<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>AI Threat Watch: AI-Enabled</title><description>An automated watch on attackers using AI and on attacks against AI systems. Short summaries, direct links to the source.</description><link>https://ai-threat.watch/</link><language>en</language><ttl>360</ttl><item><title>Detecting and countering misuse of AI: September 2026</title><link>https://www.anthropic.com/threat-intelligence-report-september-2026</link><guid isPermaLink="false">https://ai-threat.watch/#2026-09-18-anthropic-misuse-report</guid><description>&lt;p&gt;Anthropic describes actors who automate whole intrusion chains with AI agents. One Russian-speaking espionage operator had agents rebuild malware whenever a security product detected it, and used AI to sort hundreds of gigabytes of stolen data.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Anthropic | Actors: GTG-20006, Midnight Blizzard, GTG-50014, JackPoterz | Malware: PentAGI, WPPConnect, Embassy Kit, CaptiveCrunch | Attribution: Russia, per Anthropic (confidence not stated)&lt;/p&gt;</description><pubDate>Fri, 18 Sep 2026 06:00:00 GMT</pubDate><category>AI-Enabled</category><category>Must-read</category></item><item><title>Devil’s advocate? Uncensored Luciferus AI service advertised underground</title><link>https://www.sophos.com/en-us/blog/uncensored-luciferus-ai-service-advertised-underground</link><guid isPermaLink="false">https://ai-threat.watch/#2026-09-16-sophos-devil-s-advocate-uncensored-luciferus-ai</guid><description>&lt;p&gt;Sophos CTU researchers found an underground forum persona advertising Luciferus, an uncensored AI service claiming to be a proprietary 120-billion-parameter model, though researchers assess with low confidence it is based on Qwen. The service offers tiered subscriptions and demonstrated willingness to generate malware code like a Python RAT, illustrating growing commercialization of uncensored AI in cybercrime market&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Sophos | Actors: Optimus_Prime | Malware: Luciferus, WormGPT, FraudGPT&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:59:48 GMT</pubDate><category>AI-Enabled</category></item><item><title>New packages identified in GemStuffer &apos;OpenAI Swarm&apos; malicious RubyGems campaign</title><link>https://research.jfrog.com/post/gemstuffer-openai-rubygems/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-09-15-jfrog-security-research-new-packages-identified-in-gemstuffer-op</guid><description>&lt;p&gt;JFrog identified over 3,000 malicious RubyGems packages tied to the GemStuffer campaign, some exploiting a RubyGems legacy API-key caching flaw to steal credentials and others using XSS or template-injection payloads in package metadata. Naming patterns and prior incidents link the campaign to OpenAI Swarm agents generating packages at scale, though original prompts remain unavailable.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: JFrog Security Research | Actors: OpenAI Swarm | Malware: slnleaker5, f2fe-s1, yardxabc889, southpxdatapp6pi, xss-test-gem, test-apex-gem, test-ssti-0, test-ssti-1&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:59:39 GMT</pubDate><category>AI-Enabled</category></item><item><title>Kimsuky Uses the AI Agent &apos;opencode&apos; to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve</title><link>https://www.genians.co.kr/en/blog/threat_intelligence/ai-agent-opencode</link><guid isPermaLink="false">https://ai-threat.watch/#2026-09-07-genians-kimsuky-uses-the-ai-agent-opencode-to-cr</guid><description>&lt;p&gt;Genians analyzed 13 malicious LNK files linked to Kimsuky, part of an ongoing campaign called Operation GitPower using GitHub PAT-based C2 and PowerShell loaders. Metadata in decoy PDF documents showed traces of the AI coding agent &apos;opencode&apos; and unreplaced placeholder text, indicating the actor used AI/LLMs to mass produce decoy documents without proper review.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Genians | Actors: Kimsuky&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:58:49 GMT</pubDate><category>AI-Enabled</category></item><item><title>Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America</title><link>https://origin-unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-09-03-unit-42-attackers-expose-ongoing-ai-tool-use-tar</guid><description>&lt;p&gt;Unit 42 documents two active Latin American intrusion campaigns, one against Mexican/Ecuadorian government and transportation targets and one against Brazilian financial firms, where attackers used self-hosted NextChat instances and commercial LLMs like Claude and GPT-4.1 to troubleshoot scripts and build proxy tools. Exposed staging infrastructure showed AI-generated iterative filenames and prompt history, revealing&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Unit 42 | Malware: NextChat, SockTz&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:18:58 GMT</pubDate><category>AI-Enabled</category></item><item><title>Aurora ransomware targets ESXi, abuses Cursor Agent for exploitation</title><link>https://gambit.security/blog-posts/aurora-ransomware-targets-esxi-abuses-cursor-agent-for-exploitation</link><guid isPermaLink="false">https://ai-threat.watch/#2026-08-27-gambit-security-aurora-ransomware-targets-esxi-abuses-cu</guid><description>&lt;p&gt;Gambit Security found Aurora ransomware operators using Cursor Agent with Claude Sonnet to run hands-on exploitation, including domain enumeration, NTLM relay, and certificate attacks, across ten victims. The group also deployed a new Linux ESXi ransomware variant and a separate cluster using S3 exfiltration infrastructure.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Gambit Security | Actors: Aurora | Malware: Aurora, Cursor Agent, Claude Sonnet, NetExec, Impacket, Certipy, PetitPotam, Coerce Plus&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:57:34 GMT</pubDate><category>AI-Enabled</category></item><item><title>VMs won&apos;t contain cyber-capable agents</title><link>https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyber-capable-agents/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-08-26-trail-of-bits-vms-won-t-contain-cyber-capable-agents</guid><description>&lt;p&gt;Trail of Bits tested a preview of OpenAI&apos;s GPT 5.6-Cyber agent and had it attempt to escape a QEMU/KVM sandbox. The agent autonomously escaped three times, using a recently disclosed kernel bug, an unpatched libslirp flaw, and finally a chain of several previously unknown 0-days in QEMU, KVM, and libslirp, operating for roughly 12 hours with minimal human guidance. It failed to break out of the more hardened Firecrac&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Trail of Bits | Vulnerabilities: CVE-2026-53359, CVE-2026-9539&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:57:26 GMT</pubDate><category>AI-Enabled</category></item><item><title>UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations</title><link>https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-08-20-cisco-talos-uat-10147-chinese-speaking-adversary-int</guid><description>&lt;p&gt;Cisco Talos documented a financially motivated, Chinese-speaking group, UAT-10147, using agentic AI tools like PentestGPT and DeepAudit alongside Metasploit and