GitHub - cybershujin/Threat-Actors-use-of-Artifical-Intelligence

GitHub

51 min read Original article ↗
FunkSec unknown "The individuals behind FunkSec appear to have extensively leveraged AI to enhance their capabilities, as evidenced by their publications and tools. Their public script offerings include extensive code comments with perfect English (as opposed to very basic English in other mediums), likely generated by an LLM agent. Similar patterns are visible in the Rust source code linked to the group’s ransomware, suggesting it may have been developed with AI assistance.

In some of their published messages, the group specifically linked the development of their ransomware to AI-assisted agents, likely providing it with the source code for the ransomware and simply shared the output on their site.

The use of such tools aligns closely with the group’s public claims, as they also released an AI chatbot based on Miniapps to support their operations"

LLM-enhanced scripting techniques T1588 - Develop Capabilities: Tool CheckPoint Research Jan 2025 Dec 2024 – Jan 2025 Salt Typhoon GhostEmperor, FamousSparrow, Earth Estries, UNC2286 WSJ- "The group used sophisticated methods to infiltrate American telecom infrastructure through vulnerabilities including Cisco Systems routers, and investigators suspect the hackers relied on artificial intelligence or machine learning to further their espionage operations , people familiar with the matter said."

InfoSec Magazine - "Salt Typhoon’s methods included advanced use of artificial intelligence to enhance their access and intelligence-gathering efforts."

Unknown TTPs T-Mobile Hacked in Massive Chinese Breach of Telecom Networks - Wall Street Journal and Archive -no paywall

InfoSecurity Magazine

Nov 2024 Unknown Multiple Unsub - Symantic Unknown Recent malware campaigns observed by Symantec involved phishing emails containing code used to download various payloads, including Rhadamanthys, NetSupport, CleanUpLoader (Broomstick, Oyster), ModiLoader (DBatLoader), LokiBot, and Dunihi (H-Worm). Analysis of the scripts used to deliver malware in these attacks suggests they were generated using LLMs. Symantec LLM-enhanced scripting techniques T1588 - Develop Capabilities: Tool

LLM-supported social engineering T1566 - Phishing

LLM-enhanced scripting techniques: Execution through Windows Management Instrumentation (WMI) or PowerShell (T1059)

Coming Soon Jul 2024 Unknown Bitter APT APT-C-08, Aramanberry the group used the online IDE platform Replit to build phishing websites Source TA1588.007 - Artifical Intelligence

LLM-supported social engineering T1566 - Phishing

ComingSoon Unknown Unknown Multiple Unsub - Trend Micro unknown akas Criminals are using generative AI capabilities for two purposes: To support the development of malware or malicious tools...To improve their social engineering tricks. Trend Micro LLM-enhanced scripting techniques T1588 - Develop Capabilities: Tool

LLM-supported social engineering T1566 - Phishing

LLM-enhanced scripting techniques: Execution through Windows Management Instrumentation (WMI) or PowerShell (T1059)

DeepFake for Impersonation (Fraud): Where generative AI is used to make audio, video or photographic media used to impersonate individuals

Trend Micro May 2024 Unknown TA547 Scully Spider Proofpoint identified TA547 targeting German organizations with an email campaign delivering Rhadamanthys malware. This is the first time researchers observed TA547 use Rhadamanthys, an information stealer that is used by multiple cybercriminal threat actors. Additionally, the actor appeared to use a PowerShell script that researchers suspect was generated by large language model (LLM) such as ChatGPT, Gemini, CoPilot, etc. Source LLM-enhanced scripting techniques: Execution through Windows Management Instrumentation (WMI) or PowerShell (T1059) ComingSoon Apr 2024 Mar 2024 Fancy Bear Forest Blizzard, APT28, Strontium APT28 is a Russian military intelligence actor linked to GRU Unit 26165, who has targeted victims of both tactical and strategic interest to the Russian government. Microsoft assesses that Forest Blizzard operations play a significant supporting role to Russia’s foreign policy and military objectives both in Ukraine and in the broader international community. Forest Blizzard’s use of LLMs has involved research into various satellite and radar technologies that may pertain to conventional military operations in Ukraine, as well as generic research aimed at supporting their cyber operations. Microsoft

[Update 2025-11] Deployed PROMPTSTEAL (CERT-UA tracks it as LameHug) against Ukraine in June 2025 — a Python data-miner that queries an LLM (Qwen2.5-Coder-32B-Instruct) via the Hugging Face API at runtime to generate the reconnaissance/collection commands it executes; GTIG describes it as its first observed case of malware querying an LLM in live operations. GTIG, corroborated by CERT-UA

LLM-informed reconnaissance T1592 - Gather Victim Org Information

LLM-enhanced scripting techniques T1588 - Develop Capabilities: Tool

LLM-embedded malware (runtime generation) T1059 - Command and Scripting Interpreter

APT28 aka Fancy Bear Nov 2025 By Feb 2024 – Jun 2025 APT43 Lazarus, Emerald Sleet, Velvet Chollima, Kimsuky, TA406, Thallium North Korean threat actor with recent operations relied on spear-phishing emails to compromise and gather intelligence from prominent individuals with expertise on North Korea. Microsoft observed Emerald Sleet impersonating reputable academic institutions and NGOs to lure victims into replying with expert insights and commentary about foreign policies related to North Korea. Emerald Sleet’s use of LLMs has been in support of this activity and involved research into think tanks and experts on North Korea, as well as the generation of content likely to be used in spear-phishing campaigns. Emerald Sleet also interacted with LLMs to understand publicly known vulnerabilities, to troubleshoot technical issues, and for assistance with using various web technologies. Microsoft

This account of the use of AI was also reported by Mandiant in their 23-00016993 and 24-00002657 reports. Mandiant's 2024 reporting also mentions APT43 purchasing WormGPT in August 2023. Reports from Feb 2024 APT43 was observed on forums discussing ChatGPT along a topic about (toughly translated) "North Korean nuclear solution"

In another report, Mandiant describes, "We identified indications of North Korean cyber espionage actor APT43 interest in LLMs, specifically Mandiant observed evidence suggesting the group has logged on to widely available LLM tools. The group may potentially leverage LLMs to enable their operations, however the intended purpose is unclear. " Source

[Update 2026-03] Microsoft (with OpenAI) observed Emerald Sleet using LLMs to research the publicly reported vulnerability CVE-2022-30190 (MSDT "Follina"). Microsoft

LLM-assisted vulnerability research T1588.006 Obtain Capabilities: Vulnerabilities

LLM-enhanced scripting techniques T1588 - Develop Capabilities: Tool

LLM-supported social engineering T1566 - Phishing

LLM-informed reconnaissance T1592 - Gather Victim Org Information Based on Mandiants 24-00002657 report,

DeepFake for Impersonation (TTP unknown, not clear how actors used generated images from MaxAi[.]me and ZMO AI

link coming soon Feb 2024 Unknown Imperial Kitten Crimson Sandstorm, Yellowliderc, Tortoiseshell Iranian threat actor assessed to be connected to the Islamic Revolutionary Guard Corps (IRGC). This actor has targeted multiple sectors, including defense, maritime shipping, transportation, healthcare, and technology. These operations have frequently relied on watering hole attacks and social engineering to deliver custom .NET malware. Prior research also identified custom Crimson Sandstorm malware using email-based command-and-control (C2) channels. The use of LLMs by Crimson Sandstorm has reflected the broader behaviors that the security community has observed from this threat actor. Interactions have involved requests for support around social engineering, assistance in troubleshooting errors, .NET development, and ways in which an attacker might evade detection when on a compromised machine. Microsoft LLM-supported social engineering T1566 - Phishing

LLM-enhanced scripting techniques T1588 - Develop Capabilities: Tool

LLM-enhanced anomaly detection evasion T1562.001 - Impair Defenses: Disable or Modify Tools

link coming soon Feb 2024 Unknown Aquatic Panda Charcoal Typhoon, ControlX, RedHotel, Bronze University, Red Scully, Chromium Chinese state-affiliated threat actor with a broad operational scope. Activities have predominantly focused on entities within Taiwan, Thailand, Mongolia, Malaysia, France, and Nepal, with observed interests extending to institutions and individuals globally who oppose China’s policies. In recent operations, this actor group has been observed interacting with LLMs in ways that suggest a limited exploration of how LLMs can augment their technical operations. This has consisted of using LLMs to support tooling development, scripting, understanding various commodity cybersecurity tools, and for generating content that could be used to social engineer targets. Microsoft LLM-informed reconnaissance T1588.006 Obtain Capabilities: Vulnerabilities

LLM-enhanced scripting techniques T1587 - Develop Capabilities

LLM-refined operational command techniques TA0003 - Persistence and TA004 Privilege Escalation

