Statistical CTI research · 2022–2026 · Dataset generated 29 August 2026

AI in Cyberattacks: Interactive Statistical CTI Dashboard

Explore publication-level evidence about how attackers use AI. Every aggregate below is regenerated from the governed public exports and keeps its analytical denominator visible.

AI in Cyberattacks: A Statistical CTI Study cover
116retrieved source records
111deduplicated publication entities
108usable indexed references
103primary analytical denominator

Integrated research workflow

Move from statistical signal to evidence and detection

Executive dashboard

Corpus composition, publication timing, source classes, and publisher coverage.

111
publication entities
103
eligible publications
4,862
eligible tag mentions
919
eligible metric mentions
483
eligible IOC mentions
31
dashboard widgets

Disposition

Share of the complete 111-publication corpus.

Eligible for primary analysis
103
103 · 92.8%
Context only
5
5 · 4.5%
Excluded — broken source
2
2 · 1.8%
Excluded — non-AI
1
1 · 0.9%

Publication year

Eligible publication coverage; multi-label values can sum above the denominator.

2025
46
46 · 44.7%
2026
23
23 · 22.3%
2024
22
22 · 21.4%
2023
8
8 · 7.8%
Unknown
3
3 · 2.9%
2022
1
1 · 1.0%

Source type

Eligible publication coverage; multi-label values can sum above the denominator.

Operational CTI
37
37 · 35.9%
Vendor Threat Report
32
32 · 31.1%
Provider Or Government Report
17
17 · 16.5%
Government Or Law Enforcement
8
8 · 7.8%
Forecast Or Assessment
5
5 · 4.9%
Empirical Or Academic
2
2 · 1.9%
Other
2
2 · 1.9%

Publisher

Eligible publication coverage; multi-label values can sum above the denominator.

Google Threat Intelligence Group / Mandiant
10
10 · 9.7%
Palo Alto Networks Unit 42
9
9 · 8.7%
Check Point
8
8 · 7.8%
CrowdStrike
8
8 · 7.8%
Recorded Future
8
8 · 7.8%
OpenAI
7
7 · 6.8%
Anthropic
5
5 · 4.9%
Fortinet
4
4 · 3.9%
Proofpoint
4
4 · 3.9%
Rapid7
4
4 · 3.9%
Cisco Talos
3
3 · 2.9%
IBM X-Force
3
3 · 2.9%
Microsoft
3
3 · 2.9%
SentinelOne
3
3 · 2.9%
Trend Micro
3
3 · 2.9%

Attacker behavior and technique coverage

How eligible publications describe attacker AI usage, enabling technology, attack stages, tactics, techniques, and delivery paths.

AI use case

Eligible publication coverage; multi-label values can sum above the denominator.

Identity fraud and impersonation
45
45 · 43.7%
Reconnaissance and target research
44
44 · 42.7%
Obfuscation and evasion
42
42 · 40.8%
Malware development
40
40 · 38.8%
Deepfake video or image
36
36 · 35.0%
Translation and localization
28
28 · 27.2%
Vulnerability research
25
25 · 24.3%
Influence operations
21
21 · 20.4%
CAPTCHA bypass
17
17 · 16.5%
Deepfake voice
14
14 · 13.6%
Exploit development
14
14 · 13.6%
Phishing and lure generation
14
14 · 13.6%
Autonomous or agentic intrusion
7
7 · 6.8%
Code debugging and scripting
5
5 · 4.9%
Command and control
2
2 · 1.9%

AI technology

Eligible publication coverage; multi-label values can sum above the denominator.

Generative AI
59
59 · 57.3%
Large language model
55
55 · 53.4%
Agentic AI
38
38 · 36.9%
Deepfake / synthetic media
35
35 · 34.0%
Speech or voice synthesis
10
10 · 9.7%
Computer vision / OCR
2
2 · 1.9%

Kill Chain

Eligible publication coverage; multi-label values can sum above the denominator.

Actions on Objectives
90
90 · 87.4%
Exploitation
77
77 · 74.8%
Delivery
75
75 · 72.8%
Reconnaissance
47
47 · 45.6%
Command and Control
40
40 · 38.8%
Installation
36
36 · 35.0%
Weaponization
32
32 · 31.1%

ATT&CK tactic

Eligible publication coverage; multi-label values can sum above the denominator.

Initial Access
81
81 · 78.6%
Impact
59
59 · 57.3%
Execution
55
55 · 53.4%
Discovery
49
49 · 47.6%
Exfiltration
48
48 · 46.6%
Reconnaissance
42
42 · 40.8%
Defense Evasion
41
41 · 39.8%
Command and Control
37
37 · 35.9%
Collection
36
36 · 35.0%
Persistence
29
29 · 28.2%
Lateral Movement
26
26 · 25.2%
Resource Development
26
26 · 25.2%
Credential Access
25
25 · 24.3%
Privilege Escalation
21
21 · 20.4%

TTP

Eligible publication coverage; multi-label values can sum above the denominator.

Data exfiltration
48
48 · 46.6%
Command and control
37
37 · 35.9%
Deepfake impersonation
34
34 · 33.0%
Malware generation
33
33 · 32.0%
Defense evasion
32
32 · 31.1%
Credential theft
29
29 · 28.2%
Obfuscation
25
25 · 24.3%
Spearphishing
25
25 · 24.3%
Voice phishing / vishing
25
25 · 24.3%
PowerShell execution
23
23 · 22.3%
Supply-chain compromise
21
21 · 20.4%
Business email compromise
18
18 · 17.5%
Credential harvesting
18
18 · 17.5%
CAPTCHA bypass
17
17 · 16.5%
Prompt injection
16
16 · 15.5%

Attack vector

Eligible publication coverage; multi-label values can sum above the denominator.