known CVEs to automate exploitation, reconnaissance, payload generation, and troubleshooting against Windows and Linux web servers worldwide. Talos assesses with moderate-to-high confidence this represents a shift from AI-assisted scripting to semi-autonomous&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Cisco Talos | Actors: UAT-10147 | Malware: QuasarRAT, EfsPotato, BadIIS, Gh0stCringe, SPECTRE, NoodleRAT, Meterpreter, DeepAudit | Vulnerabilities: CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, CVE-2022-0847, CVE-2022-27925, CVE-2021-23758, CVE-2021-29441, CVE-2021-29442, CVE-2019-18935 | Attribution: China, per Cisco Talos (confidence not stated)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:57:00 GMT</pubDate><category>AI-Enabled</category></item><item><title>Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM</title><link>https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm</link><guid isPermaLink="false">https://ai-threat.watch/#2026-08-10-genians-security-center-kimsuky-integrates-ai-into-attack-operat</guid><description>&lt;p&gt;Genians Security Center documented the North Korea-linked Kimsuky group using AI-generated decoy documents and experimenting with local LLM tools (Ollama, GPT4All, Msty) in an ongoing campaign dubbed Operation GitPower. The actor uses LNK files, obfuscated PowerShell, and GitHub-hosted repositories as C2 to distribute AsyncRAT payloads disguised as PNG images, targeting diplomatic, military, and virtual asset sector&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Genians Security Center | Actors: Kimsuky | Malware: AsyncRAT, FlowerPower, Operation GitPower | Attribution: North Korea, per Genians Security Center (confidence not stated)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:56:25 GMT</pubDate><category>AI-Enabled</category></item><item><title>AI Security 2026</title><link>https://assets.sophos.com/X24WTUEQ/at/2gxzgxgw5xxgtsch4cmtqwkr/sophos-ai-security-report-2026.pdf</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-22-sophos-ai-security-2026</guid><description>&lt;p&gt;Sophos&apos;s 2026 AI Security Report details a real-world case, tracked as STAC6994, where about a dozen AI agents built and tested EDR evasion malware across parallel VMs, compressing weeks of development into days, before the operator deployed ransomware and stole data. The report also covers AI supply-chain attacks, underground AI infrastructure sales, and exploit timelines outpacing patching.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Sophos | Actors: STAC6994, IRON TWILIGHT (APT28), The Gentlemen, DragonForce | Malware: LameHug, MacSync, Sliver | Vulnerabilities: CVE-2026-10520, CVE-2026-42208 | Attribution: China, per Anthropic (confidence not stated)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:55:41 GMT</pubDate><category>AI-Enabled</category></item><item><title>APT42: AI-Assisted Rapport Phishing and a More Resilient TAMECAT Backdoor</title><link>https://darkatlas.io/blog/apt42-ai-assisted-phishing-tamecat-analysis</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-19-darkatlas-apt42-ai-assisted-rapport-phishing-and-a</guid><description>&lt;p&gt;Darkatlas documents Iran-linked APT42/TA453 activity including the SpearSpecter campaign, which uses search-ms and WebDAV abuse to deliver an expanded TAMECAT backdoor with browser cookie theft and multi-channel C2 via HTTPS, Discord and Telegram. The report also describes APT42 incorporating generative AI into reconnaissance, persona and pretext creation, translation, and malware development.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Darkatlas | Actors: APT42, TA453, RedKitten | Malware: TAMECAT, SpearSpecter | Attribution: Iran, per Darkatlas (confidence not stated)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:55:17 GMT</pubDate><category>AI-Enabled</category></item><item><title>ClaudeFix: Shared Claude Chats Meet ClickFix</title><link>https://www.zscaler.com:443/blogs/security-research/claudefix-shared-claude-chats-meet-clickfix</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-15-zscaler-claudefix-shared-claude-chats-meet-click</guid><description>&lt;p&gt;Zscaler Threat Hunting found threat actors abusing shared Claude chat links, disguised with an &apos;Apple Support&apos; display name, to host ClickFix instructions that install MacSync Stealer on macOS via malvertising. The malware steals keychains, browser data, crypto wallets and files, then exfiltrates and self-deletes to avoid detection. Russian-language code comments suggest a Russian-speaking actor; the campaign ran Jun&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Zscaler | Malware: MacSync Stealer | Attribution: Russia, per Zscaler Threat Hunting (low confidence)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:54:54 GMT</pubDate><category>AI-Enabled</category></item><item><title>Suspected Chinese Operators Use Claude Code and DeepSeek to Target Government and Financial Systems Across Four Countries</title><link>https://hunt.io/blog/chinese-operators-claude-deepseek-government-intrusion</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-14-hunt-io-suspected-chinese-operators-use-claude-c</guid><description>&lt;p&gt;Hunt.io researchers found an open directory tied to TencShell C2 infrastructure showing suspected China-linked operators using Claude Code and DeepSeek-v4-pro to handle exploit reasoning, session persistence, and phishing page creation during live intrusions. Victims included government and critical infrastructure targets in Afghanistan, Thailand, and Taiwan, with reconnaissance against U.S. government portals and sc&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Hunt.io | Malware: TencShell, Vshell, ARL, DeepAudit, Gshell, HSEWH-Ur | Attribution: China, per Hunt.io (low confidence)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:54:44 GMT</pubDate><category>AI-Enabled</category></item><item><title>REF6045: Mexican banking fraud toolkit with signs of AI-assisted development</title><link>https://www.elastic.co/security-labs/threat-command/mexican-banking-fraud-scmbanker-ref6045</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-08-elastic-security-labs-ref6045-mexican-banking-fraud-toolkit-wi</guid><description>&lt;p&gt;Elastic Security Labs documented REF6045, an operator-assisted banking fraud campaign using ClickFix fake-CAPTCHA lures to install a PowerShell toolkit called SCMBANKER against Mexican bank, fintech, and crypto exchange customers. The toolkit enables session monitoring, screenshots, vishing overlays, clipboard hijacking, and RAT deployment, and its scripts show artifacts suggesting an LLM was used to write most of th&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Elastic Security Labs | Malware: SCMBANKER, Remote Utilities | Attribution: not-stated, per Elastic Security Labs (confidence not stated)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:43:43 GMT</pubDate><category>AI-Enabled</category></item><item><title>Mycelium Framework: First Ever Witnessed AI-as-a-Service Botnet</title><link>https://flare.io/learn/resources/blog/mycelium-framework-ai-as-a-service-botnet</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-07-flare-mycelium-framework-first-ever-witnessed</guid><description>&lt;p&gt;Flare researchers describe an underground forum advertisement for &apos;Mycelium Framework,&apos; a botnet claiming to classify infected machines by compute, GPU, stolen AI API keys and local models, then route AI inference, social engineering and other tasks accordingly. No source code or proof of execution was provided, and most individual techniques are previously documented, so the AI-as-a-service claims remain unverified.