Aquatic Panda Reports Feb 2024 Unknown Sodium Salmon Typhoon, Samurai Panda, Maverick Panda, APT4 Sophisticated Chinese state-affiliated threat actor with a history of targeting US defense contractors, government agencies, and entities within the cryptographic technology sector. This threat actor has demonstrated its capabilities through the deployment of malware, such as Win32/Wkysol, to maintain remote access to compromised systems. With over a decade of operations marked by intermittent periods of dormancy and resurgence. (Sodium's) interactions with LLMs throughout 2023 appear exploratory and suggest that this threat actor is evaluating the effectiveness of LLMs in sourcing information on potentially sensitive topics, high profile individuals, regional geopolitics, US influence, and internal affairs. This tentative engagement with LLMs could reflect both a broadening of their intelligence-gathering toolkit and an experimental phase in assessing the capabilities of emerging technologies. Microsoft LLM-informed reconnaissance T1593 - Search Open Websites/Domains

LLM-enhanced scripting techniques T1587.001 - Develop Capabilities: Malware

LLM-refined operational command techniques T1564 - Hide Artifacts

LLM-Aided technical translation and explanation T1593 - Search Open Websites/Domains

link coming soon Feb 2024 2023 Unsub1 - Kaspersky N/A Using fake sites, they hosted “GPT chats” supposedly capable of diagnosing computer problems, making money and such. In fact, the site deployed no AI models, but only used the topic to stir interest with potential victims and make a bigger killing. One such page mimicking the Microsoft website warned visitors that their computer was infected with a Trojan. To avoid losing data, they were advised not to reboot or turn off the device until the issue was resolved. Two options were offered: call a hotline or chat with Lucy, an AI chatbot. In the second case, you had to choose a method of diagnosing the device, after which the bot said it was unable to solve the problem and recommended calling support. Naturally, professional scammers, not Microsoft engineers, were waiting at the other end of the line. Analyst note: This sounds like Bazacall like activity Source Lookalike LLM T1583 Acquire Infrastructure N/A Mar 2024 2023 Unsub2 - Kaspersky N/A “Smart chatbots” were also used as “consultants” on making money online. On one site a bot pretending to be an Elon Musk design advertised investment services. After telling the new “client” that it could make them rich quickly, the robot asked about their education, income level, and investment experience. Regardless of the answers, the bot informed the client that it would do all the earning. Next, it demonstrated an amount it could offer and prompted the user to register simply by providing their contact details. Events then likely unfolded as in other similar schemes: The “AI” asked for a small fee in recognition of its intellectual abilities, and then simply vanished into the ether. Source Lookalike LLM T1583 Acquire Infrastructure

LLM-supported social engineering T1566 - Phishing

N/A Mar 2024 Jan 2023 – Dec 2023 Multiple Unsub - JFrog N/A In an "investigation of a malicious machine-learning model...The model’s payload grants the attacker a shell on the compromised machine, enabling them to gain full control over victims’ machines through what is commonly referred to as a “backdoor”...It’s crucial to emphasize that when we refer to “malicious models”, we specifically denote those housing real, harmful payloads. Our analysis has pinpointed around 100 instances of such models to date... Source LL Models used for backdoor deployment T1195.001 Supply Chain Compromise - Compromise Software Dependencies and Development Tools T1059 Command and Scripting Interpreter N/A Feb 2024 By Feb 2024 GXC Team

group leader: googleXcoder

Resecurity has uncovered a cybercriminal group known as "GXC Team", which specializes in crafting tools for online banking theft, ecommerce fraud, and internet scams. Around November 11th, 2023, the group's leader, operating under the alias "googleXcoder", made multiple announcements on the Dark Web. These posts introduced a new tool that incorporates Artificial Intelligence (AI) for creating fraudulent invoices used for wire fraud and Business E-Mail Compromise (BEC) scams.

This tool employs proprietary algorithms to scrutinize compromised emails through POP3/IMAP4 protocols, identifying messages that either mention invoices or include attachments with payment details. Upon detection, the tool alters the banking information of the intended recipient (like the victim's supplier) to details specified by the perpetrator. The altered invoice is then either replaced in the original message or sent to a predetermined list of contacts. These methods are commonly employed in wire fraud and well-known bogus invoice scams. Often, accountants and staff in victimized companies do not thoroughly check invoices that appear familiar or nearly genuine, leading to unverified payments.
The tool's multi-language capability enables the automatic scanning of messages without any manual intervention, providing the actors with significant advantages.
The tool's interface includes options to configure simple mail transfer protocol (SMTP) settings for sending out emails with the fabricated invoices it generates. Moreover, the tool includes a feature that sends reports to a designated Telegram channel, serving as an alternative to traditional command-and-control (C2C) communication. This functionality also extends to providing details about the generated invoices.

LLM-informed reconnaissance
T1592 - Gather Victim Org Information

LLM-enhanced scripting techniques
T1588 - Develop Capabilities: Tool

LLM-supported social engineering
T1566 - Phishing

LLM-directed Automated Collection
T1114 Email Collection

LLM-enhanced data manipulation
T1565 Data Manipulation
T1657 Financial Theft

Resecurity Jan 2024 Nov 2023 – Dec 2023 Multiple UnSub - South China Post Four cyber attackers in China have been arrested for developing ransomware...The attack was first reported by an unidentified company in Hangzhou, capital of eastern Zhejiang province, which had its systems blocked by ransomware, according to a Thursday report by state-run Xinhua News Agency. The hackers demanded 20,000 Tether, a cryptocurrency stablecoin pegged one-to-one to the US dollar, to restore access....The police in late November arrested two suspects in Beijing and two others in Inner Mongolia, who admitted to “writing versions of ransomware, optimising the program with the help of ChatGPT, conducting vulnerability scans, gaining access through infiltration, implanting ransomware, and carrying out extortion”, the report said. LLM-aided development T1587 - Develop Capabilities: Malware South China Post

recommend removepaywall.com for this site

Dec 2023 Unknown baller423/goober2 potentially star23/baller13 or just ties between them Recently, our scanning environment flagged a particularly intriguing PyTorch model uploaded by a new user named baller423—though since deleted. The repository, baller423/goober2, contained a PyTorch model file harboring an intriguing payload....This IP address range belonging to KREOnet, which stands for “Korea Research Environment Open NETwork,” may serve as potential evidence suggesting the involvement of researchers in attempting the exploit Source LL Models used for backdoor deployment T1195.001 Supply Chain Compromise - Compromise Software Depedencies and Development Tools T1059.001 Command and Scripting Interpreter: Powershell Feb 2024 Unknown star23/baller13 potentially baller423/goober2 or just ties between them Shortly after the model was removed, we encountered further instances of the same payload with varying IP addresses. One such instance remains active: star23/baller13. It’s worth noting the similarity in the model name to the deleted user, suggesting potential ties between them. Source LL Models used for backdoor deployment T1195.001 Supply Chain Compromise - Compromise Software Depedencies and Development Tools T1059.001 Command and Scripting Interpreter: Powershell N/A Feb 2024 Unknown Multiple Unsub - NCSC UK N/A Threat actors, including ransomware actors, are already using AI to increase the efficiency and effectiveness of aspects of cyber operations, such as reconnaissance, phishing and coding Source LLM-informed reconnaissance T1593 - Search Open Websites/Domains

LLM-supported social engineering T1566 - Phishing

LLM-aided development T1587 - Develop Capabilities: Tool

LLM-aided development T1587 - Develop Capabilities: Malware

LLM-enhanced scripting techniques T1587 - Develop Capabilities

[Multiple Unsub - NCSC](https://github.com/cybershujin/Threat-Actors-Use-of-Artifical-Intelligence/tree/main/Multiple UnSub SlashNext) Jan 2024 Unknown Multiple Unsub - SlashNext N/A Since Q4 of 2022 when ChatGPT became widely available, there has been a 1,265% increase in malicious phishing emails, with a 967% rise in credential phishing in particular. Source LLM-supported social engineering T1566 - Phishing [Multile Unsub - SlashNext](https://github.com/cybershujin/Threat-Actors-Use-of-Artifical-Intelligence/tree/main/Multiple UnSub SlashNext) Oct 2023 Oct 2022 – Sep 2023 Multiple Unsub North Korea - US National Security Advisor N/A On Oct. 18, 2023 U.S. Deputy National Security Advisor Anne Neuberger said that North Korea's use of artificial intelligence (AI) is enhancing the country's cyber capabilities, which puts enterprises around the globe at significant risk. Neuberger said, "We have observed some North Korean and other nation-state and criminal actors try to use AI models to help accelerate writing malicious software and finding systems to exploit." LLM-assisted vulnerability research T1588.006 Obtain Capabilities: Vulnerabilities

