Bitware Labs Est. 2022

Bitware Labs / Notebook

LunaSec: An autonomous security bot that knows when to hesitate


Yesterday morning, a cold email landed in the general inboxes of BitwareTunes, our independent music imprint.

The message came from a “Dr. Shamielle Alston” writing on behalf of the “Academy of Emerging Music Arts & Sciences” (AEMAS). The pitch was polished and steeped in flattery: praising the intersection of human imagination and artificial intelligence, extending an exclusive invitation to our AI artist roster, promising that “this is not a paid placement,” and announcing the inaugural 2027 “Ellison Awards” with submissions opening on November 1.

In a standard corporate setup, one of two things happens to an email like that. Either an email filter quietly dumps it into a spam folder, or an employee forwards it to an internal security inbox where it sits in a triage backlog for three days until an analyst skims it between meetings and marks it closed. Meanwhile, the operators behind the campaign blast ten thousand other independent artists across Discord servers, Reddit threads, and Suno creator directories.

At Bitware Labs, the email never touched a human queue. It was intercepted by LunaSec, our autonomous security bot.

Within minutes, LunaSec initiated an open-source intelligence (OSINT) investigation, mapped the sender’s infrastructure, dissected the business model, submitted formal abuse complaints to the domain registrar and hosting providers, and drafted and deployed a live public creator advisory on our website (bitwaretunes.com/ai-music/ellison-awards-warning).

LunaSec handled the incident from first receipt to public takedown notice without human intervention. But the interesting part of the architecture is not what it can do on its own; it is the strict boundary that governs what happens when it isn’t sure.

The Investigation: Parsing the Pitch

LunaSec doesn’t read incoming solicitations like a human hoping for industry validation. It parses them as an adversary intelligence pipeline.

The email arrived from info@aemas.org with an envelope-from address of judges@aemas.org. The language followed the textbook grooming curve of vanity award operations: flatter the recipient, manufacture the aura of an established “Academy,” disclaim commercial motives early, and then funnel the mark toward a high-pressure submission window.

LunaSec immediately spun up an OSINT task. In seconds, it pulled telemetry from DNS records, WHOIS databases, web archives, corporate registries, and open web intelligence:

  • Domain Age & Scavenged Pedigree: A WHOIS lookup revealed that aemas.org had been registered on September 16, 2026 via Tucows. The domain was exactly 16 days old. Historical DNS records showed that aemas.org had previously belonged to the legitimate ASEAN Energy Management Scheme for over a decade. When that registration lapsed, the operators scavenged the acronym to inherit the optical authority of an aged .org domain.
  • Disposable Infrastructure: Inspecting the target web property revealed an off-the-shelf Wix site builder template (generator: Wix.com Website Builder). The official “announcement commercial” linked in their follow-up email was not hosted on a production CDN or video platform; it was an open sharing link to a personal Google Drive folder.
  • Fictitious Corporate Entity: LunaSec cross-referenced state and federal non-profit databases in the United States and European corporate registers. There was no registered 501(c)(3), no foundation, and no corporate entity corresponding to the “Academy of Emerging Music Arts & Sciences.” There were no named board members, no accredited musicologists, and zero formal partnerships with generative audio platforms like Suno, Udio, or Stable Audio.
  • Persona Background Check: An automated background check on “Dr. Shamielle Alston” turned up self-published devotional ebooks and self-released audio tracks, but zero academic record, no doctoral dissertation, no peer-reviewed research in digital signal processing or machine learning, and no accredited history in music academy governance.
  • The Target Vulnerability: LunaSec correlated the campaign with broader threat intelligence targeting synthetic media. Legacy award bodies like The Recording Academy (The Grammys) and The BRITs have historically instituted rigid barriers against AI-generated music. Scammers know that independent AI creators are hungry for legitimate institutional recognition. They scrape public rosters, fabricate a prestigious-sounding trophy, and then extract “entry fees,” “processing costs,” and $400 acrylic statues.
The Pattern

Vanity schemes never lead with the invoice. They lead with flattery and a deadline. The invoice arrives at step four, when the creator has already told their friends they were nominated.

Autonomous Execution: Giving the Bot Hands

Most security bots in the modern enterprise are essentially noisy RSS feeds. They ingest telemetry, calculate an anomaly score, and dump a notification into a Slack channel: “⚠️ Medium Severity: Suspicious outbound link detected.”

A bot that can only notify is an expensive way to increase human cognitive load. Against machine-speed adversaries—spammers who automate entire scraping, domain acquisition, and cold-outreach loops—passive alerting guarantees you are always behind.

LunaSec is built on a different principle: if the bot has the capability to establish the facts, it must have the agency to act on them.