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Flare | Malware: Mycelium Framework, Mirai, TeamTNT, DorkBot, RageBot, Phorpiex, IRCBot.HI | Vulnerabilities: CVE-2021-22205&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:44:11 GMT</pubDate><category>AI-Enabled</category></item><item><title>JADEPUFFER: Agentic ransomware for automated database extortion</title><link>https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-01-sysdig-jadepuffer-agentic-ransomware-for-automa</guid><description>&lt;p&gt;Sysdig&apos;s Threat Research Team documented what they assess to be the first fully agentic ransomware operation, dubbed JADEPUFFER, where an LLM autonomously gained access via a Langflow RCE flaw, harvested credentials, exploited Nacos authentication bypasses, and encrypted and destroyed a victim&apos;s production database for extortion. The payloads showed self-narrating reasoning and adaptive retries with no human interven&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Sysdig | Actors: JADEPUFFER | Malware: JADEPUFFER | Vulnerabilities: CVE-2025-3248, CVE-2021-29441&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:43:36 GMT</pubDate><category>AI-Enabled</category></item><item><title>Threat Actors Weaponize AI Hype to Deliver AsyncRAT</title><link>https://www.fortinet.com/blog/threat-research/threat-actors-weaponize-ai-hype-to-deliver-asyncrat</link><guid isPermaLink="false">https://ai-threat.watch/#2026-06-11-fortiguard-labs-threat-actors-weaponize-ai-hype-to-deliv</guid><description>&lt;p&gt;FortiGuard Labs documented a multi-stage Windows malware campaign using fake AI-themed documents and guides as lures to deliver AsyncRAT via AutoHotkey-based loaders and process hollowing. Chinese-language code artifacts and structured coding style suggest the attackers used generative AI tools to help build the malware, though this is inferred rather than confirmed.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: FortiGuard Labs | Malware: AsyncRAT, AutoHotkey, clay_Client&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:42:26 GMT</pubDate><category>AI-Enabled</category></item><item><title>What we learned mapping a year&apos;s worth of AI-enabled cyber threats</title><link>https://www.anthropic.com/news/AI-enabled-cyber-threats-mitre-attack</link><guid isPermaLink="false">https://ai-threat.watch/#2026-06-03-anthropic-what-we-learned-mapping-a-year-s-worth-o</guid><description>&lt;p&gt;Anthropic analyzed 832 accounts banned for malicious cyber activity between March 2025 and March 2026, mapping their techniques to MITRE ATT&amp;amp;CK. They found AI use shifting from initial access to post-compromise activity, risk scores rising over time, and the framework failing to capture autonomous agentic orchestration seen in a November 2025 state-sponsored espionage case.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Anthropic | Malware: Claude Code&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:41:04 GMT</pubDate><category>AI-Enabled</category></item><item><title>One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign</title><link>https://www.trendmicro.com/en_us/research/26/e/inside-the-influence-and-fraud-patriot-bait-campaign.html</link><guid isPermaLink="false">https://ai-threat.watch/#2026-05-21-trend-micro-one-man-one-ai-one-fake-persona-inside-t</guid><description>&lt;p&gt;A solo Russian-speaking threat actor ran a 5-year MAGA-themed Telegram influence channel and, starting September 2025, used a jailbroken Google Gemini to automate content creation, manage infrastructure, rotate stolen API keys, and run a QAnon-styled fraud chatbot. The campaign combined credential theft, a fake crypto wallet RAT, and a token scheme, showing AI can lower the cost of running influence and fraud operati&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Trend Micro | Actors: bandcampro | Malware: GoToResolve, StellarMonster, Quantum Patriot, QFS 2.0 Terminal | Attribution: Russia, per Trend Micro (medium confidence)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:16:56 GMT</pubDate><category>AI-Enabled</category></item><item><title>GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access</title><link>https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access</link><guid isPermaLink="false">https://ai-threat.watch/#2026-05-12-gtig-ai-threat-tracker</guid><description>&lt;p&gt;GTIG reports adversaries applying AI to vulnerability exploitation, initial access and faster development of evasive, polymorphic malware. It also covers supply chain attacks against AI components, and notes no actor has yet bypassed the core safety logic of frontier models.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Google Threat Intelligence Group&lt;/p&gt;</description><pubDate>Tue, 12 May 2026 06:00:00 GMT</pubDate><category>AI-Enabled</category><category>Must-read</category></item><item><title>Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America</title><link>https://www.trendmicro.com/en_us/research/26/e/vibe-hacking-two-ai-augmented-campaigns-target-government-and-financial-sectors-in-latin-america.html</link><guid isPermaLink="false">https://ai-threat.watch/#2026-05-11-trend-micro-vibe-hacking-two-ai-augmented-campaigns</guid><description>&lt;p&gt;Trend Micro identified two campaigns, SHADOW-AETHER-040 and SHADOW-AETHER-064, using agentic AI (including Claude) to drive intrusions from initial access to data exfiltration against government and financial targets in Mexico and Brazil. The AI agents dynamically generated custom tools and backdoors, used jailbreaking via fake red-team pretexts, and integrated with Shodan and VulDB for reconnaissance.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Trend Micro | Actors: SHADOW-AETHER-040, SHADOW-AETHER-064 | Malware: Chisel, Neo-reGeorg, CrackMapExec, Impacket, implante_http, ProxyChains, PetitPotam&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:40:31 GMT</pubDate><category>AI-Enabled</category></item><item><title>AI Meets Voice Phishing: How ATHR Automates the Full TOAD Attack Chain</title><link>https://abnormal.ai/blog/athr-ai-voice-phishing-toad-attacks</link><guid isPermaLink="false">https://ai-threat.watch/#2026-04-22-abnormal-ai-ai-meets-voice-phishing-how-athr-automat</guid><description>&lt;p&gt;Researchers describe ATHR, a crimeware platform sold for $4,000 plus 10% of profits that combines AI voice agents, spoofed lure emails, and live phishing panels to automate telephone-oriented attack delivery (TOAD) scams. Its AI vishing agents run scripted social engineering calls targeting crypto and email brand users, letting one operator run multi-brand campaigns without trained callers.