Credential theft
32
32 · 31.1%
Spearphishing
25
25 · 24.3%
Vishing
25
25 · 24.3%
Supply chain
21
21 · 20.4%
Business email compromise
18
18 · 17.5%
Malicious advertisement
9
9 · 8.7%
Smishing
5
5 · 4.9%
Fake AI website
2
2 · 1.9%

Actors, targets, providers, and technical entities

Publication coverage across named groups, sectors, geographies, personas, AI services, malware, infrastructure, and data types.

Threat group

Eligible publication coverage; multi-label values can sum above the denominator.

APT28 / Fancy Bear
10
10 · 9.7%
APT43 / Kimsuky
9
9 · 8.7%
Akira
7
7 · 6.8%
Lazarus Group
7
7 · 6.8%
Scattered Spider
7
7 · 6.8%
APT29 / Cozy Bear
6
6 · 5.8%
APT41
6
6 · 5.8%
FunkSec
5
5 · 4.9%
RansomHub
5
5 · 4.9%
APT42 / Charming Kitten
4
4 · 3.9%
Black Basta
4
4 · 3.9%
Famous Chollima
3
3 · 2.9%
SweetSpecter
3
3 · 2.9%
APT31
2
2 · 1.9%
BlueNoroff
2
2 · 1.9%

Sector

Eligible publication coverage; multi-label values can sum above the denominator.

Government
53
53 · 51.5%
Financial Services
48
48 · 46.6%
Telecommunications
29
29 · 28.2%
Cryptocurrency
23
23 · 22.3%
Education
16
16 · 15.5%
Critical Infrastructure
15
15 · 14.6%
Transportation and Logistics
13
13 · 12.6%
Defense
12
12 · 11.7%
Technology
8
8 · 7.8%
Healthcare
7
7 · 6.8%
Artificial Intelligence
6
6 · 5.8%
Media
6
6 · 5.8%
Energy
5
5 · 4.9%
Hospitality
5
5 · 4.9%
Nonprofit / NGO
5
5 · 4.9%

Country / region

Eligible publication coverage; multi-label values can sum above the denominator.

Russia
46
46 · 44.7%
China
44
44 · 42.7%
United States
36
36 · 35.0%
Iran
29
29 · 28.2%
North Korea
29
29 · 28.2%
France
26
26 · 25.2%
Japan
24
24 · 23.3%
Ukraine
20
20 · 19.4%
Germany
19
19 · 18.4%
India
19
19 · 18.4%
Africa
18
18 · 17.5%
Canada
17
17 · 16.5%
South Korea
15
15 · 14.6%
United Kingdom
15
15 · 14.6%
Brazil
14
14 · 13.6%

Target persona

Eligible publication coverage; multi-label values can sum above the denominator.

Executives
63
63 · 61.2%
Developers
60
60 · 58.3%
Employees
46
46 · 44.7%
Consumers or individuals
13
13 · 12.6%
Security researchers
9
9 · 8.7%
AI researchers and experts
2
2 · 1.9%

LLM provider

Eligible publication coverage; multi-label values can sum above the denominator.

OpenAI
50
50 · 48.5%
Anthropic
33
33 · 32.0%
Google
20
20 · 19.4%
Microsoft
12
12 · 11.7%
DeepSeek
8
8 · 7.8%
Hugging Face
8
8 · 7.8%
xAI
7
7 · 6.8%
Mistral AI
5
5 · 4.9%
Meta
2
2 · 1.9%

LLM model

Eligible publication coverage; multi-label values can sum above the denominator.

ChatGPT
36
36 · 35.0%
Claude
31
31 · 30.1%
Gemini
18
18 · 17.5%
Microsoft Copilot
12
12 · 11.7%
GPT-4
10
10 · 9.7%
DeepSeek
8
8 · 7.8%
Grok
5
5 · 4.9%
Mistral / Mixtral
5
5 · 4.9%
Llama
2
2 · 1.9%

Malicious-AI tool

Eligible publication coverage; multi-label values can sum above the denominator.

FraudGPT
12
12 · 11.7%
WormGPT
12
12 · 11.7%
DarkBERT
2
2 · 1.9%
Evil-GPT
2
2 · 1.9%
GhostGPT
1
1 · 1.0%
Nytheon AI
1
1 · 1.0%
Predator AI
1
1 · 1.0%

Malware / tool

Eligible publication coverage; multi-label values can sum above the denominator.

Cobalt Strike
7
7 · 6.8%
LAMEHUG
6
6 · 5.8%
Lumma
6
6 · 5.8%
FunkSec
5
5 · 4.9%
DarkGate
4
4 · 3.9%
Rhadamanthys
4
4 · 3.9%
Vidar
4
4 · 3.9%
BlackBasta ransomware
3
3 · 2.9%
Mimikatz
3
3 · 2.9%
PromptFlux
3
3 · 2.9%
AkiraBot
2
2 · 1.9%
AMOS
2
2 · 1.9%
DanaBot
2
2 · 1.9%
FunkSec ransomware
2
2 · 1.9%
LockBit ransomware
2
2 · 1.9%

Infrastructure

Eligible publication coverage; multi-label values can sum above the denominator.