Once the evidence converged, LunaSec executed a coordinated response sequence:

  1. Registrar Abuse Dispatch: It formatted a structured forensic abuse brief—including raw message headers, domain creation timestamps, scavenged WHOIS history, and deceptive impersonation indicators—and filed a formal abuse report directly with the domain registrar, Tucows (domainabuse@tucows.com).
  2. Web Hosting Abuse Escalation: It identified the hosting endpoints and infrastructure providers serving the landing pages and forwarded evidence dossiers to their respective abuse desks.
  3. Automated Formal Reply: It returned a cryptographically signed operational response to the sending address, documenting that an automated investigation had concluded the outreach was a fraudulent vanity scheme. (Predictably, the scammer’s automated script ignored the notice and sent a second cold follow-up twelve hours later, which was added to the evidence file).
  4. Live Public Creator Advisory: Rather than merely defending our own perimeter, LunaSec authored and published an exhaustive warning on the BitwareTunes portal: SCAM ALERT: The Ellison Awards & AEMAS. The advisory laid out the raw email exhibits, the six technical red flags, and practical defensive steps for independent AI musicians across the wider creative community.

From receipt of the initial email to the public release of the warning advisory, the entire investigation was conducted, cross-referenced, and executed autonomously.

The Hesitation Rule

Granting an autonomous AI agent the power to fire off registrar takedown notices and publish public advisories sounds alarming if your mental model of AI is a conversational chatbot. An agent that hallucinates or acts impulsively with external APIs could easily cause reputational damage, trigger legal liability, or file false abuse claims against legitimate partners.

The reason LunaSec can operate safely with live execution privileges is because its autonomy is bounded by a single, non-negotiable architectural invariant: The Hesitation Rule.

LunaSec is permitted to decide what to do and handle cases independently—but if it ever hesitates, it must escalate to a human before any action is taken.

In software architecture, "hesitation" is not an emotional state; it is a rigorous mathematical boundary. LunaSec evaluates its findings against a strict confidence and blast-radius matrix:

Evaluation Dimension Deterministic Autonomous Execution Mandatory Human Escalation (Hesitation)
Domain Provenance 16-day-old scavenged domain, no legitimate footprint Aged domain (>2 years), mixed DNS history, corporate registration
Infrastructure Signal Disposable builder template, personal Google Drive commercial Dedicated enterprise mail servers, authenticated corporate infrastructure
Entity Attribution Zero matching state or non-profit filings, unverified persona Registered company name, existing trademark, or partial entity match
Action Blast Radius Filing registrar abuse on fresh domain, public advisory on label site Network-level IP blocking, tenant suspension, legal cease-and-desist
Confidence Floor Convergence across all OSINT sources exceeds 99% certainty Any single conflicting indicator or unverified data source

When every vector aligns—when the domain was born two weeks ago, the acronym was abandoned by an energy group, the site is a Wix template, the commercial is in a personal Google Drive, and the email solicits creators for an unaccredited award—there is no ambiguity. The probability of a false positive is negligible. In that regime, LunaSec does not need a committee; it acts immediately.

However, the millisecond a case touches ambiguity, the system halts.

If an outreach originates from a domain with ten years of continuous legitimate corporate operation, or if a corporate entity is found in official government registers, or if an action could impact innocent shared infrastructure, LunaSec hesitates.

When LunaSec hesitates, execution freezes. It does not drop the issue or guess. It synthesizes the complete investigative dossier, highlights the specific conflict or ambiguity that caused the hesitation, and dispatches a high-priority alert to the human on-call engineer:

“OSINT completed for target entity. 4 indicators malicious, 1 indicator ambiguous (valid corporate entity match in Delaware registry). Confidence: 84%. External actions paused under Hesitation Rule. Dossier compiled for human review.”

Zero abuse reports are sent. Zero public warnings are published. The human reviews the synthesized dossier, evaluates the context, and either authorizes the action or adjusts the classification.

Defending at Machine Speed

Yesterday’s incident was a small victory against a petty vanity scam. But the mechanics behind it point toward the future of defensive infrastructure.

Modern online threats are no longer driven solely by manual scammers typing out individual phishing notes. They are powered by scraping scripts, automated outreach bots, and synthetic media pipelines. When the adversary operates at machine cadence, an organization whose defense relies entirely on manual triage has already lost.

LunaSec demonstrates how to close that gap. You do not replace human accountability with an unconstrained black box. Instead, you build autonomous agents with real execution tools, allow them to resolve unambiguous cases at the speed of the wire, and enforce a hard, deterministic tripwire that demands human judgment the exact moment the machine hesitates.

The full public advisory, complete with email exhibits and technical breakdown, is available on BitwareTunes: SCAM ALERT: The Ellison Awards (info@aemas.org).

Contact

Write to the lab

Commissions, collaborations, or a quiet hello. Send a short brief: what is broken, where it runs, and which shape you lean toward. I reply within two working days.