LLM-enhanced scripting techniques T1588 - Develop Capabilities: Tool

Oct 2023 Unknown Scattered Spider UNC3944, Storm-0875 In the second half of 2023, SCATTERED SPIDER used the Azure AD PowerShell module to download all Entra ID user immutable IDs at a North American financial services victim. Using its Entra ID backdoor, the adversary could log in as any of the downloaded users. The PowerShell used to download the users’ immutable IDs resembled large language model (LLM) outputs such as those from ChatGPT. In particular, the pattern of one comment, the actual command and then a new line for each command matches the Llama 2 70B model output. Source LLM-enhanced scripting techniques T1588 - Develop Capabilities: Tool Link Coming Soon Feb 2024 Unknown Indrik Spider Evil Corp In February 2023, CrowdStrike Services responded to an INDRIK SPIDER incident involving BITWISE SPIDER’s LockBit RED ransomware. During this incident, INDRIK SPIDER exfiltrated credentials from cloud-based credential manager Azure Key Vault. Logs show that INDRIK SPIDER also visited ChatGPT while interacting with the Azure Portal. In addition to visiting ChatGPT while browsing the Azure Portal — presumably to understand how to navigate in Azure — browsing activity analysis indicates INDRIK SPIDER used search engines such as Google and Bing and searched on GitHub during the operations to understand how to exfiltrate Azure Key Vault credentials. Using search engines and visiting ChatGPT indicate that though INDRIK SPIDER is likely new to the cloud and not yet sophisticated in this domain, it is using generative AI to fill these knowledge gaps. Source LLM-informed reconnaissance T1593 - Search Open Websites/Domains Source N/A Feb 2024 Feb 2023 UnSubs - Mandiant N/A but described as "actors aligned with nation-states including Russia, the People's Republic of China (PRC), Iran, Ethiopia, Indonesia, Cuba, Argentina, Mexico, Ecuador, and El Salvador, along with non-state actors such as individuals on the 4chan forum." Since 2019, Mandiant has identified numerous instances of information operations leveraging GANs, typically for use in profile photos of inauthentic personas, including by actors aligned with nation-states including Russia, the People's Republic of China (PRC), Iran, Ethiopia, Indonesia, Cuba, Argentina, Mexico, Ecuador, and El Salvador, along with non-state actors such as individuals on the 4chan forum. We judge that the publicly available nature of GAN-generated image tools such as the website thispersondoesnotexist.com has likely contributed to their frequent usage in information operations (Figure 2). Actors have also taken steps to obfuscate the AI-generated origin of their profile photos through tactics like adding filters or retouching facial features...Mandiant has noted evidence of financially motivated actors using manipulated video and voice content in business email compromise (BEC) scams, North Korean cyber espionage actors using manipulated images to defeat know your customer (KYC) requirements, and voice changing technology used in social engineering targeting Israeli soldiers. Source DeepFake for Impersonation T1587 - Develop capabilities N/A Aug 2023 2019 – Aug 2023 CanadianKingpin12 An investigation from researchers at cybersecurity company SlashNext, reveals that CanadianKingpin12 is actively training new chatbots using unrestricted data sets sourced from the dark web or basing them on sophisticated large language models developed for fighting cybercrime.
The researchers also learned that the advertiser also had access to another large language model named DarkBERT developed by South Korean researchers and trained on dark web data but to fight cybercrime.

This is not included in the analysis, but wanted to list this report for completeness. The reason this is not used in analysis is based on Dr.Chung, the Head of AI & the author of DarkBERT at S2W comment: Since S2W adheres to the strict and ethical guidelines outlined by the ACL, access to DarkBERT is granted following careful evaluation and is exclusively approved for academic and public interest.

N/A source not credible Unknown Unknown GTG-1002 Chinese state-sponsored (Anthropic designation); MITRE ATT&CK Campaign C0062 Anthropic disrupted what it calls the first reported AI-orchestrated cyber-espionage campaign: the actor manipulated Claude Code (via a "defensive security firm" roleplay jailbreak and task decomposition) into running a largely autonomous intrusion against ~30 global targets (major tech, financial, chemical, government), succeeding in a small number. AI performed an estimated 80–90% of tactical work — reconnaissance, exploit research/writing, credential harvesting, lateral movement, and data triage/exfiltration — with only 4–6 human decision points per campaign. Anthropic LLM-orchestrated operations TA0002 - Execution (full kill-chain)

LLM-informed reconnaissance T1595 - Active Scanning

LLM-assisted vulnerability research T1588.006 - Obtain Capabilities: Vulnerabilities

LLM-aided development T1587 - Develop Capabilities

LLM-directed Automated Collection T1567 - Exfiltration Over Web Service

Anthropic – Disrupting the first reported AI-orchestrated cyber espionage campaign Nov 2025 Sep 2025 GTG-2002 "vibe hacking" data-extortion actor (Anthropic) Used Claude Code as an active operational agent across at least 17 organizations (healthcare, emergency services, government, religious) in roughly a month: automated reconnaissance, credential harvesting, and network penetration, then analyzed exfiltrated data to size ransom demands ($75K–$500K+ in BTC) and generated per-victim custom HTML ransom notes. First confirmed AI-run extortion operation. Anthropic LLM-orchestrated operations TA0002 - Execution

LLM-aided development T1587.001 - Develop Capabilities: Malware

LLM-enhanced extortion/negotiation T1657 - Financial Theft

LLM-directed Automated Collection T1567 - Exfiltration Over Web Service

Anthropic – Detecting and countering misuse of AI: August 2025 Aug 2025 Unknown GTG-5004 UnSub RaaS developer (Anthropic) A low-skill criminal, apparently dependent on the model, used Claude to build, market, and sell a ransomware-as-a-service line (ChaCha20 encryption, anti-EDR, anti-recovery, Windows-internals exploitation), sold since ~January 2025 on Dread, CryptBB and Nulled at ~$400 (DLL/exe) / ~$800 (full RaaS kit with PHP console + C2) / ~$1,200 (FUD crypter). Anthropic LLM-aided development T1587.001 - Develop Capabilities: Malware

LLM-optimized payload crafting T1027 - Obfuscated Files/Information (FUD crypter)

LLM-enhanced anomaly detection evasion T1562.001 - Impair Defenses (anti-EDR)

T1490 - Inhibit System Recovery

Anthropic – Detecting and countering misuse of AI: August 2025 Aug 2025 Jan 2025 – Aug 2025 APT41 Wicked Panda, BARIUM, Winnti, Double Dragon (PRC) Through August 2025, GTIG observed APT41 using Gemini for C++/Golang code development on multiple tools — including a C2 framework the actor called OSSTUN — and for code-obfuscation help using public obfuscation libraries. GTIG LLM-aided development T1587.001 - Develop Capabilities: Malware

LLM-optimized payload crafting T1027 - Obfuscated Files/Information

T1071 - Application Layer Protocol (C2 development)

GTIG – AI Threat Tracker: Advances in Threat Actor Usage of AI Tools Nov 2025 Aug 2025 APT42 Charming Kitten, Mint Sandstorm, TA453, Yellow Garuda (Iran, IRGC) Used Gemini's text generation/editing to craft phishing material impersonating think-tank staff and for translation/geopolitical research; notably attempted to build a "Data Processing Agent" converting natural-language requests into SQL queries to mine sensitive personal data. GTIG LLM-supported social engineering T1566 - Phishing

LLM-informed reconnaissance T1591 - Gather Victim Org Information

LLM-enhanced data manipulation T1213 - Data from Information Repositories (NL-to-SQL agent)

GTIG – AI Threat Tracker Nov 2025 Unknown TEMP.Zagros MUDDYCOAST, MuddyWater, Mango Sandstorm, Static Kitten, Seedworm (Iran) Used Gemini to research and support development of custom malware (a Python C2 server and web shells) — an evolution in the group's capability — using social-engineering pretexts (posing as a student on a final-year project or a paper author) to bypass Gemini's safety guardrails. GTIG LLM-aided development T1587.001 - Develop Capabilities: Malware

T1505.003 - Server Software Component: Web Shell

GTIG – AI Threat Tracker Nov 2025 Unknown UNC1069 MASAN, CryptoCore (DPRK; BlueNoroff/Lazarus-adjacent) Used Gemini for cryptocurrency research and reconnaissance on where victims' wallet application data is stored, generated multilingual lures, and attempted crypto-theft code. Separately used AI-generated deepfake images/video (including a deepfaked crypto-company CEO on a Zoom call) to lure victims into installing the BIGMACHO backdoor disguised as a Zoom SDK. GTIG (see also the deepfake table below) LLM-informed reconnaissance T1593 - Search Open Websites/Domains

