Recent research and industry analysis highlight the growing influence of large language models (LLMs) in both cyber defense and cybercrime. A study from the University of Bari demonstrated that LLM-generated phishing awareness training can measurably improve users' ability to detect phishing emails, with participants showing increased recall, precision, and overall detection skill after receiving AI-tailored lessons. The research found that even simple prompting methods, which personalize training based on user profiles, were as effective as more elaborate approaches, suggesting that LLMs can efficiently enhance phishing resilience through adaptive, scalable training content.
Meanwhile, security researchers have observed that LLMs are accelerating the operational tempo of ransomware groups rather than fundamentally changing their tactics. LLMs are enabling lower-skilled threat actors to develop functional tools and infrastructure more easily, contributing to a proliferation of smaller, agile ransomware crews. These models also facilitate faster reconnaissance, phishing, and negotiation processes, and their multilingual capabilities expand the reach of cybercriminals. While LLMs have not introduced revolutionary new attack techniques, defenders should anticipate continued incremental efficiency gains among adversaries leveraging AI-driven tools.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers at the University of Bari conducted two controlled studies involving 480 participants to test whether LLM-generated phishing awareness training improves users' ability to detect phishing emails. The studies found measurable gains in recall, precision, and overall phishing detection performance, while showing that generic training performed similarly to more personalized approaches.
SentinelLABS reported that threat actors are increasingly using LLMs to speed up ransomware-related tasks such as phishing, data triage, negotiation, malware enhancement, and brand spoofing. The report said LLMs are acting as an operational accelerator rather than creating fundamentally new ransomware tactics, while contributing to a more fragmented and faster-moving extortion ecosystem.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.