Email
67
67 · 65.0%
Browser
61
61 · 59.2%
Endpoint
58
58 · 56.3%
Mobile
33
33 · 32.0%
Messaging platform
32
32 · 31.1%
Social media
31
31 · 30.1%
Cloud
19
19 · 18.4%
SaaS
16
16 · 15.5%

Data type

Eligible publication coverage; multi-label values can sum above the denominator.

Credentials and passwords
74
74 · 71.8%
Documents and files
65
65 · 63.1%
Source code
27
27 · 26.2%
Financial and payment data
12
12 · 11.7%
Session cookies or tokens
12
12 · 11.7%
Cryptocurrency keys or seed phrases
10
10 · 9.7%
Personally identifiable information
10
10 · 9.7%

Impact, evidence quality, metrics, and observables

What the corpus says about outcomes and motivation, plus the review queues that must not be mistaken for validated incident prevalence.

Impact

Eligible publication coverage; multi-label values can sum above the denominator.

Ransomware or extortion
69
69 · 67.0%
Data theft or exfiltration
53
53 · 51.5%
Service disruption
22
22 · 21.4%
Credential compromise
17
17 · 16.5%
Espionage
12
12 · 11.7%
Financial fraud
12
12 · 11.7%

Actor motivation

Eligible publication coverage; multi-label values can sum above the denominator.

Influence / information operations
28
28 · 27.2%
Financial
21
21 · 20.4%
Hacktivism
16
16 · 15.5%
Espionage
12
12 · 11.7%
Disruption / destruction
7
7 · 6.8%

Evidence landscape

Eligible publication coverage; multi-label values can sum above the denominator.

Forecast or prediction
52
52 · 50.5%
Incident response
36
36 · 35.0%
Underground-market observation
27
27 · 26.2%
Controlled study
26
26 · 25.2%
Proof of concept
20
20 · 19.4%
In-the-wild observed
19
19 · 18.4%
Threat landscape report
15
15 · 14.6%
Provider abuse telemetry
1
1 · 1.0%

Metric coverage

Eligible publication coverage; multi-label values can sum above the denominator.

Percentage
47
47 · 45.6%
Blast Radius
35
35 · 34.0%
Duration Or Dwell
34
34 · 33.0%
Financial Value
17
17 · 16.5%
Campaign Or Intrusion Duration
3
3 · 2.9%
Breakout Time
2
2 · 1.9%
Dwell Time
1
1 · 1.0%

Unique IOC candidates

472 unique typed values from 483 eligible IOC mentions; each remains an analyst-validation candidate.

Defanged Domain
163
163
SHA-256
142
142
MD5
98
98
SHA-1
66
66
IPv4
3
3

CVE

Eligible publication coverage; multi-label values can sum above the denominator.

CVE-2024-3400
5
5 · 4.9%
CVE-2019-18935
3
3 · 2.9%
CVE-2023-1389
3
3 · 2.9%
CVE-2017-0147
2
2 · 1.9%
CVE-2017-18377
2
2 · 1.9%
CVE-2018-10561
2
2 · 1.9%
CVE-2021-44228
2
2 · 1.9%
CVE-2022-30525
2
2 · 1.9%
CVE-2023-3519
2
2 · 1.9%
CVE-2024-1709
2
2 · 1.9%
CVE-2025-40947
2
2 · 1.9%
CVE-2025-40948
2
2 · 1.9%

Cross-dimensional research leads

Co-mentions are document-level intersections. They do not establish causality, attribution, targeting, victim location, or confirmed tool use.

Sector × AI use case

Number of eligible publications containing both normalized tags.

Sector × AI use case co-mention matrix
CategoryIdentity fraud and impersonationReconnaissance and target researchObfuscation and evasionMalware developmentDeepfake video or imageTranslation and localizationVulnerability researchInfluence operationsCAPTCHA bypassDeepfake voice
Government283228212016209711
Financial Services302624202315167812
Telecommunications1818171216911587
Cryptocurrency16131512896353
Education101111971011332
Critical Infrastructure911910833431
Transportation and Logistics119106744234
Defense91099684333
Technology5664543324
Healthcare5453532314

Threat group × AI use case

Number of eligible publications containing both normalized tags.

Threat group × AI use case co-mention matrix
CategoryIdentity fraud and impersonationReconnaissance and target researchObfuscation and evasionMalware developmentDeepfake video or imageTranslation and localizationVulnerability researchInfluence operationsCAPTCHA bypassDeepfake voice
APT28 / Fancy Bear8788555130
APT43 / Kimsuky8787732224
Akira5233401132
Lazarus Group7656701231
Scattered Spider4252214010
APT29 / Cozy Bear4444402111
APT416655444101
FunkSec5445311322
RansomHub4454401211
APT42 / Charming Kitten4344334000

Kill Chain × AI use case

Number of eligible publications containing both normalized tags.

Kill Chain × AI use case co-mention matrix
CategoryIdentity fraud and impersonationReconnaissance and target researchObfuscation and evasionMalware developmentDeepfake video or imageTranslation and localizationVulnerability researchInfluence operationsCAPTCHA bypassDeepfake voice
Actions on Objectives43394040322523211513
Exploitation36383532312024151312
Delivery38353534312422131314
Reconnaissance264428262217189129
Command and Control222623211315122136
Installation182325201214142105
Weaponization202320271714171088

Provider × AI use case

Number of eligible publications containing both normalized tags.