LLM-supported social engineering T1566 - Phishing

LLM-aided development T1587 - Develop Capabilities

DeepFake for Impersonation T1656 - Impersonation

GTIG – AI Threat Tracker · GTIG – UNC1069 Nov 2025 2025 UNC4899 PUKCHONG (DPRK; supply-chain compromise, TraderTraitor/Lazarus cluster) Used Gemini to develop code, research exploits (with a focus on edge devices and modern browsers), and improve tooling. GTIG LLM-assisted vulnerability research T1588.006 - Obtain Capabilities: Vulnerabilities

LLM-aided development T1587.001 - Develop Capabilities: Malware

T1195 - Supply Chain Compromise

GTIG – AI Threat Tracker Nov 2025 Unknown UNC2970 DPRK; "Operation Dream Job" recruiter-impersonation cluster (Lazarus-adjacent) Used Gemini to synthesize OSINT and profile high-value targets for campaign planning — searching information on major cybersecurity/defense firms and mapping specific technical job roles and salary data (consistent with fake-recruiter tradecraft). GTIG LLM-informed reconnaissance T1591 - Gather Victim Org Information

T1589 - Gather Victim Identity Information

Supports T1566.003 - Spearphishing via Service

GTIG – Distillation, Experimentation, and Integration of AI for Adversarial Use Feb 2026 Unknown APT31 Zirconium, Judgment Panda, Violet Typhoon (PRC) Prompted Gemini with an expert-cybersecurity persona to automate vulnerability analysis and generate targeted testing plans — in one case trialing Hexstrike MCP tooling and directing the model to analyze RCE, WAF-bypass, and SQL-injection results against specific US targets. GTIG LLM-assisted vulnerability research T1595 - Active Scanning

T1587.004 - Develop Capabilities: Exploits

Agentic/MCP-assisted offensive testing

GTIG – Distillation, Experimentation… Feb 2026 Oct 2025 – Dec 2025 (report-wide observation window) Temp.HEX PRC (Mustang Panda / TA416 reporting overlap) Misused Gemini and other AI tools to compile detailed dossiers on specific individuals (including targets in Pakistan) and collect operational and structural data on separatist organizations in multiple countries. GTIG LLM-informed reconnaissance T1591 - Gather Victim Org Information

T1589 - Gather Victim Identity Information

GTIG – Distillation, Experimentation… Feb 2026 Unknown UNC795 PRC (GTIG designator) Relied heavily on Gemini across the full attack lifecycle — engaging multiple days a week to troubleshoot code, research, and generate technical capabilities for intrusion activity, including interest in AI-integrated (agentic) code-auditing. GTIG LLM-aided development T1587.001 - Develop Capabilities: Malware

LLM-enhanced scripting techniques T1059 - Command and Scripting Interpreter

GTIG – Distillation, Experimentation… Feb 2026 Unknown UNC6418 UnSub (GTIG; targets Ukraine/defense) Misused Gemini for targeted intelligence gathering — hunting sensitive account credentials and email addresses — after which GTIG observed those same accounts hit in a phishing campaign against Ukraine and the defense sector. GTIG LLM-informed reconnaissance T1589 - Gather Victim Identity Information

LLM-supported social engineering T1566 - Phishing

GTIG – Distillation, Experimentation… Feb 2026 Q4 2025 (Oct-Dec 2025) UnSub (China-nexus, CTF-pretext) — GTIG UnSub Misused Gemini to craft lures, build infrastructure, and develop data-exfiltration tooling; when refused, reframed prompts as a "capture-the-flag (CTF) exercise" to defeat guardrails, then applied the pretext to advance phishing, exploitation, and web-shell development. GTIG LLM-supported social engineering T1566 - Phishing

T1505.003 - Server Software Component: Web Shell

GTIG – AI Threat Tracker Nov 2025 Unknown UnSub (China-nexus, cloud intrusion) — GTIG UnSub Suspected China-nexus actor leveraged Gemini across intrusion stages — reconnaissance, phishing/payload-delivery research, lateral movement, in-victim C2 support, and data-exfiltration help — including on unfamiliar surfaces (AWS, vSphere, Kubernetes). GTIG LLM-informed reconnaissance T1590 - Gather Victim Network Information

T1021 - Remote Services (lateral movement)

T1071 - Application Layer Protocol (C2)

T1567 - Exfiltration Over Web Service

GTIG – AI Threat Tracker Nov 2025 Unknown UNC5356 Financially motivated (GTIG); COINBAIT phishing kit Built the COINBAIT phishing kit using the AI app-builder platform Lovable AI (evidenced by the lovableSupabase client and lovable.app image hosting in samples). GTIG AI-generated attack infrastructure (app-builder abuse) T1583.001 - Acquire Infrastructure / T1608 - Stage Capabilities

LLM-supported social engineering T1566 - Phishing

GTIG – Distillation, Experimentation… Feb 2026 Unknown Multiple UnSub — OpenAI (Oct 2025) RU-, KR-, CN-language clusters OpenAI disrupted accounts where (a) Russian-language actors refined malware including RATs and credential stealers plus evasion; (b) Korean-language operators developed C2 systems; and (c) alleged China-linked actors crafted phishing and debugged malware targeting Taiwan's semiconductor sector, US academia and political groups. OpenAI's framing: actors "bolt AI onto old playbooks," gaining no novel capability. OpenAI LLM-aided development T1587.001 - Develop Capabilities: Malware

T1071 - Application Layer Protocol (C2 development)

LLM-supported social engineering T1566 - Phishing

LLM-enhanced scripting techniques T1059 - Command and Scripting Interpreter

OpenAI – Disrupting malicious uses of AI: October 2025 Oct 2025 2025 UnSub carding operator — Anthropic UnSub Used Claude to build out a carding (stolen-payment-card) service, developing advanced API-integration and operational-resilience mechanisms for the criminal service. Anthropic LLM-advised resource development T1587 - Develop Capabilities

T1102 - Web Service (API integration)

Anthropic – Threat Intelligence Report: August 2025 (PDF) Aug 2025 Unknown RevengeHotels TA558 (Kaspersky) Summer-2025 campaigns against Brazilian and Spanish-speaking hotels in which a significant portion of the initial-infector and downloader code appears LLM-generated (clean structure, placeholder variables, verbose per-action comments), delivering VenomRAT (HVNC, stealer, reverse proxy, UAC bypass). Analyst note: LLM authorship inferred from code style, not captured model logs. Kaspersky LLM-enhanced scripting techniques T1059 - Command and Scripting Interpreter

LLM-aided development T1587.001 - Develop Capabilities: Malware

T1566.001 - Spearphishing Attachment

Kaspersky/Securelist – RevengeHotels with AI and VenomRAT Sep 2025 Summer 2025 (Jun-Aug 2025) Armored Likho Eagle Werewolf (Kaspersky) Spear-phishing espionage against government and electric-power targets in Russia, Kazakhstan and Brazil; loader source shows verbose comments, bullet-point emoji, and redundant blocks that Kaspersky attributes to LLM generation, deploying the new Python BusySnake Stealer (PyArmor-obfuscated; credential/cookie theft, reverse SSH). Analyst note: LLM authorship inferred from code style. Kaspersky LLM-aided development T1587.001 - Develop Capabilities: Malware

T1566.001 - Spearphishing Attachment

T1027 - Obfuscated Files/Information

Kaspersky/Securelist – Armored Likho's BusySnake Stealer Jul 2026 Unknown Global Group RaaS (SentinelLABS) From mid-2025 advertised an "AI-Assisted Chat" negotiation feature to affiliates that analyzes victim-company data (revenue, public behavior) to tailor extortion communications and pressure victims — AI operationalized in the extortion/negotiation phase. SentinelLABS LLM-enhanced extortion/negotiation T1657 - Financial Theft

LLM-informed reconnaissance T1591 - Gather Victim Org Information

SentinelLABS – LLMs & Ransomware: An Operational Accelerator Dec 2025 Mid 2025 Multiple UnSub — CrowdStrike UnSub (eCrime) CrowdStrike's 2026 Global Threat Report: adversaries exploited legitimate GenAI tools at 90+ organizations by injecting malicious prompts to generate commands used to steal credentials and cryptocurrency (no named actor). CrowdStrike also reports ChatGPT referenced in criminal forums 550% more than any other model, and an 89% YoY rise in AI-enabled operations. Bias note: vendor sells EDR/identity products. CrowdStrike LLM-enhanced scripting techniques T1059 - Command and Scripting Interpreter

T1555 - Credentials from Password Stores

T1657 - Financial Theft

CrowdStrike – 2026 Global Threat Report Feb 2026 2025 Multiple UnSub — Proofpoint UnSub (multiple operators) Cybercriminals abused Lovable (an AI site-builder) to mass-produce credential-phishing pages (Microsoft/bank spoofs behind CAPTCHA), fraud sites funneling to Telegram, crypto-wallet-draining DeFi clones, and redirectors delivering zgRAT/DOILoader — tens of thousands of malicious Lovable URLs per month since February 2025, affecting 5,000+ organizations. Bias note: vendor sells email/URL security. Proofpoint AI-generated attack infrastructure (app-builder abuse) T1583.001 - Acquire Infrastructure / T1608 - Stage Capabilities