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Abnormal AI | Malware: ATHR&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:16:32 GMT</pubDate><category>AI-Enabled</category></item><item><title>A Single Operator, Two AI Platforms, Nine Government Agencies: The Full Technical Report</title><link>https://gambit.security/blog-posts/a-single-operator-two-ai-platforms-nine-government-agencies-the-full-technical-report</link><guid isPermaLink="false">https://ai-threat.watch/#2026-04-10-gambit-security-a-single-operator-two-ai-platforms-nine</guid><description>&lt;p&gt;Gambit Security&apos;s forensic report describes a single operator who used Claude Code and OpenAI&apos;s GPT-4.1 as core operational tools to breach nine Mexican government organizations and exfiltrate hundreds of millions of records between December 2025 and February 2026. Recovered materials show over 400 custom attack scripts, 20 tailored exploits, and thousands of AI-generated commands used to compress attack timelines an&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Gambit Security | Attribution: Mexico, per Gambit Security (confidence not stated)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:40:23 GMT</pubDate><category>AI-Enabled</category></item><item><title>A Slopoly start to AI-enhanced ransomware attacks</title><link>https://www.ibm.com/think/x-force/slopoly-start-ai-enhanced-ransomware-attacks</link><guid isPermaLink="false">https://ai-threat.watch/#2026-03-12-ibm-x-force-a-slopoly-start-to-ai-enhanced-ransomwar</guid><description>&lt;p&gt;IBM X-Force found a likely AI-generated PowerShell C2 backdoor, dubbed Slopoly, deployed by ransomware group Hive0163 during a live intrusion using ClickFix, NodeSnake, InterlockRAT and Interlock ransomware. The malware is technically unremarkable but shows guardrail bypass and signals adoption of AI-assisted malware development among established ransomware actors.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: IBM X-Force | Actors: Hive0163, ITG23, TA569, TAG-124 | Malware: Slopoly, NodeSnake, InterlockRAT, Interlock, JunkFiction, Broomstick, Supper, PortStarter&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:40:16 GMT</pubDate><category>AI-Enabled</category></item><item><title>Fake VCs target crypto talent in a new ClickFix campaign</title><link>https://moonlock.com/fake-vcs-target-crypto-talent-clickfix-campaign</link><guid isPermaLink="false">https://ai-threat.watch/#2026-03-02-moonlock-lab-fake-vcs-target-crypto-talent-in-a-new-c</guid><description>&lt;p&gt;Moonlock Lab documented a campaign using fake venture capital personas on LinkedIn to lure crypto professionals into spoofed Zoom/Meet pages running a ClickFix fake CAPTCHA that tricks victims into executing clipboard-injected commands, deploying cross-platform malware. Fake company sites used AI-generated headshots for fabricated staff, and infrastructure overlaps with DPRK-linked UNC1069, though attribution remains&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Moonlock Lab | Actors: Mykhailo Hureiev, Anatolli Bigdasch, UNC1069 | Attribution: North Korea, per Moonlock Lab (low confidence)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:14:58 GMT</pubDate><category>AI-Enabled</category></item><item><title>Disrupting malicious uses of AI</title><link>https://openai.com/index/disrupting-malicious-ai-uses/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-02-25-openai-disrupting-malicious-uses</guid><description>&lt;p&gt;OpenAI&apos;s case studies show models used as one step in larger workflows that also rely on websites and social accounts: romance and recovery scams, covert influence operations, and a state-linked harassment effort.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: OpenAI | Actors: Rybar&lt;/p&gt;</description><pubDate>Wed, 25 Feb 2026 06:00:00 GMT</pubDate><category>AI-Enabled</category><category>Must-read</category></item><item><title>LLMs in the Kill Chain: Inside a Custom MCP Targeting FortiGate Devices Across Continents</title><link>https://cyberandramen.net/2026/02/21/llms-in-the-kill-chain-inside-a-custom-mcp-targeting-fortigate-devices-across-continents/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-02-21-hunt-io-cyberandramen-ne-llms-in-the-kill-chain-inside-a-custom-m</guid><description>&lt;p&gt;Researchers found an exposed server revealing a threat actor using a custom MCP server (ARXON) with DeepSeek and Claude Code to automate reconnaissance, attack planning, and exploitation of compromised FortiGate devices across thousands of targets in over 100 countries. The actor evolved from using open-source HexStrike MCP tooling in December 2025 to fully custom orchestration (ARXON and CHECKER2) by February 2026,&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Hunt.io / cyberandramen.net | Malware: ARXON, CHECKER2, HexStrike, ntlmrelayx.py, Impacket, Metasploit, BloodHound, Nuclei | Vulnerabilities: CVE-2019-6693, CVE-2026-24061, CVE-2025-33073, CVE-2023-27532, CVE-2019-7192&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:39:34 GMT</pubDate><category>AI-Enabled</category></item><item><title>AI-augmented threat actor accesses FortiGate devices at scale</title><link>https://aws.amazon.com/blogs/security/ai-augmented-threat-actor-accesses-fortigate-devices-at-scale/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-02-20-amazon-threat-intelligen-ai-augmented-threat-actor-accesses-forti</guid><description>&lt;p&gt;Amazon Threat Intelligence documented a Russian-speaking, financially motivated actor using multiple commercial LLMs to compromise over 600 FortiGate devices in 55+ countries via exposed management interfaces and weak credentials, not exploits. AI generated attack plans, custom Go/Python tooling, and reconnaissance scripts, letting a low-skill actor achieve broad operational scale, though it still failed against hard&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Amazon Threat Intelligence | Actors: Ed1s0nZ | Malware: Meterpreter, mimikatz, gogo, Nuclei, CyberStrikeAI, PrivHunterAI, InfiltrateX, watermark-tool | Vulnerabilities: CVE-2019-7192, CVE-2023-27532, CVE-2024-40711&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:39:05 GMT</pubDate><category>AI-Enabled</category></item><item><title>PromptSpy ushers in the era of Android threats using GenAI</title><link>https://www.welivesecurity.com/en/eset-research/promptspy-ushers-in-era-android-threats-using-genai/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-02-19-eset-research-promptspy-ushers-in-the-era-of-android-t</guid><description>&lt;p&gt;ESET found PromptSpy, Android malware that queries Google&apos;s Gemini with UI XML dumps to get step-by-step instructions for locking itself into the recent apps list, aiding persistence. The malware also deploys a VNC module for remote device control and targets users in Argentina; no live samples have been seen in telemetry, suggesting it may still be a proof of concept.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: ESET Research | Malware: PromptSpy, VNCSpy, PromptLock, Android.Phantom, Android/Phishing.Agent.M | Attribution: China, per ESET (medium confidence)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:39:17 GMT</pubDate><category>AI-Enabled</category></item><item><title>GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use</title><link>https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use</link><guid isPermaLink="false">https://ai-threat.watch/#2026-02-12-gtig-distillation-experimentation</guid><description>&lt;p&gt;Quarterly view of how actors linked to North Korea, Iran, China and Russia used AI in late 2025. GTIG saw no breakthrough capability, but disrupted frequent model extraction attempts against its own models.