Disposition
Share of the complete 111-publication corpus.
Statistical CTI research · 2022–2026 · Dataset generated 29 August 2026
Explore publication-level evidence about how attackers use AI. Every aggregate below is regenerated from the governed public exports and keeps its analytical denominator visible.

Integrated research workflow
Corpus composition, publication timing, source classes, and publisher coverage.
Share of the complete 111-publication corpus.
Eligible publication coverage; multi-label values can sum above the denominator.
Eligible publication coverage; multi-label values can sum above the denominator.
Eligible publication coverage; multi-label values can sum above the denominator.
How eligible publications describe attacker AI usage, enabling technology, attack stages, tactics, techniques, and delivery paths.
Eligible publication coverage; multi-label values can sum above the denominator.
Eligible publication coverage; multi-label values can sum above the denominator.
Eligible publication coverage; multi-label values can sum above the denominator.
Eligible publication coverage; multi-label values can sum above the denominator.
Eligible publication coverage; multi-label values can sum above the denominator.
Eligible publication coverage; multi-label values can sum above the denominator.
Publication coverage across named groups, sectors, geographies, personas, AI services, malware, infrastructure, and data types.
Eligible publication coverage; multi-label values can sum above the denominator.
Eligible publication coverage; multi-label values can sum above the denominator.
Eligible publication coverage; multi-label values can sum above the denominator.
Eligible publication coverage; multi-label values can sum above the denominator.
Eligible publication coverage; multi-label values can sum above the denominator.
Eligible publication coverage; multi-label values can sum above the denominator.
Eligible publication coverage; multi-label values can sum above the denominator.
Eligible publication coverage; multi-label values can sum above the denominator.
Eligible publication coverage; multi-label values can sum above the denominator.
Eligible publication coverage; multi-label values can sum above the denominator.
What the corpus says about outcomes and motivation, plus the review queues that must not be mistaken for validated incident prevalence.
Eligible publication coverage; multi-label values can sum above the denominator.
Eligible publication coverage; multi-label values can sum above the denominator.
Eligible publication coverage; multi-label values can sum above the denominator.
Eligible publication coverage; multi-label values can sum above the denominator.
472 unique typed values from 483 eligible IOC mentions; each remains an analyst-validation candidate.
Eligible publication coverage; multi-label values can sum above the denominator.
Co-mentions are document-level intersections. They do not establish causality, attribution, targeting, victim location, or confirmed tool use.
Number of eligible publications containing both normalized tags.
| Category | Identity fraud and impersonation | Reconnaissance and target research | Obfuscation and evasion | Malware development | Deepfake video or image | Translation and localization | Vulnerability research | Influence operations | CAPTCHA bypass | Deepfake voice |
|---|---|---|---|---|---|---|---|---|---|---|
| Government | 28 | 32 | 28 | 21 | 20 | 16 | 20 | 9 | 7 | 11 |
| Financial Services | 30 | 26 | 24 | 20 | 23 | 15 | 16 | 7 | 8 | 12 |
| Telecommunications | 18 | 18 | 17 | 12 | 16 | 9 | 11 | 5 | 8 | 7 |
| Cryptocurrency | 16 | 13 | 15 | 12 | 8 | 9 | 6 | 3 | 5 | 3 |
| Education | 10 | 11 | 11 | 9 | 7 | 10 | 11 | 3 | 3 | 2 |
| Critical Infrastructure | 9 | 11 | 9 | 10 | 8 | 3 | 3 | 4 | 3 | 1 |
| Transportation and Logistics | 11 | 9 | 10 | 6 | 7 | 4 | 4 | 2 | 3 | 4 |
| Defense | 9 | 10 | 9 | 9 | 6 | 8 | 4 | 3 | 3 | 3 |
| Technology | 5 | 6 | 6 | 4 | 5 | 4 | 3 | 3 | 2 | 4 |
| Healthcare | 5 | 4 | 5 | 3 | 5 | 3 | 2 | 3 | 1 | 4 |
Number of eligible publications containing both normalized tags.