LLM-supported social engineering T1566 - Phishing

T1657 - Financial Theft

Proofpoint – Cybercriminals Abuse AI Website Creation App For Phishing Aug 2025 Feb 2025 – Jul 2025 Coral Sleet Storm-1877 (DPRK) Microsoft observed rapid capability growth via AI-assisted iterative development — using AI coding tools to generate, refine and reimplement malware components, agentic AI for an end-to-end lure-development workflow, and jailbroken LLM software to generate malicious code. Microsoft LLM-aided development T1587.001 - Develop Capabilities: Malware

LLM-supported social engineering T1566 - Phishing (agentic lure development)

Microsoft – AI as tradecraft: How threat actors operationalize AI Mar 2026 Unknown Sapphire Sleet DPRK (crypto-theft / fake-recruiter cluster) Develops fake digital personas using AI to support social-engineering campaigns targeting employment/recruitment opportunities. Microsoft LLM-supported social engineering T1585 - Establish Accounts (AI personas)

T1566.003 - Spearphishing via Service

Microsoft – AI as tradecraft Mar 2026 Unknown QUIETVAULT UnSub (GTIG); JS credential stealer A credential/token stealer (GitHub/npm tokens) that, beyond its primary targets, invokes AI prompts and on-host installed AI CLI tools to search the infected system for additional secrets, then exfiltrates via attacker-created public GitHub repos. Novel abuse of the victim's own AI tooling. GTIG LL Models used for backdoor deployment (on-host AI abused for collection) T1552 - Unsecured Credentials

T1119 - Automated Collection

T1567 - Exfiltration Over Web Service

GTIG – AI Threat Tracker Nov 2025 Unknown PROMPTFLUX UnSub (GTIG; likely financially motivated) Experimental VBScript dropper with a "Thinking Robot" module that calls the Gemini API at runtime to request VBScript obfuscation/evasion techniques for "just-in-time" self-modification, rewriting its own source into the Startup folder; spreads via removable drives and network shares. GTIG assesses it experimental and not yet observed deployed in operations. GTIG LLM-embedded malware (runtime generation) T1027 - Obfuscated Files/Information

T1059.005 - Command and Scripting Interpreter: Visual Basic

T1547.001 - Registry Run Keys / Startup Folder

GTIG – AI Threat Tracker Nov 2025 Unknown UnSub — Huntress (AI-generated AD recon) UnSub An unnamed actor deployed an AI-generated PowerShell script (self-labeled "100% Working AD Information Gathering Script - FULLY FIXED") to enumerate Active Directory, alongside s5cmd and SharpShares. Huntress via The Hacker News LLM-enhanced scripting techniques T1059.001 - Command and Scripting Interpreter: PowerShell

T1087 - Account Discovery

T1069 - Permission Groups Discovery

The Hacker News (reporting Huntress) – Attacker Uses Suspected AI-Generated PowerShell to Map AD Jul 2026 Jun 2026 UNC2814 GTIG vulnerability-research cluster In GTIG's May 2026 tracker, UNC2814 used "expert persona" prompting — directing Gemini to act as a senior security auditor / C-C++ binary security expert — to drive vulnerability research on embedded devices (router firmware, hunting pre-auth RCE). GTIG LLM-assisted vulnerability research T1588.006 - Obtain Capabilities: Vulnerabilities

T1587.004 - Develop Capabilities: Exploits

GTIG – AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation May 2026 Unknown APT45 DPRK state-sponsored (GTIG/Mandiant) GTIG observed APT45 sending thousands of repetitive prompts that recursively analyze different CVEs and validate PoC exploits — scaled, automated AI-assisted vulnerability research — and experimenting with agentic tooling. GTIG LLM-assisted vulnerability research T1588.006 - Obtain Capabilities: Vulnerabilities

T1587.004 - Develop Capabilities: Exploits

GTIG – AI Threat Tracker (May 2026) May 2026 Unknown APT27 Emissary Panda, Iron Tiger, LuckyMouse, Budworm, Bronze Union (PRC) PRC-nexus APT27 leveraged Gemini to accelerate development of a fleet-management application likely to support the operation of an operational relay box (ORB) network (samples had hardcoded maxHops and device-type support). GTIG LLM-aided development T1587.001 - Develop Capabilities: Malware

T1583 - Acquire Infrastructure (ORB network)

GTIG – AI Threat Tracker (May 2026) May 2026 Unknown UNC6201 PRC-nexus (GTIG) PRC-nexus UNC6201 attempted to use a public GitHub Python script that automatically registers and immediately cancels premium LLM accounts at scale (across Gemini, Claude and OpenAI) to obtain anonymized premium model access. GTIG LLM-advised resource development T1585 - Establish Accounts

T1583.003 - Acquire Infrastructure: Virtual Private Server

GTIG – AI Threat Tracker (May 2026) May 2026 Unknown UNC5673 PRC-nexus; notable overlaps with TEMP.Hex (GTIG) PRC-nexus UNC5673 built obfuscated, scalable LLM-abuse infrastructure — account pooling and cost-sharing proxy middleware (Claude-Relay-Service, CLI-Proxy-API) fronting Gemini/Claude/OpenAI — while targeting government sectors in South and Southeast Asia. GTIG LLM-advised resource development T1585 - Establish Accounts

T1090 - Proxy

T1583.003 - Acquire Infrastructure: Virtual Private Server

GTIG – AI Threat Tracker (May 2026) May 2026 Unknown UnSub (AI-developed zero-day) — GTIG UnSub (cybercrime) GTIG assessed with high confidence that an actor leveraged an AI model (assessed NOT to be Gemini) to support discovery and weaponization of a zero-day 2FA-bypass in a popular open-source web-based sysadmin tool — GTIG's first observed AI-developed zero-day; planned mass-exploitation was likely disrupted by proactive counter-discovery. Code carried LLM-characteristic docstrings and a hallucinated CVSS score. GTIG LLM-assisted vulnerability research T1588.006 - Obtain Capabilities: Vulnerabilities

T1587.004 - Develop Capabilities: Exploits

GTIG – AI Threat Tracker (May 2026) May 2026 Unknown UnSub (Russia-nexus) — GTIG UnSub; malware CANFAIL, LONGSTREAM An unattributed Russia-nexus actor delivered AI-enabled malware (CANFAIL, LONGSTREAM) against Ukraine that uses LLM-generated decoy code (repetitive benign filler routines) to obfuscate its malicious functionality. GTIG LLM-aided development T1587.001 - Develop Capabilities: Malware

T1027 - Obfuscated Files/Information (LLM-generated decoy code)

GTIG – AI Threat Tracker (May 2026) May 2026 Unknown Storm-1747 Tycoon2FA operators (Microsoft) Microsoft attributes the Tycoon2FA phishing-as-a-service platform to Storm-1747; operators use AI to refine phishing lure content at scale (tens of millions of emails/month, ~62% of the phishing Microsoft was blocking), with AI-refined messages reaching ~54% click-through vs ~12% for traditional campaigns. The platform performs adversary-in-the-middle (AiTM) attacks that defeat MFA by intercepting credentials and session tokens in real time. Microsoft LLM-supported social engineering T1566.002 - Spearphishing Link

T1557 - Adversary-in-the-Middle

T1539 - Steal Web Session Cookie

T1550.004 - Use Alternate Authentication Material: Web Session Cookie

Microsoft – Threat actor abuse of AI accelerates from tool to cyberattack surface Apr 2026 Unknown PROMPTSPY UnSub (GTIG; ESET-identified Android backdoor) Android backdoor (identified with ESET) that embeds an autonomous Gemini-API agent to navigate the device UI and drive on-device data theft. GTIG assesses it experimental and unattributed. Analyst note: included alongside PROMPTFLUX as experimental, unattributed AI-embedded malware. GTIG LLM-embedded malware (runtime generation) T1059 - Command and Scripting Interpreter

LLM-directed Automated Collection T1119 - Automated Collection

GTIG – AI Threat Tracker (May 2026) May 2026 Unknown UnSub (suspected PRC-nexus, agentic frameworks) — GTIG UnSub A suspected PRC-nexus actor deployed agentic offensive-security frameworks (Hexstrike, Strix) against a Japanese technology firm and an East Asian cybersecurity platform — confirmed AI-as-tool use across the intrusion, though GTIG did not assign a named cluster. GTIG LLM-orchestrated operations TA0002 - Execution (agentic offensive frameworks)

