Check Point Research reported that AI use in offensive cyber operations advanced from planning support to direct execution during March and April, with commercial tools such as Claude Code appearing in live criminal, ransomware, mass-exploitation, and state-linked espionage activity. The report cites persistent AI-assisted operations tied to the breach of nine Mexican government agencies and the Bissa Scanner mass-exploitation platform, and says attackers are increasingly using AI to accelerate reconnaissance, exploitation, and post-compromise actions in ways that closely resemble skilled human operators.
The report also identifies new attack surfaces and scaling effects created by enterprise AI adoption. Agentic configuration artifacts including CLAUDE.md, hooks, settings files, and MCP-related files were described as targets for jailbreaks, supply-chain compromise, and credential theft, while the EvilTokens platform was highlighted for using LLMs to automate token theft, email analysis, business email compromise, and multilingual fraud. Check Point said AI is shrinking the patch window for defenders by speeding flaw discovery and weaponization, pointing to exploitation of an LMDeploy SSRF issue within 12 hours of disclosure, while warning that existing victim-side controls remain poorly suited to detecting AI-executed intrusions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-03, Intezer published research describing five ways threat actors obtain LLM inference access, including underground offensive LLMs, crypto-funded intermediaries, leaked API keys, free-tier APIs, and exposed self-hosted servers. The report said exposed self-hosted LLM servers were the most durable abuse path and documented open instances across multiple AI platforms, including signs of active compromise on 14 LocalAI hosts.
On 2026-06-03, Anthropic published an analysis of 832 accounts banned for malicious cyber activity between March 2025 and March 2026, concluding that attackers are using AI deeper into the intrusion lifecycle, including post-compromise tasks such as account discovery and lateral movement. The report also said MITRE ATT&CK does not yet adequately capture AI-enabled behaviors like autonomous orchestration and agentic execution, and noted discussions with MITRE about evolving the framework.
An ASEC article described the evolution of AI-powered cybercrime from early malicious LLM services such as WormGPT into a broader ecosystem that included paid SaaS tools, open-source releases, local uncensored models, and AI-embedded malware such as Promptflux and Promptspy. The report said AI use had expanded beyond phishing content generation into reconnaissance, exploit validation, credential triage, attack orchestration, and malware self-modification.
On 2026-05-26, Check Point Research published a digest summarizing March–April 2026 AI-related cyber threat activity. The report concluded that agentic AI configuration files had become a persistent attack surface and that existing victim-side controls were poorly suited to detecting AI-executed operations.
In the March–April 2026 period, attackers were reported to have exploited an LMDeploy SSRF vulnerability within 12 hours of its disclosure. The case was presented as evidence that AI is compressing the time between vulnerability disclosure and weaponization.
During March–April 2026, the EvilTokens platform was described as operationalizing LLMs for token theft, email analysis, business email compromise generation, and multilingual fraud at scale. This marked a concrete example of AI-enabled phishing infrastructure being used in the wild.
During March–April 2026, the Bissa Scanner mass-exploitation platform was highlighted as another case where commercial AI tooling was used in active offensive operations. The activity illustrated AI use in scalable criminal exploitation rather than only pre-attack assistance.
During March–April 2026, attackers reportedly used the commercial AI tool Claude Code persistently in a live intrusion affecting nine Mexican government agencies. The case was cited as evidence that AI had moved from planning support into real-time operational deployment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourceitpro.com
Open sourceintezer.com
Open sourceanthropic.com
Open sourcedetect.fyi
Open sourceasec.ahnlab.com
Open sourceresearch.checkpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.