Provider × AI use case co-mention matrix
CategoryIdentity fraud and impersonationReconnaissance and target researchObfuscation and evasionMalware developmentDeepfake video or imageTranslation and localizationVulnerability researchInfluence operationsCAPTCHA bypassDeepfake voice
OpenAI2521252519211514109
Anthropic15141516811135105
Google12111011101310234
Microsoft9697678325
DeepSeek5346374223
Hugging Face6545654301
xAI4454353212
Mistral AI4343443303
Meta1011211101

Sector × country / region

Number of eligible publications containing both normalized tags.

Sector × country / region co-mention matrix
CategoryRussiaChinaUnited StatesIranNorth KoreaFranceJapanUkraineGermanyIndia
Government27282315181381293
Financial Services2724231518161113125
Telecommunications211413121598954
Cryptocurrency1513119998856
Education7886663631
Critical Infrastructure7786333332
Transportation and Logistics86104684543
Defense10998693843
Technology5563652321
Healthcare3461253232

Eligible publication explorer

All 103 primary-denominator records are server rendered. JavaScript progressively adds local filtering; no data is sent off-site.

103 of 103 eligible publications

Evidence-eligible publications about AI usage in cyberattacks
DatePublisherPublicationAI use casesSectors / groups / providersTagsMetricsIOCs
2025-02 arXiv [2502.00961] AI-Powered Spearphishing Cyber Attacks: Fact or Fiction? Deepfake video or image Hugging Face 8 2 0
2025-08 Recorded Future Emerging AI Threats: The Future of Automated Operations Code debugging and scriptingDeepfake video or imageIdentity fraud and impersonationInfluence operationsMalware developmentObfuscation and evasionPhishing and lure generation Critical InfrastructureDefenseGovernmentAnthropicOpenAI 63 3 0
2025-03-31 Cisco Talos Cisco Talos 2024 Year in Review CAPTCHA bypassCode debugging and scriptingDeepfake video or imageIdentity fraud and impersonationMalware developmentObfuscation and evasionReconnaissance and target research Critical InfrastructureEducationFinancial ServicesGovernmentLegal ServicesManufacturingNonprofit / NGO 126 123 0
2026-08-04 Cisco Talos “Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI Malware developmentReconnaissance and target researchTranslation and localizationVulnerability research CryptocurrencyUAT-10147AnthropicGoogleHugging FaceOpenAI 50 7 2
2026-08-20 Cisco Talos UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations Code debugging and scriptingIdentity fraud and impersonationObfuscation and evasionReconnaissance and target researchVulnerability research EducationGovernmentUAT-10147AnthropicGoogle 70 1 0
2024-05-29 Microsoft 2024 State of Multicloud Security Report EnergyGovernment 25 59 0
2025 CERT-EU CERT-EU - Threat Landscape Report 2025 - A Year In Review Deepfake video or image 11 3 0
2025-01-30 Google Threat Intelligence Group / Mandiant Adversarial Misuse of Generative AI Deepfake video or imageIdentity fraud and impersonationMalware developmentObfuscation and evasionReconnaissance and target researchTranslation and localizationVulnerability research CryptocurrencyDefenseEducationFinancial ServicesGovernmentTelecommunicationsAPT41 93 4 0
2024-11-15 Google Threat Intelligence Group / Mandiant AI Enhancing Your Adversarial Emulation Reconnaissance and target research Financial ServicesGovernmentTelecommunicationsUNC6671GoogleOpenAI 34 16 0
2024-07-24 Google Threat Intelligence Group / Mandiant AI-Powered Voice Spoofing for Next-Gen Vishing Attacks CAPTCHA bypassDeepfake video or imageDeepfake voiceIdentity fraud and impersonationReconnaissance and target research Financial ServicesGovernmentTelecommunicationsUNC6671 39 1 0
2026-05-12 Google Threat Intelligence Group / Mandiant Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access Autonomous or agentic intrusionCAPTCHA bypassDeepfake video or imageDeepfake voiceExploit developmentIdentity fraud and impersonationMalware development Financial ServicesGovernmentMediaTelecommunicationsAPT27APT45UNC2814 117 0 0
2025-05-27 Google Threat Intelligence Group / Mandiant Text-to-Malware: How Cybercriminals Weaponize Fake AI-Themed Websites Obfuscation and evasionReconnaissance and target research CryptocurrencyFinancial ServicesGovernmentTelecommunicationsUNC6032UNC6671 52 0 38
2026-04-17 Google Threat Intelligence Group / Mandiant Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever Exploit developmentVulnerability research Critical InfrastructureFinancial ServicesGovernmentTelecommunicationsUNC6671AnthropicGoogle 39 0 0
2026-02-13 Google Threat Intelligence Group / Mandiant GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use Identity fraud and impersonationMalware developmentObfuscation and evasionPhishing and lure generationReconnaissance and target researchTranslation and localizationVulnerability research CryptocurrencyDefenseFinancial ServicesGovernmentTelecommunicationsAPT31APT41 99 0 0
