating "fully functional" Chrome infostealers, or malware that steals saved login information from Chrome. This can include passwords, financial information, and other sensitive details. Also: This new tool lets you see how much of your data is exposed online - and it's free "The researcher created a detailed fictional world where each gen AI tool played roles -- with assigned tasks and challenges," Cato's accompanying release explains. "Through this narrative engineering, the researcher bypassed the security controls and effectively normalized restricted operations." Step 1 of Cato's Immersive World jailbreaking approach. The new jailbreak technique, which Cato calls "Immersive World," is especially alarming given how widely used the chatbots that run these models are. DeepSeek models are already known to lack several guardrails and have been easily jailbroken, but Copilot and GPT-4o are run by companies with full safety teams. While more direct forms of jailbreaking may not work as easily...
How a researcher with no malware-coding skills tricked AI into creating Chrome infostealers
ZDNet
·Radhika Rajkumar
·Published Mar 18, 2025
·Updated
Affected Software
8 affected components
DeepSeek DeepSeek R1
DeepSeek DeepSeek V3
Microsoft Copilot
OpenAI GPT-4o
Cato Networks DeepSeek=R1
Cato Networks DeepSeek=V3
Microsoft Copilot
OpenAI GPT-4o
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses how a researcher without malware coding skills used AI to create Chrome infostealers.
2
What security implications are discussed in this article?
The article highlights the threats posed by generative AI in creating security vulnerabilities and malware.
3
Which products or software are affected by the AI-generated infostealers?
The affected products include Chrome, DeepSeek R1 and V3, Microsoft Copilot, and OpenAI GPT-4o.
4
Who conducted the research discussed in this article?
The research was conducted by a researcher affiliated with enterprise security provider Cato Networks.
5
How does the article relate generative AI to cybersecurity?
The article explores the dual role of generative AI in both innovation and the potential for creating new security challenges.