Openly available and weakly restricted AI systems are being used to speed up cybercrime and expand operational support for violent groups. Reporting citing ThreatDown said 6,644 Hugging Face models labeled uncensored or unfiltered were downloaded more than 22 million times in 30 days, while criminals increasingly rent or repackage legitimate frontier models through malicious AI services instead of building their own. Security researchers and industry leaders said the shift is accelerating vulnerability discovery and exploitation, while also enabling AI-native threats such as prompt injection and model poisoning.
Separate research from Cambridge University found Boko Haram used mainstream U.S. and Chinese AI chatbots to assist with bomb-making, attack planning, propaganda, surveillance, movement, and other day-to-day tasks, with former members describing internal AI training and specialized units dedicated to chatbot use. Across cybercrime, AI is also being used to automate ransomware, phishing, fraud, and cloud intrusions, including cases where ransomware activity was heavily automated, cloud attack timelines were cut to 72 hours, and AI supported bank fraud targeting financial institutions in Mexico. The combined findings show AI is becoming a repeatable force multiplier that makes attacks faster, cheaper, more scalable, and more difficult for defenders to disrupt.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Reporting on cybercrime trends said attackers are increasingly using AI to speed ransomware, phishing, fraud, and cloud intrusions as open-weight and jailbroken models become easier to obtain. Examples cited included AI automating much of a ransomware attack, reducing a cloud attack timeline to 72 hours, and supporting a bank fraud scheme targeting financial organizations in Mexico.
A Cambridge University study, based on interviews with 27 former Boko Haram members, found the group used U.S. and Chinese AI chatbots for bomb-making, attack planning, propaganda, surveillance, movement, and other operational support. Former members also said Boko Haram ran internal AI training and received outside instruction on VPNs, encryption, and bypassing chatbot safety controls.
ThreatDown research found 6,644 openly published Hugging Face models labeled as uncensored or unfiltered, downloaded more than 22 million times in a 30-day period. The report framed these openly available models as accelerating offensive cyber capabilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
netaskari.substack.com
Open sourcecysecurity.news
Open sourcecysecurity.news
Open sourcesecuritymagazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.