2025-11-06 Google Threat Intelligence Group / Mandiant GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools Deepfake video or imageExploit developmentIdentity fraud and impersonationMalware developmentObfuscation and evasionReconnaissance and target researchTranslation and localization CryptocurrencyEducationFinancial ServicesGovernmentTelecommunicationsAPT28 / Fancy BearAPT41 103 0 0
2023-08-17 Google Threat Intelligence Group / Mandiant Threat Actors are Interested in Generative AI, but Use Remains Limited Deepfake video or imageDeepfake voiceIdentity fraud and impersonationInfluence operationsMalware developmentObfuscation and evasionReconnaissance and target research Financial ServicesGovernmentMediaTelecommunicationsAPT43 / KimsukyAPT43UNC6671 65 0 0
2026-02-10 Google Threat Intelligence Group / Mandiant UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering Deepfake video or imageReconnaissance and target researchTranslation and localization CryptocurrencyFinancial ServicesGovernmentTechnologyTelecommunicationsBlueNoroffUNC1069 61 0 16
2025-04-28 Fortinet 2025 Global Threat Landscape Report Deepfake video or imageIdentity fraud and impersonationMalware developmentObfuscation and evasionPhishing and lure generationReconnaissance and target research Critical InfrastructureCryptocurrencyFinancial ServicesGovernmentTelecommunicationsAPT28 / Fancy BearAPT29 / Cozy Bear 107 97 0
2025-03-25 KELA 2025 AI Threat Report: How Cybercriminals Are Weaponizing AI Technology Deepfake video or imageDeepfake voiceExploit developmentIdentity fraud and impersonationInfluence operationsMalware developmentPhishing and lure generation Financial ServicesGovernmentStorm-2139STORM-2139UNC6780AnthropicDeepSeek 82 10 0
2024-10-09 OpenAI An update on disrupting deceptive uses of AI Influence operations OpenAI 5 0 0
2025-06-05 OpenAI Disrupting malicious uses of AI: June 2025 Influence operations OpenAI 7 0 0
2025-10-07 OpenAI Disrupting malicious uses of AI: October 2025 Influence operations OpenAI 8 0 4
2026-02-25 OpenAI Disrupting malicious uses of AI Influence operations OpenAI 6 0 0
2024-02-14 OpenAI Disrupting malicious uses of AI by state-affiliated threat actors Code debugging and scriptingObfuscation and evasionTranslation and localization APT43 / KimsukyOpenAI 20 0 4
2025-10-01 OpenAI Scam operations: Online fraud networks Identity fraud and impersonationObfuscation and evasionTranslation and localization OpenAI 15 0 2
2024-10-01 OpenAI STORM-0817: Iran-linked malware and scraping activity Code debugging and scriptingReconnaissance and target researchTranslation and localization DefenseEducationGovernmentMediaSweetSpecterSTORM-0817OpenAI 22 0 0
2023-01-06 Check Point OPWNAI : Cybercriminals Starting to Use ChatGPT - Check Point Research Malware development CryptocurrencyOpenAI 42 0 0
2025-01-10 Check Point FunkSec – Alleged Top Ransomware Group Powered by AI - Check Point Research Identity fraud and impersonationMalware development AkiraFunkSecOpenAI 54 2 9
2025-05-20 Check Point Impersonated GenAI Site Lures Victims to Infostealer Download - Check Point Research Identity fraud and impersonationObfuscation and evasion CryptocurrencyFinancial ServicesGoogleOpenAI 65 0 36
2025-04-30 Check Point The State of AI in Cyber Security - Check Point Research Deepfake video or imageDeepfake voiceExploit developmentIdentity fraud and impersonationInfluence operationsMalware developmentTranslation and localization DeepSeekHugging FaceMicrosoftOpenAI 67 11 2
2026-02-17 Check Point AI in the Middle: Turning Web-Based AI Services into C2 Proxies & The Future Of AI Driven Attacks - Check Point Research CAPTCHA bypassCommand and controlMalware developmentReconnaissance and target researchTranslation and localization Critical InfrastructureDefenseAnthropicGoogleMicrosoftOpenAIxAI 72 1 0
2026-07-01 Check Point Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique - Check Point Research Malware developmentTranslation and localization Financial ServicesAnthropicDeepSeekOpenAI 60 0 1
2026-03-30 Check Point ChatGPT Data Leakage via a Hidden Outbound Channel in the Code Execution Runtime - Check Point Research OpenAI 38 0 0
2025-10-28 Kaspersky GReAT BlueNoroff’s latest campaigns: GhostCall and GhostHire | Securelist CAPTCHA bypassDeepfake video or imageIdentity fraud and impersonationMalware developmentObfuscation and evasionReconnaissance and target research CryptocurrencyFinancial ServicesTelecommunicationsTransportation and LogisticsAPT43 / KimsukyBlueNoroffLazarus Group 96 2 90
2025-07-30 Palo Alto Networks Unit 42 2025 Unit 42 Global Incident Response Report: Social Engineering Edition CAPTCHA bypassIdentity fraud and impersonationReconnaissance and target research Financial ServicesGovernmentRetailTelecommunicationsAnthropic 65 16 0
2025-05-01 Palo Alto Networks Unit 42 AI Agents Are Here. So Are the Threats. CAPTCHA bypassIdentity fraud and impersonation Anthropic 45 2 1
2026-08-25 Palo Alto Networks Unit 42 The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution CAPTCHA bypassIdentity fraud and impersonationMalware developmentObfuscation and evasionReconnaissance and target research Artificial IntelligenceCritical InfrastructureCryptocurrencyFunkSecAnthropicOpenAI 61 13 12