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Google Threat Intelligence Group | Attribution: North Korea, per Google Threat Intelligence Group (confidence not stated); Iran, per Google Threat Intelligence Group (confidence not stated); China, per Google Threat Intelligence Group (confidence not stated); Russia, per Google Threat Intelligence Group (confidence not stated)&lt;/p&gt;</description><pubDate>Thu, 12 Feb 2026 06:00:00 GMT</pubDate><category>AI-Enabled</category><category>Must-read</category></item><item><title>The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time</title><link>https://unit42.paloaltonetworks.com/real-time-malicious-javascript-through-llms/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-01-22-unit-42-palo-alto-networ-the-next-frontier-of-runtime-assembly-at</guid><description>&lt;p&gt;Unit 42 researchers built a proof of concept where a benign-looking webpage queries trusted LLM APIs like DeepSeek and Gemini at runtime to generate and assemble phishing JavaScript in the victim&apos;s browser, bypassing network detection and guardrails through prompt engineering. This produces polymorphic, brand-impersonating phishing pages with no static malicious payload, though the technique was not observed used by&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Unit 42 (Palo Alto Networks) | Malware: LogoKit&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:14:32 GMT</pubDate><category>AI-Enabled</category></item><item><title>AI-Poisoning &amp; AMOS Stealer: The Biggest Mac Threat</title><link>https://www.huntress.com/blog/amos-stealer-chatgpt-grok-ai-trust</link><guid isPermaLink="false">https://ai-threat.watch/#2025-12-10-huntress-ai-poisoning-amos-stealer-the-biggest-ma</guid><description>&lt;p&gt;Huntress found that attackers used SEO poisoning to push fake ChatGPT and Grok shared conversations, hosted on legitimate OpenAI and xAI domains, to the top of Google results for common Mac troubleshooting queries. Victims who followed the AI-generated Terminal instructions were infected with an AMOS stealer variant that harvests credentials, escalates to root, and persists via a LaunchDaemon watchdog.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Huntress | Malware: AMOS, Atomic macOS Stealer&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:14:12 GMT</pubDate><category>AI-Enabled</category></item><item><title>The Dual-Use Dilemma of AI: Malicious LLMs</title><link>https://unit42.paloaltonetworks.com/dilemma-of-ai-malicious-llms/</link><guid isPermaLink="false">https://ai-threat.watch/#2025-11-25-unit-42-the-dual-use-dilemma-of-ai-malicious-llm</guid><description>&lt;p&gt;Unit 42 examines two commercialized malicious LLMs, WormGPT and KawaiiGPT, sold or freely distributed to cybercriminals for generating phishing, BEC lures, ransomware code and ransom notes. Testing showed WormGPT 4 producing functional PowerShell ransomware scripts and KawaiiGPT crafting convincing spear-phishing content, lowering technical barriers for less-skilled attackers.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Unit 42 | Malware: WormGPT, WormGPT 4, KawaiiGPT&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:13:54 GMT</pubDate><category>AI-Enabled</category></item><item><title>The Future of Malware is LLM-powered</title><link>https://www.netskope.com/blog/the-future-of-malware-is-llm-powered</link><guid isPermaLink="false">https://ai-threat.watch/#2025-11-20-netskope-the-future-of-malware-is-llm-powered</guid><description>&lt;p&gt;Netskope Threat Labs tested whether GPT-3.5-Turbo, GPT-4 and preliminary GPT-5 could be prompted or jailbroken into generating malicious code for process injection and VM detection. They found guardrails could be bypassed with role-based prompt injection but generated code was often unreliable, especially against cloud VDI, though GPT-5 showed marked improvement. This is proof-of-concept research, not an observed rea&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Netskope&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:13:45 GMT</pubDate><category>AI-Enabled</category></item><item><title>Disrupting the first reported AI-orchestrated cyber espionage campaign</title><link>https://assets.anthropic.com/m/ec212e6566a0d47/original/Disrupting-the-first-reported-AI-orchestrated-cyber-espionage-campaign.pdf</link><guid isPermaLink="false">https://ai-threat.watch/#2025-11-13-anthropic-gtg-1002</guid><description>&lt;p&gt;A group tasked Claude Code with running intrusions against roughly 30 organisations, with the model carrying out an estimated 80 to 90 percent of tactical work. Anthropic validated a handful of successful compromises before banning the accounts.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Anthropic | Actors: GTG-1002, Chinese state-sponsored group | Malware: Claude Code | Attribution: China, per Anthropic (high confidence)&lt;/p&gt;</description><pubDate>Thu, 13 Nov 2025 06:00:00 GMT</pubDate><category>AI-Enabled</category><category>Must-read</category></item><item><title>GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools</title><link>https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools</link><guid isPermaLink="false">https://ai-threat.watch/#2025-11-05-gtig-advances-ai-tools</guid><description>&lt;p&gt;GTIG documents the first malware families that query an LLM during execution to generate scripts and rewrite their own code. It also describes actors posing as students or researchers to talk Gemini past its safeguards.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Google Threat Intelligence Group | Actors: APT28 | Malware: PROMPTFLUX, PROMPTSTEAL&lt;/p&gt;</description><pubDate>Wed, 05 Nov 2025 06:00:00 GMT</pubDate><category>AI-Enabled</category><category>Must-read</category></item><item><title>APT Meets GPT: Targeted Operations with Untamed LLMs</title><link>https://www.volexity.com/blog/2025/10/08/apt-meets-gpt-targeted-operations-with-untamed-llms/</link><guid isPermaLink="false">https://ai-threat.watch/#2025-10-08-volexity-apt-meets-gpt-targeted-operations-with-u</guid><description>&lt;p&gt;Volexity documents UTA0388, a China-aligned actor running spear phishing campaigns since June 2025 that deploy the GOVERSHELL backdoor via search order hijacking. Volexity assesses with high confidence the group used LLMs, later confirmed by OpenAI, to assist phishing content and malware development, and links the group to Proofpoint&apos;s previously reported UNK_DropPitch/HealthKick activity.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Volexity | Actors: UTA0388, UNK_DropPitch | Malware: GOVERSHELL, HealthKick, Tablacus Explorer | Attribution: China, per Volexity (high confidence)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:13:23 GMT</pubDate><category>AI-Enabled</category></item><item><title>Disrupting malicious uses of AI: October 2025</title><link>https://openai.com/global-affairs/disrupting-malicious-uses-of-ai-october-2025/</link><guid isPermaLink="false">https://ai-threat.watch/#2025-10-07-openai-october-report</guid><description>&lt;p&gt;OpenAI details banned accounts tied to state actors and criminal groups that used ChatGPT for malware development, scams and surveillance tooling. It reports no evidence that its models gave attackers novel offensive capability.