AI Service Web Interface - AML.T0114
Definition
Adversaries may communicate with compromised systems by abusing the web interface of an AI service as an intermediary command-and-control relay. Instead of connecting directly to attacker-controlled infrastructure or using an AI provider's API, malware may open or automate a browser, embedded browser, or WebView component to interact with a public AI assistant.
The malware may prompt the AI assistant to fetch an attacker-controlled URL, include victim data in URL parameters or prompt content, and return attacker-supplied content through the AI assistant's response. The implant can then parse the response and execute embedded instructions.
This technique is especially useful when an AI web interface permits anonymous or unauthenticated browsing, summarization, or URL-fetch behavior. In those cases, adversaries may avoid controls that depend on API keys, service accounts, user identities, or revocable credentials.
This technique allows command-and-control traffic to blend into apparently legitimate AI web traffic to trusted service domains. In this pattern, the AI service acts as a proxy between the compromised system and attacker-controlled infrastructure, shifting detection from API key and account monitoring toward browser automation, prompt content, URL-fetch behavior, and AI service telemetry.
D3FEND Inferred Relationships
There are no artifacts defined on this offensive technique (yet). Please consider contributing an addition to D3FEND.