2026-03-19 Palo Alto Networks Unit 42 Analyzing the Current State of AI Use in Malware Autonomous or agentic intrusionCAPTCHA bypassMalware developmentObfuscation and evasionReconnaissance and target research AnthropicOpenAI 57 4 4
2026-07-30 Palo Alto Networks Unit 42 Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks Autonomous or agentic intrusionCAPTCHA bypassExploit developmentPhishing and lure generation GovernmentAnthropicDeepSeekOpenAI 66 2 3
2026-08-04 Palo Alto Networks Unit 42 The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software Autonomous or agentic intrusionCAPTCHA bypassExploit developmentVulnerability research AnthropicOpenAI 44 10 0
2025-08-19 Palo Alto Networks Unit 42 Fashionable Phishing Bait: GenAI on the Hook CAPTCHA bypassDeepfake video or imageIdentity fraud and impersonationPhishing and lure generation Legal ServicesTelecommunicationsAkiraLazarus Group 40 7 0
2026-01-22 Palo Alto Networks Unit 42 The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time CAPTCHA bypassIdentity fraud and impersonationMalware developmentObfuscation and evasionPhishing and lure generationTranslation and localization CryptocurrencyDefenseAPT28 / Fancy BearAPT28AnthropicDeepSeekGoogle 62 1 0
2026-07-15 Palo Alto Networks Unit 42 TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development CAPTCHA bypassMalware development CryptocurrencyAnthropic 74 12 40
2025-11-13 Anthropic Disrupting the first reported AI-orchestrated cyber espionage campaign Autonomous or agentic intrusionExploit developmentMalware developmentReconnaissance and target researchVulnerability research Financial ServicesGovernmentManufacturingAnthropic 50 6 0
2026-06-03 Anthropic What we learned mapping a year’s worth of AI-enabled cyber threats Phishing and lure generation Financial ServicesGovernmentAnthropic 24 8 0
2025-04-23 Anthropic Detecting and countering malicious uses of Claude: March 2025 Identity fraud and impersonationInfluence operationsMalware development Artificial IntelligenceFinancial ServicesGovernmentAnthropic 25 0 0
2025-08-27 Anthropic Detecting and countering misuse of AI: August 2025 Reconnaissance and target research CryptocurrencyFinancial ServicesGovernmentTechnologyTelecommunicationsAnthropic 35 3 0
2026-06-03 Anthropic Mapping AI-enabled cyber threats: Insights from the LLM ATT&CK Navigator Autonomous or agentic intrusionMalware developmentObfuscation and evasionReconnaissance and target research Critical InfrastructureFinancial ServicesGovernmentAnthropic 68 34 0
2025-04-30 Check Point AI Security Report 2025 Financial ServicesGovernment 20 3 2
2026-06-23 CISA Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite | CISA Obfuscation and evasionReconnaissance and target research DefenseGovernmentNonprofit / NGOTA488 97 5 24
2026-06-23 CISA Defending Against an Active Threat to Siemens S7 Series PLCs | CISA Exploit developmentObfuscation and evasionReconnaissance and target research Critical InfrastructureEnergyGovernment 37 0 0
2024-08-20 CrowdStrike CrowdStrike 2024 Threat Hunting Report: Executive Summary Obfuscation and evasion Financial ServicesGovernmentHealthcareHospitalityTechnologyTelecommunicationsTransportation and Logistics 33 42 0
2025-08-04 CrowdStrike AI vs AI: The Cybersecurity Arms Race Command and controlDeepfake video or imageDeepfake voiceIdentity fraud and impersonationObfuscation and evasionReconnaissance and target researchTranslation and localization Financial ServicesGovernmentAnthropicMicrosoftOpenAI 65 6 0
2024-02-21 CrowdStrike 2024 Global Threat Report Trends and Overview Influence operationsObfuscation and evasionVulnerability research Financial ServicesGovernmentAnthropicMicrosoftOpenAI 41 12 0
2025-08-04 CrowdStrike CrowdStrike 2025 Threat Hunting Report: AI Becomes a Weapon and a Target Deepfake video or imageIdentity fraud and impersonationMalware developmentObfuscation and evasionPhishing and lure generationVulnerability research Financial ServicesGovernmentTelecommunicationsAPT42 / Charming KittenFamous ChollimaScattered SpiderAnthropic 66 16 0
2024-09-26 CrowdStrike How CrowdStrike Hunts, Identifies and Defeats Cloud-Focused Threats Obfuscation and evasionVulnerability research Financial ServicesGovernmentAPT29 / Cozy BearScattered SpiderAnthropicMicrosoftOpenAI 39 8 0
2025 CrowdStrike How cyber adversaries use GenAI in vulnerability research and cloud operations Exploit developmentVulnerability research Critical InfrastructureGovernment 22 1 0
2025 CrowdStrike How adversaries are using GenAI for social engineering attacks Deepfake video or imagePhishing and lure generation Famous ChollimaAnthropicGoogleOpenAI 39 4 0
2024-02-21 CrowdStrike CrowdStrike 2024 Global Threat Report: Executive Summary Exploit development GovernmentAPT28 / Fancy BearAPT29 / Cozy BearScattered Spider 37 18 0