| Category | Identity fraud and impersonation | Reconnaissance and target research | Obfuscation and evasion | Malware development | Deepfake video or image | Translation and localization | Vulnerability research | Influence operations | CAPTCHA bypass | Deepfake voice |
|---|---|---|---|---|---|---|---|---|---|---|
| APT28 / Fancy Bear | 8 | 7 | 8 | 8 | 5 | 5 | 5 | 1 | 3 | 0 |
| APT43 / Kimsuky | 8 | 7 | 8 | 7 | 7 | 3 | 2 | 2 | 2 | 4 |
| Akira | 5 | 2 | 3 | 3 | 4 | 0 | 1 | 1 | 3 | 2 |
| Lazarus Group | 7 | 6 | 5 | 6 | 7 | 0 | 1 | 2 | 3 | 1 |
| Scattered Spider | 4 | 2 | 5 | 2 | 2 | 1 | 4 | 0 | 1 | 0 |
| APT29 / Cozy Bear | 4 | 4 | 4 | 4 | 4 | 0 | 2 | 1 | 1 | 1 |
| APT41 | 6 | 6 | 5 | 5 | 4 | 4 | 4 | 1 | 0 | 1 |
| FunkSec | 5 | 4 | 4 | 5 | 3 | 1 | 1 | 3 | 2 | 2 |
| RansomHub | 4 | 4 | 5 | 4 | 4 | 0 | 1 | 2 | 1 | 1 |
| APT42 / Charming Kitten | 4 | 3 | 4 | 4 | 3 | 3 | 4 | 0 | 0 | 0 |
Number of eligible publications containing both normalized tags.
| Category | Identity fraud and impersonation | Reconnaissance and target research | Obfuscation and evasion | Malware development | Deepfake video or image | Translation and localization | Vulnerability research | Influence operations | CAPTCHA bypass | Deepfake voice |
|---|---|---|---|---|---|---|---|---|---|---|
| Actions on Objectives | 43 | 39 | 40 | 40 | 32 | 25 | 23 | 21 | 15 | 13 |
| Exploitation | 36 | 38 | 35 | 32 | 31 | 20 | 24 | 15 | 13 | 12 |
| Delivery | 38 | 35 | 35 | 34 | 31 | 24 | 22 | 13 | 13 | 14 |
| Reconnaissance | 26 | 44 | 28 | 26 | 22 | 17 | 18 | 9 | 12 | 9 |
| Command and Control | 22 | 26 | 23 | 21 | 13 | 15 | 12 | 2 | 13 | 6 |
| Installation | 18 | 23 | 25 | 20 | 12 | 14 | 14 | 2 | 10 | 5 |
| Weaponization | 20 | 23 | 20 | 27 | 17 | 14 | 17 | 10 | 8 | 8 |
Number of eligible publications containing both normalized tags.
| Category | Identity fraud and impersonation | Reconnaissance and target research | Obfuscation and evasion | Malware development | Deepfake video or image | Translation and localization | Vulnerability research | Influence operations | CAPTCHA bypass | Deepfake voice |
|---|---|---|---|---|---|---|---|---|---|---|
| OpenAI | 25 | 21 | 25 | 25 | 19 | 21 | 15 | 14 | 10 | 9 |
| Anthropic | 15 | 14 | 15 | 16 | 8 | 11 | 13 | 5 | 10 | 5 |
| 12 | 11 | 10 | 11 | 10 | 13 | 10 | 2 | 3 | 4 | |
| Microsoft | 9 | 6 | 9 | 7 | 6 | 7 | 8 | 3 | 2 | 5 |
| DeepSeek | 5 | 3 | 4 | 6 | 3 | 7 | 4 | 2 | 2 | 3 |
| Hugging Face | 6 | 5 | 4 | 5 | 6 | 5 | 4 | 3 | 0 | 1 |
| xAI | 4 | 4 | 5 | 4 | 3 | 5 | 3 | 2 | 1 | 2 |
| Mistral AI | 4 | 3 | 4 | 3 | 4 | 4 | 3 | 3 | 0 | 3 |
| Meta | 1 | 0 | 1 | 1 | 2 | 1 | 1 | 1 | 0 | 1 |
Number of eligible publications containing both normalized tags.
