The Current State of AI Use in Cyberattacks

Analytics2026-08-06, 09:03
The Current State of AI Use in Cyberattacks
Three new reports from CrowdStrike, Trend Micro and Check Point Research show that AI is becoming not only a common tool for attackers, but also the foundation of a distinct criminal ecosystem. Below are the most interesting findings on this topic from each report.
CrowdStrike 2026 Threat Hunting Report is not focused directly on AI, but it highlights its growing impact on cyberattacks: • In 2025, activity involving AI increased by 89%. The technology is being used to scale operations and accelerate attacks, including attacks targeting AI infrastructure itself. • The number of detections initiated by AI agents is already 2.5 times higher than the number of signals associated with human activity, significantly increasing the volume of events requiring analysis. • In the first half of 2026, 88% of public PoCs were exploited within 48 hours of publication. The development of advanced AI systems may shorten this window even further.
Trend Micro 2026 H1 APT Report provides examples of AI use by state-affiliated groups: • Earth Krahang enhanced a public PoC for CVE-2026-0740 with AI, turning it into a tool for mass, automated scanning for vulnerable servers. • Earth Naga used vibe coding to develop a malicious PowerShell script that uses process hollowing and reflective DLL loading techniques to execute code in memory. • In one attack, the attackers (likely Earth Lamia) launched Claude Code as an autonomous agent. It scanned the internal network, attempted to exploit known vulnerabilities, harvested credentials, and tried to crack passwords. • North Korean IT workers use ChatGPT, deepfakes, and face swapping to pass job interviews for subsequent cyberespionage operations. More details are available in the April post.
Check Point Research AI Security Report shows that a distinct ecosystem is emerging around the criminal use of AI: • In skilled hands, AI already enables the development of large-scale malware. The report again mentions the VoidLink framework— an 88,000-line framework written by a single person in less than a week. • As part of the Bissa Scanner campaign, credentials for Anthropic, OpenAI, Google, and other AI services were stolen from more than 30,000 .env configuration files. The stolen accounts can then be resold as part of an LLMjacking scheme — attackers use paid AI APIs at the owner's expense. • The popularity of AI services tailored for cyberattacks (such as WormGPT) is declining because of poor quality. Serious attackers increasingly prefer regular commercial models, using techniques to bypass their safeguards. • The number of detections of long malicious prompts characteristic of prompt injection attacks increased approximately fivefold from March to May 2026.
The reports describe different stages of the same transformation. CrowdStrike shows how AI accelerates operations, Trend Micro shows how it is already being used in real-world APT campaigns, and Check Point shows how a distinct criminal ecosystem is forming around it. As a result, AI is becoming as commonplace a part of attackers' infrastructure as cloud services or traditional automation tools.
Vulnerabilities
10
CVE-2026-0740
Researchers
Sélim Lanouar
Vendors
Crowdstrike
Trend Micro
Check Point Research
Anthropic
Openai
Google
Products
Bissa Scanner
Chatgpt
Check Point Research Ai Security Report
Claude Code
Crowdstrike 2026 Threat Hunting Report
Powershell
More