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: OpenAI | Actors: Russian-speaking criminal groups, North Korean (DPRK) actors | Malware: XenoRAT&lt;/p&gt;</description><pubDate>Tue, 07 Oct 2025 06:00:00 GMT</pubDate><category>AI-Enabled</category></item><item><title>DeceptiveDevelopment: From primitive crypto theft to sophisticated AI-based deception</title><link>https://www.welivesecurity.com/en/eset-research/deceptivedevelopment-from-primitive-crypto-theft-to-sophisticated-ai-based-deception/</link><guid isPermaLink="false">https://ai-threat.watch/#2025-09-29-eset-research-deceptivedevelopment-from-primitive-cryp</guid><description>&lt;p&gt;ESET details DeceptiveDevelopment, a North Korea-aligned group using fake recruiter profiles and ClickFix social engineering to deliver malware like BeaverTail, InvisibleFerret, OtterCookie, WeaselStore and TsunamiKit to job-seeking developers across Windows, Linux and macOS. The group is closely linked to North Korean IT worker campaigns (WageMole) that use AI-driven tools to fabricate synthetic identities to secure&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: ESET Research | Actors: DeceptiveDevelopment, WageMole, Contagious Interview, DEV#POPPER, Void Dokkaebi, Lazarus | Malware: BeaverTail, InvisibleFerret, OtterCookie, WeaselStore, GolangGhost, FlexibleFerret, PylangGhost, TsunamiKit | Attribution: North Korea, per ESET Research (high confidence)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:13:05 GMT</pubDate><category>AI-Enabled</category></item><item><title>SentinelOne finds MalTerminal malware using OpenAI GPT-4</title><link>https://dataconomy.com/2025/09/23/sentinelone-finds-malterminal-malware-using-openai-gpt-4/</link><guid isPermaLink="false">https://ai-threat.watch/#2025-09-23-dataconomy-malterminal</guid><description>&lt;p&gt;SentinelLABS hunted for binaries carrying LLM API keys and embedded prompts, and found MalTerminal, which asks GPT-4 to write ransomware or a reverse shell at runtime. A retired API endpoint dates it before November 2023. No live use is known.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Dataconomy | Malware: MalTerminal&lt;/p&gt;</description><pubDate>Tue, 23 Sep 2025 06:00:00 GMT</pubDate><category>AI-Enabled</category></item><item><title>AI-Driven Deepfake-Based Military ID Forgery APT Campaign</title><link>https://www.genians.co.kr/en/blog/threat_intelligence/deepfake</link><guid isPermaLink="false">https://ai-threat.watch/#2025-09-16-genians-ai-driven-deepfake-based-military-id-for</guid><description>&lt;p&gt;Genians Security Center documented a July 2025 spear-phishing campaign impersonating a South Korean military ID office, where the attacker used ChatGPT to generate a fake military employee ID image, verified via metadata and deepfake detection tools. The email delivered obfuscated LNK and batch scripts leading to an AutoIt-based backdoor for persistence and C2 communication.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Genians | Malware: AutoIt3, config.bin, HncUpdateTray.exe&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:12:41 GMT</pubDate><category>AI-Enabled</category></item><item><title>A new RevengeHotels campaign targets Latin America</title><link>https://securelist.com/revengehotels-attacks-with-ai-and-venomrat-across-latin-america/117493/</link><guid isPermaLink="false">https://ai-threat.watch/#2025-09-16-securelist-a-new-revengehotels-campaign-targets-lat</guid><description>&lt;p&gt;Kaspersky reports that RevengeHotels (TA558), a hotel-targeting phishing group, now uses LLM-generated code in its JavaScript loaders and PowerShell downloaders to deliver VenomRAT. The campaign targets Brazilian and Spanish-speaking hotels via invoice-themed phishing emails, showing how a known criminal group is adopting AI to build malware components.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Securelist | Actors: RevengeHotels, TA558 | Malware: VenomRAT, QuasarRAT, RevengeRAT, NanoCoreRAT, NjRAT, 888 RAT, ProCC, XWorm | Vulnerabilities: CVE-2017-0199&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:12:50 GMT</pubDate><category>AI-Enabled</category></item><item><title>Threat Intelligence Report: August 2025</title><link>https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf</link><guid isPermaLink="false">https://ai-threat.watch/#2025-08-27-anthropic-threat-intel-august</guid><description>&lt;p&gt;Introduces vibe hacking: one criminal used Claude Code to run data extortion against at least 17 organisations. Other cases cover North Korean remote worker fraud, ransomware sold by a developer with little coding skill, and AI across the fraud ecosystem.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Anthropic | Actors: North Korean IT workers | Malware: Claude Code, Claude | Attribution: North Korea, per Anthropic (confidence not stated); China, per Anthropic (confidence not stated)&lt;/p&gt;</description><pubDate>Wed, 27 Aug 2025 06:00:00 GMT</pubDate><category>AI-Enabled</category><category>Must-read</category></item><item><title>First known AI-powered ransomware uncovered by ESET Research</title><link>https://welivesecurity.com/en/ransomware/first-known-ai-powered-ransomware-uncovered-eset-research</link><guid isPermaLink="false">https://ai-threat.watch/#2025-08-26-eset-promptlock</guid><description>&lt;p&gt;PromptLock runs OpenAI&apos;s gpt-oss-20b locally through Ollama to generate Lua scripts that enumerate, exfiltrate and encrypt files. ESET later confirmed the samples match an academic prototype, not malware deployed in attacks.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: ESET Research | Malware: PromptLock&lt;/p&gt;</description><pubDate>Tue, 26 Aug 2025 06:00:00 GMT</pubDate><category>AI-Enabled</category></item><item><title>Phishing and scams: how fraudsters are deceiving users in 2025</title><link>https://securelist.com/new-phishing-and-scam-trends-in-2025/117217/</link><guid isPermaLink="false">https://ai-threat.watch/#2025-08-13-securelist-phishing-and-scams-how-fraudsters-are-de</guid><description>&lt;p&gt;Kaspersky researchers describe how scammers now use AI tools such as DeepSeek to write convincing phishing text, AI-generated voices and deepfakes for fake celebrity giveaways and bank impersonation calls, and OSINT AI tools to personalize attacks. The report also covers new evasion techniques like blob URLs, Google Translate proxying, and Telegram bot abuse, and a shift toward stealing biometric and signature data.