| Category | Russia | China | United States | Iran | North Korea | France | Japan | Ukraine | Germany | India |
|---|---|---|---|---|---|---|---|---|---|---|
| Government | 27 | 28 | 23 | 15 | 18 | 13 | 8 | 12 | 9 | 3 |
| Financial Services | 27 | 24 | 23 | 15 | 18 | 16 | 11 | 13 | 12 | 5 |
| Telecommunications | 21 | 14 | 13 | 12 | 15 | 9 | 8 | 9 | 5 | 4 |
| Cryptocurrency | 15 | 13 | 11 | 9 | 9 | 9 | 8 | 8 | 5 | 6 |
| Education | 7 | 8 | 8 | 6 | 6 | 6 | 3 | 6 | 3 | 1 |
| Critical Infrastructure | 7 | 7 | 8 | 6 | 3 | 3 | 3 | 3 | 3 | 2 |
| Transportation and Logistics | 8 | 6 | 10 | 4 | 6 | 8 | 4 | 5 | 4 | 3 |
| Defense | 10 | 9 | 9 | 8 | 6 | 9 | 3 | 8 | 4 | 3 |
| Technology | 5 | 5 | 6 | 3 | 6 | 5 | 2 | 3 | 2 | 1 |
| Healthcare | 3 | 4 | 6 | 1 | 2 | 5 | 3 | 2 | 3 | 2 |
All 103 primary-denominator records are server rendered. JavaScript progressively adds local filtering; no data is sent off-site.
103 of 103 eligible publications
| Date | Publisher | Publication | AI use cases | Sectors / groups / providers | Tags | Metrics | IOCs |
|---|---|---|---|---|---|---|---|
| 2025-02 | arXiv | [2502.00961] AI-Powered Spearphishing Cyber Attacks: Fact or Fiction? | Deepfake video or image | Hugging Face | 8 | 2 | 0 |
| 2025-08 | Recorded Future | Emerging AI Threats: The Future of Automated Operations | Code debugging and scriptingDeepfake video or imageIdentity fraud and impersonationInfluence operationsMalware developmentObfuscation and evasionPhishing and lure generation | Critical InfrastructureDefenseGovernmentAnthropicOpenAI | 63 | 3 | 0 |
| 2025-03-31 | Cisco Talos | Cisco Talos 2024 Year in Review | CAPTCHA bypassCode debugging and scriptingDeepfake video or imageIdentity fraud and impersonationMalware developmentObfuscation and evasionReconnaissance and target research | Critical InfrastructureEducationFinancial ServicesGovernmentLegal ServicesManufacturingNonprofit / NGO | 126 | 123 | 0 |
| 2026-08-04 | Cisco Talos | “Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI | Malware developmentReconnaissance and target researchTranslation and localizationVulnerability research | CryptocurrencyUAT-10147AnthropicGoogleHugging FaceOpenAI | 50 | 7 | 2 |
| 2026-08-20 | Cisco Talos | UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations | Code debugging and scriptingIdentity fraud and impersonationObfuscation and evasionReconnaissance and target researchVulnerability research | EducationGovernmentUAT-10147AnthropicGoogle | 70 | 1 | 0 |
| 2024-05-29 | Microsoft | 2024 State of Multicloud Security Report | EnergyGovernment | 25 | 59 | 0 | |
| 2025 | CERT-EU | CERT-EU - Threat Landscape Report 2025 - A Year In Review | Deepfake video or image | 11 | 3 | 0 | |
| 2025-01-30 | Google Threat Intelligence Group / Mandiant | Adversarial Misuse of Generative AI | Deepfake video or imageIdentity fraud and impersonationMalware developmentObfuscation and evasionReconnaissance and target researchTranslation and localizationVulnerability research | CryptocurrencyDefenseEducationFinancial ServicesGovernmentTelecommunicationsAPT41 | 93 | 4 | 0 |
| 2024-11-15 | Google Threat Intelligence Group / Mandiant | AI Enhancing Your Adversarial Emulation | Reconnaissance and target research | Financial ServicesGovernmentTelecommunicationsUNC6671GoogleOpenAI | 34 | 16 | 0 |
