Threat researchers and industry reports say cybercriminals are increasingly using AI-powered tooling to improve phishing, social engineering, credential theft, malware development, and activity inside compromised networks. Sophos found growing discussion across underground forums and marketplaces about large language models being used for multilingual lures, deepfake-enabled fraud, and other attack workflows, while ReliaQuest reported that AI has made attacks cheaper, faster to scale, easier to customize, and harder to detect without fundamentally changing core intrusion tradecraft.
Proofpoint’s 2026 ransomware survey found 65% of victim organizations believed AI increased attack effectiveness, with human interaction frequently enabling initial access through malicious links, attachments, and credential harvesting. Researchers said AI is now being applied to industrial-scale phishing, identity fabrication, phishing pages, web shells, credential harvesters, code padding to evade static analysis, and fake AI-branded downloads, while some criminals also worry automation could displace manual operators or degrade criminal product quality. Defenders were urged to reinforce core controls including MFA, passkeys, patching, behavioral detection, environment visibility, and defense-in-depth as AI-assisted attacks become more convincing and covert.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On July 22, Proofpoint published its 2026 AI-Era Ransomware Report, stating that AI tooling has become part of the attacker playbook in ransomware operations. The report said 65% of surveyed organizations hit by ransomware believed AI increased the effectiveness of the attack.
ReliaQuest said that by mid-2025, underground AI use had expanded to include deepfake services, AI-assisted scripts, and a growing market for AI-enabled tools. It assessed that AI had moved closer to the core offensive workflow of cyber intrusions.
ReliaQuest reported that in 2024, threat actors primarily used AI to polish phishing emails, generate basic scripts, and support malicious tools such as FraudGPT. The company characterized this as an earlier stage before AI moved closer to core intrusion workflows.
Sophos reported a spike in cybercriminal forum discussions about AI following the launch of Claude Mythos Preview. The discussions reflected both interest in AI-enabled cybercrime and skepticism about how disruptive frontier models would be.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourceinfosecurity-magazine.com
Open sourceinfosecurity-magazine.com
Open sourcesophos.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.