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Securelist | Malware: DeepSeek&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:11:40 GMT</pubDate><category>AI-Enabled</category></item><item><title>LAMEHUG: APT28&apos;s New Arsenal - First AI-Powered Malware Explained</title><link>https://guardsix.com/blog/apt28s-new-arsenal-lamehug-the-first-ai-powered-malware</link><guid isPermaLink="false">https://ai-threat.watch/#2025-07-18-thn-lamehug</guid><description>&lt;p&gt;CERT-UA reported that APT28 (UAC-0001) used LameHug, a Python malware delivered via phishing that queries the Qwen 2.5-Coder-32B-Instruct model through the Hugging Face API to generate Windows recon and exfiltration commands. This is described as one of the first publicly documented cases of malware using an LLM to dynamically generate attack commands against Ukrainian defense sector targets. Guardsix summarizes the&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: guardsix | Actors: APT28, UAC-0001, Forest Blizzard | Malware: LAMEHUG, LameHug, AI_generator_uncensored_Canvas_PRO_v0.9.exe, image.py | Attribution: Russia, per CERT-UA (medium confidence)&lt;/p&gt;</description><pubDate>Fri, 18 Jul 2025 06:00:00 GMT</pubDate><category>AI-Enabled</category></item><item><title>Cybercriminal abuse of large language models</title><link>https://blog.talosintelligence.com/cybercriminal-abuse-of-large-language-models/</link><guid isPermaLink="false">https://ai-threat.watch/#2025-06-25-cisco-talos-cybercriminal-abuse-of-large-language-mo</guid><description>&lt;p&gt;Talos researchers document cybercriminals using uncensored LLMs, custom criminal LLMs like FraudGPT and WormGPT, and jailbreak techniques to write malware, phishing content and scan for vulnerabilities. The report also covers attacks against LLMs themselves, including pickle-based backdoored models on Hugging Face and RAG poisoning risks. Talos found that FraudGPT&apos;s seller was actually running a cryptocurrency scam r&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Cisco Talos | Actors: CanadianKingpin12 | Malware: GhostGPT, WormGPT, DarkGPT, DarkestGPT, FraudGPT, WhiteRabbitNeo, Llama 2 Uncensored, OnionGPT&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:11:02 GMT</pubDate><category>AI-Enabled</category></item><item><title>Black Hat SEO Poisoning Search Engine Results For AI to Distribute Malware</title><link>https://www.zscaler.com:443/blogs/security-research/black-hat-seo-poisoning-search-engine-results-ai-distribute-malware</link><guid isPermaLink="false">https://ai-threat.watch/#2025-06-24-zscaler-threatlabz-black-hat-seo-poisoning-search-engine-re</guid><description>&lt;p&gt;Zscaler researchers found threat actors using Black Hat SEO to rank fake AI-themed websites (mimicking tools like ChatGPT and Luma AI) highly in search results. Victims who click through are fingerprinted and redirected through multiple layers to download malware including Vidar, Lumma Stealer and Legion Loader, often bundled in oversized installers to evade sandboxes.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Zscaler ThreatLabz | Malware: Vidar, Lumma, Legion Loader, Legion Loader&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:11:17 GMT</pubDate><category>AI-Enabled</category></item><item><title>Storm-1516 Deploys AI-Generated Media to Spread Disinformation: Targets European Leaders and Influences Istanbul Peace Talks</title><link>https://blog.eclecticiq.com/storm-1516-deploys-ai-generated-media-to-spread-disinformation-targets-european-leaders-and-influence-istanbul-peace-talks</link><guid isPermaLink="false">https://ai-threat.watch/#2025-05-14-eclecticiq-storm-1516-deploys-ai-generated-media-to</guid><description>&lt;p&gt;EclecticIQ documents pro-Kremlin group Storm-1516 using AI-generated images and videos to falsely accuse Macron, Starmer, Merz and Zelensky of cocaine use, aiming to undermine European unity ahead of Istanbul peace talks. The campaign was amplified by Storm-1516-linked X accounts and Russian MFA official Maria Zakharova, and relied on generative AI to fabricate visuals rapidly for viral spread.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: EclecticIQ | Actors: Storm-1516 | Attribution: Russia, per EclecticIQ (high confidence)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:10:52 GMT</pubDate><category>AI-Enabled</category></item><item><title>False Face: Unit 42 Demonstrates the Alarming Ease of Synthetic Identity Creation</title><link>https://unit42.paloaltonetworks.com/north-korean-synthetic-identity-creation/</link><guid isPermaLink="false">https://ai-threat.watch/#2025-04-21-unit-42-palo-alto-networ-false-face-unit-42-demonstrates-the-alar</guid><description>&lt;p&gt;Unit 42 shows that North Korean IT worker operatives are using real-time deepfake tools during job interviews to create synthetic identities and evade detection. A researcher with no prior experience built a passable real-time deepfake in about 70 minutes using cheap hardware and free tools, illustrating low barriers to this technique. The report also outlines technical artifacts and HR/security mitigations to detect&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Unit 42, Palo Alto Networks | Actors: North Korean IT workers, DPRK | Malware: Wagemole, BeaverTail, InvisibleFerret | Attribution: North Korea, per Unit 42, Palo Alto Networks (high confidence)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:10:46 GMT</pubDate><category>AI-Enabled</category></item><item><title>Operating Multi-Client Influence Networks Across Platforms</title><link>https://cdn.sanity.io/files/4zrzovbb/website/45bc6adf039848841ed9e47051fb1209d6bb2b26.pdf</link><guid isPermaLink="false">https://ai-threat.watch/#2025-04-01-anthropic-operating-multi-client-influence-network</guid><description>&lt;p&gt;Anthropic disrupted an influence-as-a-service operation that used Claude to manage over 100 social media personas across X and Facebook, making tactical decisions on engagement and generating image prompts. The operation served at least four distinct clients pushing narratives on European, Iranian, UAE, and Kenyan interests, prioritizing persistence and relationship-building over viral spread. No nation-state attribu&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Anthropic | Malware: Claude&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:37:33 GMT</pubDate><category>AI-Enabled</category></item><item><title>How GhostGPT Empowers Cybercriminals with Uncensored AI</title><link>https://abnormal.ai/blog/ghostgpt-uncensored-ai-chatbot</link><guid isPermaLink="false">https://ai-threat.watch/#2025-01-30-abnormal-ai-how-ghostgpt-empowers-cybercriminals-wit</guid><description>&lt;p&gt;Abnormal Security researchers identified GhostGPT, an uncensored chatbot sold via Telegram that likely wraps a jailbroken ChatGPT or open-source LLM to remove safety guardrails. It is marketed to generate phishing emails, BEC templates, malware code and exploits, lowering the skill barrier for cybercriminals. Researchers tested it by having it produce a convincing Docusign phishing email template.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Abnormal AI | Malware: GhostGPT, WormGPT, WolfGPT, EscapeGPT&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:10:12 GMT</pubDate><category>AI-Enabled</category></item><item><title>Adversarial Misuse of Generative AI</title><link>https://cloud.google.com/blog/topics/threat-intelligence/adversarial-misuse-generative-ai</link><guid isPermaLink="false">https://ai-threat.watch/#2025-01-29-gtig-adversarial-misuse</guid><description>&lt;p&gt;GTIG&apos;s first analysis of how government-backed groups used Gemini. Actors from Iran, China, North Korea and Russia used it for research, coding help and content, and did not develop novel capabilities with it.