| 2024-07-24 | Google Threat Intelligence Group / Mandiant | AI-Powered Voice Spoofing for Next-Gen Vishing Attacks | CAPTCHA bypassDeepfake video or imageDeepfake voiceIdentity fraud and impersonationReconnaissance and target research | Financial ServicesGovernmentTelecommunicationsUNC6671 | 39 | 1 | 0 |
| 2026-05-12 | Google Threat Intelligence Group / Mandiant | Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access | Autonomous or agentic intrusionCAPTCHA bypassDeepfake video or imageDeepfake voiceExploit developmentIdentity fraud and impersonationMalware development | Financial ServicesGovernmentMediaTelecommunicationsAPT27APT45UNC2814 | 117 | 0 | 0 |
| 2025-05-27 | Google Threat Intelligence Group / Mandiant | Text-to-Malware: How Cybercriminals Weaponize Fake AI-Themed Websites | Obfuscation and evasionReconnaissance and target research | CryptocurrencyFinancial ServicesGovernmentTelecommunicationsUNC6032UNC6671 | 52 | 0 | 38 |
| 2026-04-17 | Google Threat Intelligence Group / Mandiant | Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever | Exploit developmentVulnerability research | Critical InfrastructureFinancial ServicesGovernmentTelecommunicationsUNC6671AnthropicGoogle | 39 | 0 | 0 |
| 2026-02-13 | Google Threat Intelligence Group / Mandiant | GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use | Identity fraud and impersonationMalware developmentObfuscation and evasionPhishing and lure generationReconnaissance and target researchTranslation and localizationVulnerability research | CryptocurrencyDefenseFinancial ServicesGovernmentTelecommunicationsAPT31APT41 | 99 | 0 | 0 |
| 2025-11-06 | Google Threat Intelligence Group / Mandiant | GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools | Deepfake video or imageExploit developmentIdentity fraud and impersonationMalware developmentObfuscation and evasionReconnaissance and target researchTranslation and localization | CryptocurrencyEducationFinancial ServicesGovernmentTelecommunicationsAPT28 / Fancy BearAPT41 | 103 | 0 | 0 |
| 2023-08-17 | Google Threat Intelligence Group / Mandiant | Threat Actors are Interested in Generative AI, but Use Remains Limited | Deepfake video or imageDeepfake voiceIdentity fraud and impersonationInfluence operationsMalware developmentObfuscation and evasionReconnaissance and target research | Financial ServicesGovernmentMediaTelecommunicationsAPT43 / KimsukyAPT43UNC6671 | 65 | 0 | 0 |
| 2026-02-10 | Google Threat Intelligence Group / Mandiant | UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering | Deepfake video or imageReconnaissance and target researchTranslation and localization | CryptocurrencyFinancial ServicesGovernmentTechnologyTelecommunicationsBlueNoroffUNC1069 | 61 | 0 | 16 |
| 2025-04-28 | Fortinet | 2025 Global Threat Landscape Report | Deepfake video or imageIdentity fraud and impersonationMalware developmentObfuscation and evasionPhishing and lure generationReconnaissance and target research | Critical InfrastructureCryptocurrencyFinancial ServicesGovernmentTelecommunicationsAPT28 / Fancy BearAPT29 / Cozy Bear | 107 | 97 | 0 |
| 2025-03-25 | KELA | 2025 AI Threat Report: How Cybercriminals Are Weaponizing AI Technology | Deepfake video or imageDeepfake voiceExploit developmentIdentity fraud and impersonationInfluence operationsMalware developmentPhishing and lure generation | Financial ServicesGovernmentStorm-2139STORM-2139UNC6780AnthropicDeepSeek | 82 | 10 | 0 |
