Google Threat Intelligence Group reported that threat actors are increasingly incorporating artificial intelligence tools into malicious operations, using them to improve phishing, social engineering, research, translation, and content generation. The activity reflects a broader shift in attacker tradecraft, with AI helping operators produce more convincing lures, refine messaging for different targets and languages, and accelerate routine tasks that support intrusion campaigns.
The report indicates that AI adoption by threat actors is advancing but remains largely focused on productivity gains rather than replacing core offensive capabilities. Attackers are using these tools to scale existing workflows and lower the effort required for reconnaissance and deception, while defenders face a growing volume of more polished malicious content and a faster operational tempo from both cybercriminal and state-linked actors.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Google Cloud published a GTIG AI Threat Tracker blog post on advances in threat actor usage of AI tools. No additional event details are available in the provided reference content.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.