메뉴
BL
Wired AI 7일 전

AI 인프라를 노리는 해킹 웜, 탐지 우회로 위협 확대

IMP
8/10
핵심 요약

사이버보안 기업 크라우드스트라이크(CrowdStrike)는 AI 소프트웨어 공급망을 노리고 접근 권한을 탈취하며 시스템을 파괴하는 악성코드(웜)를 발견했습니다. 이 악성코드는 정상적인 AI 코딩 자동화 과정과 매우 유사하게 동작하여 기존 보안 시스템의 사각지대에 숨어 탐지를 우회하는 것이 특징입니다. AI 개발 생태계가 확장됨에 따라 새로운 형태의 공급망 보안 위협에 대비해야 하는 중요한 사례입니다.

번역된 본문

전 세계적으로 AI 도구가 급격히 확산되고 소프트웨어 개발에 깊숙이 자리 잡음에 따라, 사이버보안 기업 크라우드스트라이크(CrowdStrike)의 새로운 연구는 해커들이 AI 툴체인을 적극적으로 겨냥하고 있음을 보여줍니다. 이들은 침해 경로를 통해 액세스 자격 증명을 탈취하고, 표적 환경에 대한 더 깊은 접근 권한을 얻은 뒤, 민감한 데이터를 유출하거나 파일과 시스템을 파괴하는 등의 공격을 수행합니다. 그 과정에서 자신들의 흔적을 지우기 위한 새로운 방법들도 모색하고 있습니다.

연구원들은 AI 소프트웨어 공급망 공격을 조사하던 중 실제 운영 환경에서 활동하는 웜(악성코드)을 발견했습니다. 크라우드스트라이크의 적대 위협 대응 부문 수석 부사장인 애덤 마이어스(Adam Meyers)는 이 활동이 특정 위협 행위자와 아직 연결되지는 않았지만, 팀PCP(TeamPCP, 크라우드스트라이크가 추적하는 '변형된 거미(Altered Spider)') 및 북한 해커 그룹과 같은 공격자들이 AI 소프트웨어 공급망을 표적으로 삼는 더 큰 진화 흐름과 일치한다고 밝혔습니다.

마이어스는 와이어드(WIRED)와의 인터뷰에서 "이는 새로운 유형의 공격이 부상하고 있음을 보여주는 캠페인 중 하나"라며, "AI 코딩 에이전트가 개발 표준으로 자리 잡으면서 공급망 위협은 이러한 신뢰 관계를 악용하도록 진화하고 있다. 우리는 AI와 AI 툴체인이 더 넓은 기술 생태계에 얼마나 깊이 영향을 미치고 있는지 이번에 처음으로 직접 목격하고 있다."고 말했습니다.

크라우드스트라이크가 식별한 이 웜은 단계별로 작동합니다. 첫째, 대상 환경을 평가하기 위해 정찰을 수행합니다. 그런 다음 공격자에게 전달할 수 있는 액세스 토큰과 암호화 키, 서버 접근 자격 증명 및 기타 민감한 데이터를 찾습니다. 악성코드가 권한을 획득하면 추가로 스스로 압축을 해제하고 자격 증명을 계속 탈취하는데, 특히 핵심 소프트웨어 패키지 관리 서버와 풀 리퀘스트(pull request) 등의 개발 기능에 대한 접근 권한을 주는 'npm' 토큰을 주로 노립니다. 악성코드가 시스템 깊숙이 침투할수록 더 많은 민감한 데이터를 빼낼 수 있습니다.

이 시점에서 악성코드는 파일을 파괴하거나 침해된 인프라에 대한 정상적인 접근을 차단하는 마이어스가 이르는 '죽음의 스위치(death switch)'와 같은 파괴적인 기능을 배치할 수도 있습니다. 하지만 핵심 발견은 이 웜의 악의적인 활동 상당수가 근본적으로 보안 사각지대에서 이루어진다는 것입니다. 왜냐하면 이 악성코드의 행동 방식이 정상적인 작업과 매우 유사하기 때문입니다.

마이어스는 "건초 더미에서 바늘을 찾는 것과 같지만, 사실 이것은 바늘 더미에서 바늘을 찾는 것과 같다"며, "이 악성코드는 조직이 코드를 빌드하기 위해 사용하는 수많은 자동화 시스템과 매우 유사하게 보이므로 탐지하기가 매우 어렵다."고 설명했습니다.

