Artificial intelligence has finally ceased to be a theoretical tool of the future—today it is embedded in real cyberattacks worldwide. My analysis of fresh data from 2025 and the first half of 2026 shows that AI is being used by attackers at every stage: from reconnaissance to writing malicious code.
AI in the arsenal of APT groups
Over the past year and a half, at least 18 APT groups (Advanced Persistent Threat) have conducted attacks using AI tools. This is not about isolated experiments, but about systematic adoption. For example, the group GTG-1002 actively uses language models to generate phishing emails that adapt to a specific victim and successfully bypass standard spam filters. This dramatically increases the effectiveness of social engineering.
The TAT26-12 cluster has gone further by automating the reconnaissance process: AI collects data on employees, internal infrastructure, and company vulnerabilities without human involvement. Special attention deserves the specialized software PromptSpy, designed for attacks on corporate systems based on large language models (LLMs). Its task is to extract system prompts and manipulate the behavior of AI assistants. Also noted is the tool LAMEHUG, which allows generating malicious code with minimal human participation.
Trends on dark forums
Analysis of activity on shadow forums reveals a curious picture. Among newcomers, OpenAI's ChatGPT still dominates, but in real attacks, Google's Gemini appears more often. Attackers actively discuss methods for bypassing model restrictions, and some attempt to create full-fledged malicious applications based on publicly available AI.
Evolution of ransomware
The ransomware market is undergoing transformation. During the reporting period, more than 50 new groups emerged and over 9,300 incidents were recorded. A key trend is the abandonment of data blocking as the primary method of pressure. Instead, attackers prefer the threat of publishing stolen information. This lowers the technical barrier to entry and complicates defense.
The dynamics of the shadow economy are also telling: over the past year and a half, six major data trading platforms have been shut down, but five new ones have emerged in their place. On active card shops, more than 16.5 million compromised payment cards have been put up for sale.
Let me remind you that earlier OpenAI already slowed down the development of advanced systems after the Hugging Face incident, which confirms that the threat of AI attacks is taken seriously at the highest level.
My comment: We are witnessing a fundamental shift in cybersecurity. AI not only automates attacks—it makes them personalized and difficult to detect. Companies need to rethink their defense approaches by implementing AI solutions for protection as well. The arms race in this field is just beginning, and victory will go to those who adapt faster.