2024-06-27 ESET ESET Threat Report: Infostealers using AI & banking malware creating deepfake videos to steal money Deepfake video or imageIdentity fraud and impersonationTranslation and localization Critical InfrastructureFinancial ServicesGoogleOpenAI 25 3 0
2024-01 Europol Facing reality? Law enforcement and the challenge of deepfakes | Europol Deepfake video or imageInfluence operations 13 3 0
2025-12-19 FBI Senior U.S. Officials Continue To Be Impersonated in Malicious Messaging Campaign | Federal Bureau of Investigation Deepfake voiceIdentity fraud and impersonation CryptocurrencyFinancial ServicesGovernment 22 0 0
2024-11-13 FinCEN FinCEN Issues Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions | FinCEN.gov Deepfake video or image Financial ServicesGovernment 13 0 0
2023-11-09 Fortinet Threat Predictions for 2024: Chained AI and CaaS Operations Give Attackers More “Easy” Buttons Than Ever | FortiGuard Labs Reconnaissance and target research EnergyTransportation and Logistics 18 1 0
2025-04-28 Fortinet Key Takeaways from the 2025 Global Threat Landscape Report | FortiGuard Labs Deepfake video or imageMalware developmentReconnaissance and target research Artificial IntelligenceCritical Infrastructure 52 9 0
2024-11-21 Fortinet Cyberthreat Predictions for 2025: An Annual Perspective from FortiGuard Labs Deepfake video or imageIdentity fraud and impersonationMalware developmentReconnaissance and target research Critical InfrastructureDefenseEducationEnergyFinancial ServicesGovernmentHealthcare 61 11 0
2025-10-22 UK Government International scientific report on the safety of advanced AI: interim report - GOV.UK Deepfake video or imageDeepfake voiceIdentity fraud and impersonationInfluence operationsObfuscation and evasionTranslation and localizationVulnerability research Artificial IntelligenceDefenseEducationEnergyFinancial ServicesGovernmentHealthcare 87 50 26
2025-04-02 IBM X-Force X-Force Threat Intelligence Index 2024 reveals stolen credentials as top risk, with AI attacks on the horizon | IBM 18 13 0
2026-04-30 IBM X-Force The adversary didn’t wait. Neither should you. | IBM Reconnaissance and target researchVulnerability research 15 2 0
2025-04-04 IBM X-Force Hive0137 on an AI journey | IBM Malware developmentObfuscation and evasionPhishing and lure generationTranslation and localization HospitalityTA571TA577 39 4 8
2024-12-03 FBI IC3 Internet Crime Complaint Center (IC3) | Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud Identity fraud and impersonation CryptocurrencyFinancial ServicesGovernment 19 0 0
2026-08-03 INTERPOL INTERPOL report finds AI linked to more than half of cybercrime in Africa Deepfake video or imageReconnaissance and target research Financial ServicesMediaTelecommunications 31 1 0
2024-05-22 Kroll Q1 2024 Threat Landscape Report: Insider Threat & Phishing Evolve Under AI Auspices Deepfake video or imageDeepfake voiceIdentity fraud and impersonation Financial ServicesTelecommunicationsAkiraAPT43 / Kimsuky 43 12 0
2024-02-14 Microsoft Staying ahead of threat actors in the age of AI CAPTCHA bypassIdentity fraud and impersonationMalware developmentObfuscation and evasionReconnaissance and target researchTranslation and localizationVulnerability research DefenseEducationFinancial ServicesGovernmentNonprofit / NGOTechnologyTransportation and Logistics 70 1 0
2023-11 Microsoft Cyber Signals Issue 6: AI Cyber Defense for Threats | Security Insider Deepfake video or imageDeepfake voiceIdentity fraud and impersonationMalware developmentObfuscation and evasionReconnaissance and target research DefenseFinancial ServicesGovernmentNonprofit / NGOTechnologyTransportation and LogisticsAPT43 / Kimsuky 58 3 1
2025-05-07 UK Government Impact of AI on cyber threat from now to 2027 | National Cyber Security Centre Exploit developmentInfluence operationsMalware developmentObfuscation and evasionReconnaissance and target researchVulnerability research EducationGovernment 42 0 0
2024-01-24 UK Government The near-term impact of AI on the cyber threat | National Cyber Security Centre Exploit developmentMalware developmentObfuscation and evasionReconnaissance and target researchTranslation and localizationVulnerability research EducationGovernment 36 0 0
2025-11-12 Proofpoint Operation Endgame Quakes Rhadamanthys Identity fraud and impersonationObfuscation and evasion CryptocurrencyFinancial ServicesGovernmentTransportation and LogisticsTA547TA2541TA571 55 4 39
2024-05-14 Proofpoint SugarGh0st RAT Targets American AI Experts Artificial IntelligenceEducationFinancial ServicesGovernmentMediaTelecommunicationsSweetSpecter 40 4 6
2024-04-03 Proofpoint TA547 Targets German Organizations: Rhadamanthys Stealer Identity fraud and impersonationMalware developmentPhishing and lure generation Financial ServicesGovernmentTA547AnthropicGoogleMicrosoftOpenAI 48 0 3
2024-01-22 Proofpoint Cyber Threat Landscape 2024: What to Expect Financial ServicesGovernmentTA473TA577Anthropic 29 0 0
2025-07-02 Rapid7 How Social Engineering Attacks Are Evolving in 2025 Identity fraud and impersonation Transportation and LogisticsBlack BastaScattered Spider 25 0 0