또한 마이어스는 이러한 AI 소프트웨어 개발 파이프라인에서는 보안 스캐너와 분석 도구가 잠재적으로 의심스러운 활동을 탐지하기 위해 전통적으로 사용하던 데이터를 수집하기가 더 어렵다고 덧붙였습니다. 그는 "합법적인 AI 코딩 시스템이 이 웜과 똑같은 방식으로 작동하기 때문에 원격 측정 데이터(telemetry)가 많이 겹친다. 따라서 사용 가능한 원격 측정 데이터를 바탕으로 정상적인 활동과 비정상적인 활동을 구별하는 것이 매우 어려워진다."고 말했습니다.

더욱 은밀하게 시선을 끌지 않기 위해, 웜의 개발자들은 다양한 기능이 기반 작업이 이루어진 후 몇 시간 또는 며칠 뒤에 실행되도록 지연 시간을 두었습니다. 이로 인해 방어자들이 특정 이벤트가 특정 결과로 이어지는 인과관계를 파악하기가 훨씬 더 어려워졌습니다. 마이어스는 크라우드스트라이크가 이러한 단서들을 더 많이 연결하기 위한 전략을 모색해 왔지만, AI 소프트웨어 개발이 폭발적으로 성장함에 따라 모든 관계자가 구조적인 해결책을 위해 협력해야 할 시급한 필요성이 있다고 강조했습니다.

마이어스는 "우리가 조사할 수 있는 원격 측정 신호를 실제로 내보내는 활동은 극히 일부에 불과하기 때문에 탐지 표면이 제한적이다."라며, "그렇기 때문에 정상적인 행동과 비정상적인 행동을 결정하는 것이 극도로 부담스럽고 어려운 작업이 되고 있다."고 덧붙였습니다.

원문 보기
원문 보기 (영어)
Comment Loader Save Story Save this story Comment Loader Save Story Save this story As AI tools proliferate and become deeply ingrained in software development around the world, new research from the cybersecurity firm Crowdstrike shows how attackers are actively targeting the AI toolchain to steal access credentials, gain deeper access to a target environment, exfiltrate sensitive data, and even destroy target files and systems—all while finding new ways to cover their tracks. Researchers discovered a worm in the wild while investigating AI software supply chain attacks. Adam Meyers, CrowdStrike's senior vice president of counter adversary work, says that the company has not yet attributed the activity to a specific actor, but that it fits into larger evolutions in how attackers like TeamPCP (which Crowdstrike tracks as “Altered Spider”) and North Korean groups are targeting the AI software supply chain. “This is one of the campaigns that we’ve seen showing that this is an emerging attack class,” Meyers tells WIRED. “As AI coding agents become the development standard, supply chain threats are evolving to exploit those trust relationships. For the first time we’re experiencing how much AI and the AI toolchain has played into the broader tech ecosystem.” The worm CrowdStrike identified works in phases. First it does reconnaissance to assess the target environment. Then it looks for access tokens and other sensitive data, like cryptographic keys and server access credentials that it can deliver to attackers. As the malware gains privileges, it further unpacks itself and continues to grab credentials, particularly “npm" tokens that give access to key software package management servers and other development capabilities like pull requests. The deeper the malware bores into the system, the more sensitive data it can grab. At this point, the malware can also deploy its destructive capability, or what Meyers calls a “death switch,” to destroy files or block legitimate access to the compromised infrastructure. The key finding, though, is that much of the worm's malicious activity takes place in what are essentially blind spots, because so much of its behavior mimics legitimate actions. “It's like a needle in a haystack except this is a needle in a needle stack,” Meyers says. “This looks very much like a lot of the automation organizations are using to build code, so it’s very difficult to detect.” Meyers adds, too, that in these AI software development pipelines, it is harder to gather the data points that security scanners and analysis tools traditionally use to detect potentially suspicious activity. “There’s a lot of telemetry overlap because legitimate AI coding systems are operating the same way as this worm, so it becomes very difficult to discern from the telemetry you have available to you what is legitimate and what is illegitimate,” Meyers says. To hide in plain sight even more insidiously, the authors of the worm included time delays where various capabilities will execute hours or even days after the groundwork is laid, making it even harder for defenders to establish a cause and effect of certain events leading to certain outcomes. Meyers says that Crowdstrike has been working on strategies to connect more of the dots, but he emphasizes that as AI software development explodes, there is a pressing need for all players to collaborate on structural solutions. “It’s a limited detection surface because only so much of this activity is actually going to produce any sort of telemetry signal for us to look at,” Meyers says, “so it becomes extremely onerous to determine what is legitimate and what is illegitimate behavior.”