LLM-assisted vulnerability research T1595 - Active Scanning

GTIG – AI Threat Tracker (May 2026) May 2026 Unknown JADEPUFFER "Agentic Threat Actor (ATA)" (Sysdig) Sysdig's Threat Research Team documented what it assesses as the first fully agentic ransomware operation — an extortion campaign driven end-to-end by an LLM agent. The agent gained initial access to an internet-facing Langflow instance (CVE-2025-3248, unauthenticated Python execution), then autonomously ran reconnaissance, harvested credentials (LLM API keys, cloud, database, crypto wallets), moved laterally (MinIO default credentials, Nacos compromise), established persistence (a crontab beacon every 30 minutes), and executed impact — AES-encrypting 1,342 Nacos configurations, dropping database tables, and writing a ransom note — across 600+ coordinated payloads. Sysdig's evidence that it was LLM-driven: self-narrating payload commentary, machine-speed error diagnosis/correction (a failed Nacos login was root-caused and fixed in 31 seconds), natural-language context comprehension, and structured task-completion markers. Bias note: Sysdig sells cloud/runtime security. Sysdig LLM-orchestrated operations TA0002 - Execution (full end-to-end kill-chain)

T1190 - Exploit Public-Facing Application

T1552 - Unsecured Credentials

T1486 - Data Encrypted for Impact

LLM-enhanced extortion/negotiation T1657 - Financial Theft

Sysdig – JADEPUFFER: Agentic ransomware for automated database extortion Jul 2026 Unknown UnSub (Iranian-nexus developer) — Unit 42 TuxBot v3; Keksec-ecosystem-adjacent IoT botnet Unit 42 recovered a multi-architecture IoT botnet (Telnet/SSH scanner with 1,496 credential pairs, persistence, C2) whose developer relied heavily on LLM-generated code throughout — bot modules, C2 server code, and porting a public ADB exploit into a custom format — with verbatim LLM chain-of-thought comments left in the source files. Live since Jan 2026 (first VirusTotal submission), with fresh April 2026 samples and active C2 telemetry (Xpanse). A leaked build hostname on Iran's ArvanCloud CDN ties development to an Iran-hosted workstation. Analyst note: the LLM hallucinated an Argon2id implementation (silently fell back to SHA256 while keeping Argon2id-labeled comments) and left boilerplate "for educational and authorized security research only" disclaimers in the malware source. Unit 42 LLM-aided development T1587.001 - Develop Capabilities: Malware

LLM-assisted vulnerability research T1587.004 - Develop Capabilities: Exploits (ADB exploit porting)

T1584 - Compromise Infrastructure (botnet build/C2)

Unit 42 – TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Code Jul 2026 Jan 2025 – Apr 2026 bandcampro UnSub (Russian-speaking; Trend Micro designation) Trend Micro/TrendAI recovered captured Gemini CLI session logs showing bandcampro used a jailbroken Gemini (posing as an "authorized penetration tester" to suppress safety disclaimers) for an estimated ~90% of a fraud operation — writing and deploying C2 server code, migrating botnet infrastructure to a new VPS behind a Cloudflare tunnel in 6 minutes, running multithreaded credential/password scanning, processing infostealer dumps, and self-diagnosing its own C2 bugs ("Bro, I solved the riddle!"). Compromised 8 machines at a US dental clinic (accessing its Open Dental database) and targeted individuals for crypto-wallet theft. Trend Micro/TrendAI via The Register LLM-orchestrated operations (Agentic AI attack orchestration) TA0002 - Execution (~90% of operation AI-driven)

LLM-aided development T1587.001 - Develop Capabilities: Malware (C2 server code)

LLM-directed Automated Collection T1119 - Automated Collection (infostealer-dump processing)

T1583 - Acquire Infrastructure (C2 migration)

The Register – 'The bots are alive!' Jailbroken Gemini spun up new C2 server for Russian fraudster in just 6 minutes Jul 2026 Mar 2026 – Apr 2026 UnSub (suspected China-nexus) — Hunt.io UnSub Hunt.io discovered an exposed operational C2 directory (2,431 files) revealing a suspected China-based actor running Claude Code (agentic execution — Bash commands, parallel sessions, phishing-page deployment) and DeepSeek-v4-pro (attack-logic reasoning, exploit-script generation, bypass re-strategizing after failed attempts) in tandem. Confirmed compromise with data theft against a Thai government system (SQLi) and an Afghan government portal (custom deserialization exploit); 2 of 10 mapped Taiwanese firms successfully exploited, 8 reconnaissance-only; NASA-adjacent US hosts scanned only; a financial-services CORS exploit extracted admin credentials from a payment processor. Active June 8–12, 2026. Attribution (Simplified Chinese artifacts, Hong Kong-hosted infrastructure, TTP overlap with a prior suspected-China C2 cluster) is explicitly moderate-confidence, not a named-group claim. Hunt.io LLM-orchestrated operations (Agentic AI attack orchestration) TA0002 - Execution

LLM-assisted vulnerability research T1587.004 - Develop Capabilities: Exploits (DeepSeek-generated bypasses)

T1190 - Exploit Public-Facing Application (SQLi, webshells)

LLM-supported social engineering T1566 - Phishing (Claude Code-built clone pages)

T1567 - Exfiltration Over Web Service

Hunt.io – Chinese Operators, Claude, DeepSeek Government Intrusion · SecurityAffairs coverage Jul 2026 May 2026 – Jun 2026 UnSub (financially motivated) — Sygnia UnSub Sygnia incident response on a breached AWS environment found behavioral evidence consistent with agentic-AI-assisted execution — four access keys from four separately compromised accounts used from the same source IP/user-agent within the same second, checklist-style rapid technique execution across newly discovered surfaces, and cross-credential "operational memory" spanning dozens of identities. The actor progressed from initial access to broad cloud takeover in ~72 hours (credential/secrets harvesting, new IAM users, reverse shells, RDS data exfiltration). Analyst note: the AI-involvement evidence is behavioral/inferential (speed, parallelism, code style) — Sygnia does not claim to have captured LLM prompts or recovered agent tooling directly, and is appropriately hedged in its own language; vendor sells IR/cloud-security services. Sygnia LLM-orchestrated operations (Agentic AI attack orchestration) TA0002 - Execution (parallel, cross-identity)

T1552 - Unsecured Credentials

T1136 - Create Account (IAM users)

T1567 - Exfiltration Over Web Service (RDS data)

Sygnia – Inside an AI-Assisted Cloud Attack Jun 2026 Unknown UnSub (autonomous AI agent framework) — Hugging Face UnSub Hugging Face disclosed a July 2026 intrusion of its internal infrastructure that its own incident response assessed was run by an autonomous agent framework (built on an agentic security-research harness; the underlying LLM was not identified). Initial access came via malicious datasets exploiting two code-execution flaws in the dataset-processing pipeline — a remote-code dataset loader and template injection in dataset configuration — after which the agent executed code on processing workers, escalated to node-level access, harvested several service credentials, and moved laterally across internal clusters over a weekend. Hugging Face logged 17,000+ recorded agent actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services. A limited set of internal datasets was accessed; Hugging Face found no evidence of tampering with public models, datasets, or Spaces, and verified the software supply chain clean. Analyst note: this is the victim's own IR disclosure; no threat actor is named or attributed and the specific model is unidentified — the agentic/AI-driven characterization is Hugging Face's own. Hugging Face LLM-orchestrated operations (Agentic AI attack orchestration) TA0002 - Execution (autonomous agent, 17,000+ actions across ephemeral sandboxes)

T1190 - Exploit Public-Facing Application (dataset-loader RCE + template injection)

T1552 - Unsecured Credentials (service credentials harvested)

T1102 - Web Service (self-migrating C2 on public services)

Hugging Face — Security incident, July 2026 Jul 2026 Jul 2026 LAUNDRY BEAR Void Blizzard (Microsoft); CL-STA-1114 (Unit 42); TA488 (Proofpoint) A joint advisory from CISA, FBI and NSA with international partners (AA26-204A) attributes to the Russian state-supported actor LAUNDRY BEAR a phishing campaign against users of the Zimbra Collaboration Suite, targeting government, defense, energy, technology, education, media, law enforcement and non-governmental organizations since at least July 2025. The actor weaponized CVE-2025-66376, a cross-site scripting flaw caused by insufficient sanitization of CSS @import directives in message content, so that simply opening a crafted phishing email caused Zimbra's own webmail interface to execute attacker-supplied JavaScript inside the victim's authenticated session. Harvested material — up to 90 days of email history per victim, the organization's internal directory, live two-factor authentication tokens and any application passcode generated after compromise — was exfiltrated to "Flowerbed", a container-based collection framework running on short-lived virtual private servers. The advisory assesses that AI tools were used to help develop the Flowerbed codebase. Analyst note: government joint advisory (trusted tier); the AI-assistance finding is an assessment stated by the authoring agencies, not a recovered artifact. Microsoft separately assesses the actor as active since at least April 2024 — the span below reflects the campaign window described in this advisory. LLM-aided development T1588.007 - Obtain Capabilities: Artificial Intelligence (AI tooling assessed as used to build the Flowerbed framework)

