The cybersecurity threat landscape has undergone a fundamental transformation. My analysis of data from 2025 and the first half of 2026 shows that artificial intelligence has ceased to be a theoretical concept and has become a full-fledged combat tool in the arsenal of attackers. This is not about isolated experiments, but about the systematic integration of AI into all stages of attacks—from reconnaissance to the final phase.

Practical application of AI in real attacks

Over the past year and a half, at least 18 APT groups actively using neural networks in their operations have been recorded. The GTG-1002 cluster deserves special attention, as it uses language models to generate phishing emails. These texts are not just adapted to a specific victim—they successfully bypass standard spam filters, making them almost indistinguishable from legitimate correspondence.

The TAT26-12 group has gone further by automating the cyber reconnaissance process. AI collects and analyzes data about employees, infrastructure, and organizational vulnerabilities, significantly accelerating attack preparation. The PromptSpy tool stands out separately—highly specialized software for hacking corporate LLM systems. Its task is to extract system prompts and manipulate model behavior, opening a completely new attack vector against companies that have integrated AI into their business processes.

Equally telling is the LAMEHUG tool, which generates malicious code with minimal human involvement. This means the entry barrier to cybercrime is lowered to a level where creating malware no longer requires deep technical knowledge.

Trends on dark forums

Analysis of activity on underground forums demonstrates interesting dynamics. OpenAI's ChatGPT remains the most popular solution among novice hackers, but for full-scale attacks, professionals increasingly choose Google's Gemini. This indicates the latter model's more advanced capabilities in the context of complex scenarios.

Forum participants actively discuss methods for bypassing restrictions, and some even attempt to create malicious software using publicly available neural networks. This confirms that AI has become an integral part of the hacker toolkit.

Evolution of ransomware

The transformation of the ransomware market deserves special attention. Over the reporting period, more than 50 new groups emerged, and the number of incidents exceeded 9,300. The key trend is the abandonment of data locking as the primary method of pressure. Instead, attackers are betting on the threat of publishing stolen information, which significantly simplifies the technical part of the attack but complicates defense for victims.

At the same time, curious dynamics are observed on underground platforms: the closure of six major marketplaces led to the emergence of five new ones, and more than 16.5 million compromised payment cards are listed for sale on active card shops.

My comment: We are witnessing a turning point where AI is becoming an equal participant in cyber warfare. The fact that even OpenAI is forced to slow down the development of advanced systems due to cyber risks confirms the seriousness of the threat. The security industry urgently needs to rethink its approaches to defense—traditional methods are no longer coping with the new generation of AI-powered attacks.