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Google Threat Intelligence Group | Actors: APT43 | Attribution: Iran, per Google Threat Intelligence Group (confidence not stated); China, per Google Threat Intelligence Group (confidence not stated); North Korea, per Google Threat Intelligence Group (confidence not stated); Russia, per Google Threat Intelligence Group (confidence not stated)&lt;/p&gt;</description><pubDate>Wed, 29 Jan 2025 06:00:00 GMT</pubDate><category>AI-Enabled</category><category>Must-read</category></item><item><title>Jailbreaking Social Engineering via Adversarial Digital Twins</title><link>https://www.knostic.ai/blog/jailbreaking-social-engineering-via-adversarial-digital-twins</link><guid isPermaLink="false">https://ai-threat.watch/#2024-09-23-knostic-jailbreaking-social-engineering-via-adve</guid><description>&lt;p&gt;Knostic researchers describe a proof-of-concept red team method using an LLM to build a psychological profile and a fake persona (&apos;Adversarial Digital Twin&apos;) from a target&apos;s social media data, then jailbreak the LLM&apos;s guardrails to generate rapport-building conversations for social engineering. The technique was demonstrated in a controlled exercise, not observed in the wild, but shows how LLMs could lower the skill&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Knostic | Malware: Dark Gemini, Maltego&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:09:07 GMT</pubDate><category>AI-Enabled</category></item><item><title>The Emerging Dynamics of Deepfake Scam Campaigns on the Web</title><link>https://unit42.paloaltonetworks.com/dynamics-of-deepfake-scams/</link><guid isPermaLink="false">https://ai-threat.watch/#2024-08-29-unit-42-the-emerging-dynamics-of-deepfake-scam-c</guid><description>&lt;p&gt;Unit 42 researchers identified a large network of scam websites using deepfake videos of public figures like Elon Musk and various world leaders to promote fake investment schemes and government giveaways across multiple languages and countries. Infrastructure analysis of hundreds of domains, averaging 114,000 visits each, suggests a single threat actor group behind these long-running campaigns.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Unit 42 | Malware: Quantum AI&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:08:35 GMT</pubDate><category>AI-Enabled</category></item><item><title>Black Basta and the Use of LLMs by Threat Actors</title><link>https://thecyberwire.com/podcasts/microsoft-threat-intelligence/26/transcript</link><guid isPermaLink="false">https://ai-threat.watch/#2024-08-28-the-cyberwire-black-basta-and-the-use-of-llms-by-threa</guid><description>&lt;p&gt;Microsoft researchers describe Black Basta&apos;s shifting initial access techniques across several malware loaders, then discuss how state-sponsored actors used LLMs via OpenAI accounts. Microsoft and OpenAI disrupted five state-affiliated accounts used for tasks like translation, coding help, and open-source research, consistent with actors&apos; existing goals rather than new capabilities.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: The CyberWire | Actors: Black Basta, Storm-506, Storm-1811, Storm-464, Storm-450, Forest Blizzard, Emerald Sleet, Strawberry Tempest | Malware: Qakbot, Pikabot, DarkGate, IcedID, TeamsPhisher, BatLoader, ZLoader, Cobalt Strike | Attribution: Russia, per Microsoft (confidence not stated); North Korea, per Microsoft (confidence not stated)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:08:57 GMT</pubDate><category>AI-Enabled</category></item><item><title>Social Media Malvertising Campaign Promotes Fake AI Editor Website for Credential Theft</title><link>https://www.trendmicro.com/en_us/research/24/h/malvertising-campaign-fake-ai-editor-website-credential-theft.html</link><guid isPermaLink="false">https://ai-threat.watch/#2024-08-01-trend-micro-social-media-malvertising-campaign-promo</guid><description>&lt;p&gt;Trend Micro documented a malvertising campaign that hijacks Facebook pages, rebrands them as the AI photo editor Evoto, and lures victims to download a disguised ITarian RMM installer. Once enrolled, the tool downloads Lumma Stealer and disables Windows Defender scanning to exfiltrate credentials, wallets and browser data. AI branding is used purely as a lure, not as an offensive capability.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Trend Micro | Malware: Lumma Stealer, PackLab Crypter, ITarian&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:08:10 GMT</pubDate><category>AI-Enabled</category></item><item><title>AI-Powered Deepfake Tools Becoming More Accessible Than Ever</title><link>https://www.trendmicro.com/en_us/research/24/g/ai-deepfake-cybercrime.html</link><guid isPermaLink="false">https://ai-threat.watch/#2024-07-30-trend-micro-ai-powered-deepfake-tools-becoming-more</guid><description>&lt;p&gt;Trend Micro research documents new cybercrime underground tools including deepfake generators (DeepNude Pro, SwapFace, VideoCallSpoofer) and re-emerging malicious LLM services like WormGPT and DarkBERT with added multimodal capabilities. Many advertised jailbreak LLM services are actually thin wrappers around commercial models, and adoption of these tools by criminals remains relatively slow.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Trend Micro | Malware: DeepNude Pro, Deepfake 3D Pro, Deepfake AI, SwapFace, VideoCallSpoofer, WormGPT, DarkBERT, DarkGemini&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:08:01 GMT</pubDate><category>AI-Enabled</category></item><item><title>Whose Voice Is It Anyway? AI-Powered Voice Spoofing for Next-Gen Vishing Attacks</title><link>https://cloud.google.com/blog/topics/threat-intelligence/ai-powered-voice-spoofing-vishing-attacks</link><guid isPermaLink="false">https://ai-threat.watch/#2024-07-23-mandiant-whose-voice-is-it-anyway-ai-powered-voic</guid><description>&lt;p&gt;Mandiant describes how attackers use AI voice cloning for vishing, including a red team case study where a cloned executive voice tricked an employee into bypassing security warnings and executing malware. It also cites a reported HK$200 million deepfake scam and offers mitigation guidance like code words and source verification.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Mandiant&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:07:53 GMT</pubDate><category>AI-Enabled</category></item><item><title>State-Sponsored Russian Media Leverages Meliorator Software for Foreign Malign Influence Activity</title><link>https://www.ic3.gov/CSA/2024/240709.pdf</link><guid isPermaLink="false">https://ai-threat.watch/#2024-07-09-fbi-state-sponsored-russian-media-leverages</guid><description>&lt;p&gt;FBI, CNMF, and allied agencies detail Meliorator, an AI-enhanced tool used by RT affiliates to mass-create fake social media personas that spread Russian disinformation on X. The software auto-generates biographical data and AI profile photos, bypasses two-factor authentication, and obfuscates IP addresses to evade detection.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: FBI | Actors: RT | Malware: Meliorator, Brigadir, Taras, Faker | Attribution: Russia, per FBI, CNMF, AIVD, MIVD, DNP, CCCS (high confidence)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:58:33 GMT</pubDate><category>AI-Enabled</category></item></channel></rss>