T1587.001 - Develop Capabilities: Malware (Flowerbed collection framework)

T1566 - Phishing (crafted Zimbra phishing mail)

T1203 - Exploitation for Client Execution (CVE-2025-66376 XSS executing on message open)

T1114.002 - Email Collection: Remote Email Collection (90 days of mail per victim)

CISA AA26-204A — Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Jul 2026 Jul 2025 – Jul 2026 UnSub (FakeAgent) — Huntress UnSub Huntress documented "FakeAgent", a malvertising campaign that abused a public Claude Artifact hosted on Anthropic's own claude.ai domain as the delivery lure. Users searching Bing for the Claude Desktop app were served a sponsored advertisement pointing at a legitimate claude.ai URL; that URL resolved to an attacker-built Claude Artifact crafted to imitate the official Claude Desktop download page, which redirected victims to attacker-controlled infrastructure serving a fake ClaudeDesktop.exe. The payload was SectopRAT, a .NET remote-access trojan that steals credentials, browser data, payment-card details and files, and which retrieved its command-and-control details from data staged in the Ethereum blockchain as an anti-takedown and anti-analysis technique. The malicious artifact was downloaded roughly 7,100 times, and Huntress observed impact across 29 organizations before Anthropic removed it on 22 July 2026 following Huntress's report. Analyst note: vendor report (Huntress, trusted tier). Included because the actor used a generative-AI app builder to produce the malicious lure page itself — the attack infrastructure was AI-generated — rather than merely abusing AI-branded hosting. AI-generated attack infrastructure (app-builder abuse) T1583.001 - Acquire Infrastructure: Domains (lure served from the legitimate claude.ai domain via a public Artifact)

T1608 - Stage Capabilities (fake installer page staged as a Claude Artifact)

T1583.008 - Acquire Infrastructure: Malvertising (sponsored Bing ads)

T1204.002 - User Execution: Malicious File (trojanized ClaudeDesktop.exe)

T1102 - Web Service (C2 details staged on the Ethereum blockchain)

Huntress — Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT Jul 2026 Jul 2026 STAC6994 Unknown (Sophos-designated cluster) Sophos analysts discovered a rogue device running continuous payload generation inside a customer environment, and identified a threat actor using AI to test EDR evasion tactics in a 'red team' post-exploitation framework. The operator provisioned virtual machines from Ludus and drove the Cursor IDE with approximately 12 AI agents in defined roles: one agent running Claude Opus 4.5 handled core operations and rule-setting, while others managed OPSEC hardening, documentation, proxy stress testing, VM deployment, and testing tools against the EDR agents. Code commits flowed to Git through Model Context Protocol (MCP). The framework ran parallel testing across three environments — one VM with Sophos endpoint protection, one with CrowdStrike, and one with no EDR as a control — while a fourth VM operated as a Sliver C2 server. According to recovered artifacts, the agents read research articles scraped from the SpecterOps blog, extracted offensive techniques, mapped them to the MITRE ATT&CK framework, identified the steps and tools needed to reproduce each technique, prepared the lab environment, executed it, and reported findings. At the core was a Python-based modular payload generator that wrapped raw payloads in layers of encryption and evasion techniques, producing custom executables in Rust and Go — nearly 80 modules testing over 70 different techniques. Sophos notes the crucial operational signal was tempo: the full cycle compressed weeks into days. Sophos CTU confirmed the STAC6994 operator subsequently engaged in ransomware deployment and data theft; the framework was a production tool for real intrusions. Sophos X-Ops

Analyst note: Sophos records two caveats worth preserving — agent documentation claimed near-universal success against the EDR agents, but Sophos analysts noted "the evidence did not fully support that conclusion"; and "the evidence did not show AI embedded inside deployed malware" (AI was developer-side only). Vendor report, and Sophos's own product is one of the EDRs tested in the lab described.

LLM-agent-driven capability development and evasion testing T1587.001 - Develop Capabilities: Malware

LLM-enhanced anomaly detection evasion T1562.001 - Impair Defenses: Disable or Modify Tools

LLM-aided development T1587 - Develop Capabilities

LLM-assisted vulnerability research T1588.006 - Obtain Capabilities: Vulnerabilities

LLM-optimized payload crafting T1027 - Obfuscated Files or Information

Sophos X-Ops — AI Security 2026 Jul 2026 May 2026 UnSub (Mexican government campaign) — Gambit Security UnSub (no designation assigned by the reporting vendor) Gambit Security documented a single operator who compromised nine Mexican government organizations using two commercial AI platforms as core operational tools. Victims included SAT (Servicio de Administración Tributaria, the federal tax authority), the Estado de México, Jalisco, Michoacán and Tamaulipas state governments, the Registro Civil de CDMX and Salud CDMX, the INE electoral institute, and the SADM Monterrey municipal water utility. Per Gambit: "The campaign relied heavily on two commercial AI platforms as core operational tools - Anthropic's Claude Code and OpenAI's GPT-4.1 API. These systems performed much of the technical work, including reconnaissance, exploit customization, privilege escalation, database architecture mapping, exfiltration infrastructure development, tunnel chain construction, and credential harvesting." Gambit logged 1,088 operator prompts driving 5,317 AI-executed commands across 34 sessions, 20 exploit scripts covering 20 CVEs, and 400+ custom scripts (301 Bash, 113 Python); a custom 17,550-line Python tool (BACKUPOSINT.py) used the GPT-4.1 API to generate 2,597 intelligence reports across 305 SAT servers. Gambit assessed that "approximately 75 percent of remote command execution activity across the campaign was generated and executed by Claude Code via its tool-use interface." On guardrails, Gambit records: "In 40 minutes, the conversation moved from 'I'm not going to create that file' to 'What command do you want to execute now?' on a live government server... The guardrails did not hold in this case." When Claude refused to write an anti-forensics rulebook, the operator pasted a pre-written 1,084-line pentest cheatsheet and asked Claude to save it — processed as a file-write rather than a content-generation request — after which it persisted as claude.md, auto-loading as a system prompt every session. First publicly disclosed via a Bloomberg exclusive (25 Feb 2026); Anthropic's only on-record statement was that it banned the accounts involved. Gambit Security

Analyst note: Gambit assigns no actor designation and states no attribution; the word "attribution" does not appear in the report. Motivation appears financially driven (a commercial document-forgery service and a live SAT query API). The report is explicitly self-limiting — "This report is not comprehensive… only selected portions are analyzed" — and its underlying forensic material is available only to trusted parties on request, so the evidence is not independently reviewable. The widely repeated "150GB" and "ten government bodies" figures are press-reported, not in the report, which says nine.

LLM-orchestrated operations (Agentic AI attack orchestration) TA0002 - Execution (Claude Code executed ~75% of remote commands)

LLM-informed reconnaissance T1592 - Gather Victim Org Information

LLM-assisted vulnerability research T1588.006 - Obtain Capabilities: Vulnerabilities

LLM-enhanced scripting techniques T1059 - Command and Scripting Interpreter

LLM-directed Automated Collection T1213 - Data from Information Repositories

T1567 - Exfiltration Over Web Service

Gambit Security — A Single Operator, Two AI Platforms, Nine Government Agencies

Technical report PDF

Apr 2026 Nov 2025 – Feb 2026 UnSub (FortiGate campaign) — Amazon Threat Intelligence UnSub (no designation assigned) Amazon Threat Intelligence documented a financially motivated, Russian-speaking operator (individual or small group, assessed at "low-to-medium baseline technical capability" and explicitly not linked to any state-sponsored group) who compromised 600+ FortiGate devices across 55+ countries between 11 January and 18 February 2026. Initial access was credential abuse against internet-exposed management interfaces (ports 443, 8443, 10443, 4443) protected by single-factor authentication — not CVE exploitation; CVEs appear in the actor's target catalogue rather than the entry path. AI use here was directly observed in recovered artifacts rather than inferred from tempo, which makes this one of the better-evidenced cases in the corpus: the actor's misconfigured server (1,400+ files across 139 subdirectories) held claude and claude-0 directories containing 200+ files of Claude Code task outputs, session diffs and cached prompt states; a .claude/settings.json pre-approving Claude Code to autonomously run Impacket, Metasploit and hashcat, with hardcoded domain credentials; a vulnerability assessment report dated 1 Feb 2026 attributed to Claude Code in its footer, with a 400ms round-trip time confirming live remote execution; and a deepseek_attack_plan.py script generating attack plans from reconnaissance data. Custom tooling included ARXON (a Python MCP server) and CHECKER2 (a Go/Docker parallel VPN-scanning orchestrator), the actor having migrated from the public HexStrike framework. Amazon Threat Intelligence, with artifact analysis by Cyber and Ramen

Analyst note: Amazon deliberately withheld vendor names, saying only that the actor "uses at least two distinct commercial LLM providers"; the DeepSeek and Claude attribution comes from Cyber and Ramen's independent analysis of the exposed server. Beware secondary coverage naming "CyberStrikeAI" as the actor or platform — that string appears in neither primary and appears to be a content-farm fabrication.