2025-06-26 Rapid7 How LLMs Like WormGPT Are Reshaping Cybercrime in 2025 Deepfake video or imageExploit developmentIdentity fraud and impersonationInfluence operationsMalware developmentObfuscation and evasionReconnaissance and target research Critical InfrastructureHugging FaceMistral AIOpenAIxAI 52 2 0
2025-06-23 Rapid7 Emerging Trends in AI-Related Cyberthreats in 2025 - Rapid7 Blog Deepfake video or imageIdentity fraud and impersonationInfluence operationsMalware developmentObfuscation and evasionReconnaissance and target research APT28 / Fancy BearAPT31CyberAv3ngersFunkSecLazarus GroupRansomHubSweetSpecter 55 0 0
2025-11-12 Rapid7 The Q3 2025 Threat Landscape Report Deepfake video or imageDeepfake voiceIdentity fraud and impersonationInfluence operationsMalware developmentObfuscation and evasionReconnaissance and target research Critical InfrastructureCryptocurrencyDefenseFinancial ServicesGovernmentHealthcareLegal Services 130 10 0
2024 Recorded Future 2024 Threat Analysis and 2025 Predictions │ Recorded Future Annual Threat Report Identity fraud and impersonationInfluence operationsObfuscation and evasion Critical InfrastructureCryptocurrencyTelecommunications 29 2 0
2025-10-24 Recorded Future 2025 Cloud Threat Hunting and Defense Landscape Identity fraud and impersonationObfuscation and evasionReconnaissance and target researchTranslation and localizationVulnerability research CryptocurrencyEducationFinancial ServicesGovernmentTelecommunicationsTransportation and LogisticsAPT28 / Fancy Bear 112 7 4
2025 Recorded Future 2025 Year in Review: Malicious Infrastructure 17 1 0
Unknown Recorded Future Adversarial Intelligence: Red Teaming Malicious Use Cases for AI Deepfake video or imageIdentity fraud and impersonationInfluence operationsObfuscation and evasionReconnaissance and target researchTranslation and localization 21 0 0
Unknown Recorded Future Emerging Enterprise Security Risks of AI Malware development 22 3 0
2022-11-30 Recorded Future I, Chatbot | Recorded Future Influence operationsMalware developmentTranslation and localization MediaOpenAI 33 0 0
2023-01-26 Recorded Future I Have No Mouth, and I Must Do Crime | Recorded Future Deepfake video or imageDeepfake voiceIdentity fraud and impersonationInfluence operations 20 0 1
2025-04-09 SentinelOne AkiraBot | AI-Powered Bot Bypasses CAPTCHAs, Spams Websites At Scale | SentinelOne CAPTCHA bypass Financial ServicesTelecommunicationsAkiraOpenAI 33 6 64
2023-11-07 SentinelOne Predator AI | ChatGPT-Powered Infostealer Takes Aim at Cloud Platforms | SentinelOne TelecommunicationsOpenAI 28 0 2
2025-09-19 SentinelOne Prompts as Code & Embedded Keys | The Hunt for LLM-Enabled Malware | SentinelOne Malware developmentObfuscation and evasionTranslation and localizationVulnerability research EducationTelecommunicationsAPT28 / Fancy BearAPT28AnthropicDeepSeekGoogle 55 2 39
2025-04-16 Sophos The Sophos Annual Threat Report: Cybercrime on Main Street 2025 Obfuscation and evasion CryptocurrencyAkiraRansomHubOpenAI 73 13 0
2025-02-04 ThreatDown / Malwarebytes ThreatDown State of Malware Report 2025: Autonomous AI and Ransomware HealthcareOpenAIxAI 19 6 0
2026-04-16 Trend Micro 2025 APT Report: Staying Ahead of the Modern Threat Landscape Reconnaissance and target research Government 30 1 0
2023-08 Trend Micro Back to the Hype: An Update on How Cybercriminals Are Using GenAI Deepfake video or imageIdentity fraud and impersonationTranslation and localization CryptocurrencyEducationFinancial ServicesGovernmentHugging FaceOpenAI 30 5 0
2023-04-17 Trend Micro Hype vs. Reality: AI in the Cybercriminal Underground Deepfake video or imageMalware development GoogleMetaOpenAI 30 11 0
2025-09 UNODC Emerging threats: The intersection of criminal and technological innovation in the use of automation and artificial intelligence in the cybercrime landscape of Southeast Asia CAPTCHA bypassDeepfake video or imageDeepfake voiceIdentity fraud and impersonationInfluence operationsMalware developmentObfuscation and evasion CryptocurrencyEducationFinancial ServicesGovernmentHealthcareHospitalityTechnology 85 11 0
Unknown USENIX Malla: Demystifying Real-world Large Language Model Integrated Malicious Services | USENIX EducationHospitality 4 0 0
2025-03-20 Zscaler ThreatLabz ThreatLabz 2025 AI Security Report Autonomous or agentic intrusionDeepfake video or imageDeepfake voiceIdentity fraud and impersonationObfuscation and evasionPhishing and lure generationReconnaissance and target research Artificial IntelligenceFinancial ServicesGovernmentHealthcareTransportation and LogisticsAnthropicDeepSeek 92 143 0

Reproducible research

Download the published dataset

Use the publication table for analysis-ready records and the long-form tables for reproducible aggregation. Candidate tags, metrics, and IOCs remain analyst-review inputs rather than validated operational intelligence. Review the governed dataset landing page for schemas, provenance, file sizes, spreadsheet safeguards, and interpretation limits.