Palo Alto Networks' Unit 42 reported that artificial intelligence is currently serving mainly as a force multiplier for attackers, speeding up and scaling established intrusion workflows rather than introducing entirely new attack methods. Drawing on incident response investigations, the report said threat actors still rely on familiar tactics including credential theft, phishing, exploitation of known vulnerabilities, and ransomware, while using AI to accelerate malware development, automate content generation, and streamline reconnaissance.
Unit 42 leaders Andy Piazza and Richard Emerson said AI-enabled attacks have not yet required enterprises to redesign core defense strategies, but warned that broader attacker adoption could strain detect-and-respond operations and raise the value of prevention-focused controls. The report also pointed to emerging activity including AI-assisted malware, malware that queries LLM or MCP servers for command-and-control guidance, agentic ransomware, and token jacking aimed at cloud AI services and LLM API credentials.

Track how attackers are adapting to this technology.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.