Security

Microsoft sues 'foreign-based' cyber-crooks, seizes sites used to abuse AI

Scumbags stole API keys, then started a hacking-as-a-service biz, it is claimed


Microsoft has sued a group of unnamed cybercriminals who developed tools to bypass safety guardrails in its generative AI tools. The tools were used to create harmful content, and access to the tools were sold as a service to other miscreants.

The lawsuit, filed in December in a US District Court, accuses 10 defendants of using API keys stolen from "multiple" Microsoft customers along with custom-designed software to break into computers running Microsoft's Azure Open AI service. 

Microsoft says it uncovered the scheme in July 2024, but the exact way in which the criminals stole the API keys is unknown.

While the legal complaint doesn't identify any of the 10 defendants, Steven Masada, assistant general counsel for Microsoft's Digital Crimes Unit,  described the criminals as a "foreign-based threat–actor group." 

The lawsuit accuses the 10 of violating the federal laws including the Computer Fraud and Abuse Act, the Digital Millennium Copyright Act, and the Racketeer Influenced and Corrupt Organizations Act (RICO), and seeks relief and damages related to the "creation, control, maintenance, trafficking, and ongoing use of illegal computer networks and piratical software to cause harm to Microsoft, its customers, and the public at large" [PDF].

In addition to the complaint, the newly unsealed court documents also include a court order [PDF] allowing Microsoft to seize web domains used in the criminal operation. This, according to Masada, will "allow us to gather crucial evidence about the individuals behind these operations, to decipher how these services are monetized, and to disrupt additional technical infrastructure we find."

After using the stolen customer credentials to break into Azure, the complaint alleges, intruders used this illicit access to "create harmful content in violation of Microsoft's policies and through circumvention of Microsoft's technical protective measures."

Plus, the digital thieves resold this access as a "hacking-as-a-service scheme" to other criminals, the lawsuit claims:

First, Defendants created a client-side software tool referred to by Defendants as "de3u," which Defendants make publicly available via the "rentry.org/dc3u" domain. Second,Defendants created software for running a reverse proxy service, referred to as the "oai reverse proxy," designed specifically for processing and routing communications from the de3u software to Microsoft's systems.

The de3u software, according to the lawsuit, allows users to issue Microsoft API calls to generate images using the DALL-E model, which is available to Azure OpenAI Service customers. 

"Using an open source software package, [the] defendants built a web application that implements a custom layout and data flow designed specifically for using tools like DALL-E to generate images using text prompts," the court documents claim.

Microsoft has since boosted its genAI guardrails and added safety mitigations that it says help prevent this type of abuse. It did not provide specific details about what these new safety measures include. ®

Send us news
4 Comments

Russia's Star Blizzard phishing crew caught targeting WhatsApp accounts

FSB cyberspies venture into a new app for espionage, Microsoft says

Microsoft eggheads say AI can never be made secure – after testing Redmond's own products

If you want a picture of the future, imagine your infosec team stamping on software forever

How Windows got to version 3 – an illustrated history

With added manga and snark. What's not to like?

Miscreants 'mass exploited' Fortinet firewalls, 'highly probable' zero-day used

Ransomware 'not off the table,' Arctic Wolf threat hunter tells El Reg

Ransomware crew abuses AWS native encryption, sets data-destruct timer for 7 days

'Codefinger' crims on the hunt for compromised keys

Mitel 0-day, 5-year-old Oracle RCE bug under active exploit

3 CVEs added to CISA's catalog

The unlicensed OneDrive free ride ends this month

Kind old Microsoft is worried about security and compliance ... nothing to do with a free storage loophole

Chinese cyber-spies peek over shoulder of officials probing real-estate deals near American military bases

Gee, wonder why Beijing is so keen on the – checks notes – Committee on Foreign Investment in the US

China's Salt Typhoon spies spotted on US govt networks before telcos, CISA boss says

We are only seeing 'the tip of the iceberg,' Easterly warns

FBI wipes Chinese PlugX malware from thousands of Windows PCs in America

Hey, Xi: Zài jiàn!

Microsoft tests 45% M365 price hikes in Asia-Pacific to see how much you enjoy AI

Won’t say if other nations will be hit, but will ‘listen, learn, and improve’ as buyers react – so far with anger

Crims backdoored the backdoors they supplied to other miscreants. Then the domains lapsed

Here's what $20 gets you these days