LLM-orchestrated operations (Agentic AI attack orchestration) TA0002 - Execution (Claude Code pre-approved to run offensive tooling autonomously)

LLM-assisted vulnerability research T1588.006 - Obtain Capabilities: Vulnerabilities

LLM-advised resource development T1587 - Develop Capabilities (ARXON MCP server, CHECKER2 orchestrator)

LLM-informed reconnaissance T1595 - Active Scanning

T1110 - Brute Force / Credential abuse against exposed management interfaces

Amazon — AI-augmented threat actor accesses FortiGate devices at scale

Cyber and Ramen — LLMs in the Kill Chain

Feb 2026 Jan 2026 – Feb 2026 Earth Krahang Unknown China-aligned actor. Trend Micro's 2026 H1 APT report records: "It used generative AI to enhance a publicly available proof-of-concept exploit for CVE-2026-0740, a vulnerability in the Ninja Forms – File Uploads plugin for WordPress. The enhanced exploit could conduct large-scale automated scans to identify vulnerable public-facing servers. The group also installed Trae, an integrated development environment (IDE) AI coding tool developed by ByteDance, on its C&C server. AI-generated code comments written in Simplified Chinese suggested the operator's origin." Trend states H1 2026 was the first time its research teams documented this group integrating generative AI into the attack lifecycle. Group profile: global government and defense sectors. Trend Micro

Analyst note: the model behind the exploit enhancement is not named — the report says only "generative AI." Trae is a separate observation (found installed on the C&C server) and should not be conflated with the tool used to enhance the exploit. Evidence is artifact-based from the actor's own infrastructure. Trend gives no per-campaign dates for this activity, so the Activity Span reflects the report's stated Jan–Jun 2026 scope, not an observed campaign window. CVE-2026-0740's NVD publication date (7 Apr 2026) is not linked by Trend to the campaign and should not be read as a start date.

LLM-assisted vulnerability research T1588.006 - Obtain Capabilities: Vulnerabilities

LLM-aided development T1587 - Develop Capabilities

LLM-optimized payload crafting T1588 - Develop Capabilities: Tool

LLM-informed reconnaissance T1595 - Active Scanning

Trend Micro — 2026 H1 APT Report

Full report PDF

Jul 2026 Jan 2026 – Jun 2026 Earth Naga Associated with Flax Typhoon (per Trend Micro) China-aligned actor. Trend Micro's 2026 H1 APT report records: "It has been observed to use an iterative AI prompting workflow ('vibe coding') to develop a malicious PowerShell script. The script compiles and executes C# code at runtime to perform process hollowing and reflective loading of backdoor payloads. Multiple evolving versions of the script were found on the hosting server, with the AI's responses to prompts left inside the code as comments; these comments inadvertently revealed the development methodology." Group profile: critical infrastructure, government and technology sectors. Trend Micro

Analyst note: Trend names no loader or malware family for this script, and names no AI vendor or model. The evidence basis is the strongest of the three Trend AI cases — multiple evolving script versions recovered from the actor's hosting server with the AI's own prompt responses left in as code comments. No per-campaign dates are given; the Activity Span reflects the report's Jan–Jun 2026 scope, not an observed window.

LLM-aided development T1587.001 - Develop Capabilities: Malware

LLM-enhanced scripting techniques T1059.001 - Command and Scripting Interpreter: PowerShell

T1055.012 - Process Injection: Process Hollowing

T1620 - Reflective Code Loading

Trend Micro — 2026 H1 APT Report

Full report PDF

Jul 2026 Jan 2026 – Jun 2026 UnSub (possibly Earth Lamia) — Trend Micro UnSub Trend Micro's 2026 H1 APT report records: "The use of an autonomous AI agent for lateral movement by an unknown actor (possibly Earth Lamia). The group deployed the Claude Code command-line interface (CLI) as an autonomous AI agent against an organization in Thailand. The actor jailbroke the AI model by falsely claiming the operation was a legitimate penetration test. The AI agent then autonomously conducted internal network scanning, exploitation attempts (EternalBlue, SMBGhost, PrintNightmare, SMB relay), credential harvesting (via secretsdump, LaZagne, and Impacket), and password spraying." Trend Micro

Analyst note: Trend attributes this primarily to "an unknown actor," with "possibly Earth Lamia" as a hedge — the name appears exactly once across the 28-page report — so this is logged under the UnSub convention rather than as an Earth Lamia entry. Target sector is not stated. No per-campaign dates are given; the Activity Span reflects the report's Jan–Jun 2026 scope. The false-authorization jailbreak pretext is recorded here as tradecraft detail; it is not mapped as a TTP label, as guardrail-bypass sits on the out-of-scope 'attacks on AI' side of this project's line.

LLM-orchestrated operations (Agentic AI attack orchestration) TA0008 - Lateral Movement (agent ran the intrusion autonomously)

T1595 - Active Scanning

T1210 - Exploitation of Remote Services (EternalBlue, SMBGhost, PrintNightmare, SMB relay)

T1003 - OS Credential Dumping (secretsdump, LaZagne, Impacket)

T1110.003 - Brute Force: Password Spraying

Trend Micro — 2026 H1 APT Report

Full report PDF

Jul 2026 Jan 2026 – Jun 2026 DragonForce Unknown In a DragonForce ransomware case investigated by the Sophos Incident Response team, "the threat actor produced what we strongly suspect to be an AI-generated report during negotiations with the targeted organization, containing a detailed analysis of the exfiltrated data, including PII and legal risks. AI-generated analysis was used as part of an attempt to exert pressure and persuade the organization to pay the ransom." Sophos places this at the lightest-touch end of its AI autonomy gradient — a human using generative AI to produce an artifact and deploying it manually. Sophos X-Ops

Analyst note: Sophos's own IR casework (primary), but the AI attribution is explicitly "strongly suspect," not confirmed — the same confidence level as the existing TA547 and Multiple UnSub – Symantec entries. No dates, model, or campaign window are given.

LLM-enhanced extortion/negotiation T1657 - Financial Theft

LLM-directed Automated Collection T1213 - Data from Information Repositories (analysis of exfiltrated victim data)

Sophos X-Ops — AI Security 2026 Jul 2026 Unknown The Gentlemen Unknown Sophos, describing the lightest-touch tier of its AI autonomy gradient (a human using generative AI to produce an artifact and deploying it manually, noted alongside a threat actor targeting Mexican government organizations that used Claude Code and GPT to generate scripts): "Leaked chats from The Gentlemen ransomware group confirmed similar applications." Sophos X-Ops

Analyst note: this single sentence is the full extent of Sophos's reporting on this group's AI use — no detail, no model, no dates, and no campaign window is stated, so Activity Span is recorded as Unknown rather than inferred. Included on the strength of the named actor plus leaked-chat evidence; expand if better primary reporting emerges.

LLM-aided development T1587 - Develop Capabilities

LLM-enhanced scripting techniques T1588 - Develop Capabilities: Tool

Sophos X-Ops — AI Security 2026 Jul 2026 Unknown UnSub (DAIQ Wealth sha zhu pan) — Sophos CTU UnSub "Sophos CTU investigated a sha zhu pan scheme involving AI-themed social engineering. A UK-based victim was drawn into a fake AI-powered investment platform called DAIQ Wealth through months of AI-themed 'lessons' on the LINE messaging app. A network of personas built rapport through group chats, each operated by a different individual, suggesting an organized workforce following predefined scripts. The victim lost hundreds of thousands of pounds. When the victim expressed concern about holding almost £20,000 GBP in cash at home, the scammers arranged a physical cash courier to the UK address within 24 hours, complete with a branded receipt from a legitimate financial firm used without its knowledge." Sophos X-Ops

Analyst note: this is AI-themed lure infrastructure rather than AI-enabled attack — included on the same basis as the existing Unsub1/Unsub2 – Kaspersky entries. The personas were human-operated and Sophos reports no evidence of an LLM generating the conversation. No campaign window given.

Lookalike LLM T1583 - Acquire Infrastructure

LLM-supported social engineering T1566 - Phishing

T1657 - Financial Theft

Sophos X-Ops — AI Security 2026 Jul 2026 Unknown