| 2024-10-09 | OpenAI | An update on disrupting deceptive uses of AI | Influence operations | OpenAI | 5 | 0 | 0 |
| 2025-06-05 | OpenAI | Disrupting malicious uses of AI: June 2025 | Influence operations | OpenAI | 7 | 0 | 0 |
| 2025-10-07 | OpenAI | Disrupting malicious uses of AI: October 2025 | Influence operations | OpenAI | 8 | 0 | 4 |
| 2026-02-25 | OpenAI | Disrupting malicious uses of AI | Influence operations | OpenAI | 6 | 0 | 0 |
| 2024-02-14 | OpenAI | Disrupting malicious uses of AI by state-affiliated threat actors | Code debugging and scriptingObfuscation and evasionTranslation and localization | APT43 / KimsukyOpenAI | 20 | 0 | 4 |
| 2025-10-01 | OpenAI | Scam operations: Online fraud networks | Identity fraud and impersonationObfuscation and evasionTranslation and localization | OpenAI | 15 | 0 | 2 |
| 2024-10-01 | OpenAI | STORM-0817: Iran-linked malware and scraping activity | Code debugging and scriptingReconnaissance and target researchTranslation and localization | DefenseEducationGovernmentMediaSweetSpecterSTORM-0817OpenAI | 22 | 0 | 0 |
| 2023-01-06 | Check Point | OPWNAI : Cybercriminals Starting to Use ChatGPT - Check Point Research | Malware development | CryptocurrencyOpenAI | 42 | 0 | 0 |
| 2025-01-10 | Check Point | FunkSec – Alleged Top Ransomware Group Powered by AI - Check Point Research | Identity fraud and impersonationMalware development | AkiraFunkSecOpenAI | 54 | 2 | 9 |
| 2025-05-20 | Check Point | Impersonated GenAI Site Lures Victims to Infostealer Download - Check Point Research | Identity fraud and impersonationObfuscation and evasion | CryptocurrencyFinancial ServicesGoogleOpenAI | 65 | 0 | 36 |
| 2025-04-30 | Check Point | The State of AI in Cyber Security - Check Point Research | Deepfake video or imageDeepfake voiceExploit developmentIdentity fraud and impersonationInfluence operationsMalware developmentTranslation and localization | DeepSeekHugging FaceMicrosoftOpenAI | 67 | 11 | 2 |
| 2026-02-17 | Check Point | AI in the Middle: Turning Web-Based AI Services into C2 Proxies & The Future Of AI Driven Attacks - Check Point Research | CAPTCHA bypassCommand and controlMalware developmentReconnaissance and target researchTranslation and localization | Critical InfrastructureDefenseAnthropicGoogleMicrosoftOpenAIxAI | 72 | 1 | 0 |
| 2026-07-01 | Check Point | Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique - Check Point Research | Malware developmentTranslation and localization | Financial ServicesAnthropicDeepSeekOpenAI | 60 | 0 | 1 |
| 2026-03-30 | Check Point | ChatGPT Data Leakage via a Hidden Outbound Channel in the Code Execution Runtime - Check Point Research | OpenAI | 38 | 0 | 0 | |
| 2025-10-28 | Kaspersky GReAT | BlueNoroff’s latest campaigns: GhostCall and GhostHire | Securelist | CAPTCHA bypassDeepfake video or imageIdentity fraud and impersonationMalware developmentObfuscation and evasionReconnaissance and target research | CryptocurrencyFinancial ServicesTelecommunicationsTransportation and LogisticsAPT43 / KimsukyBlueNoroffLazarus Group | 96 | 2 | 90 |
| 2025-07-30 | Palo Alto Networks Unit 42 | 2025 Unit 42 Global Incident Response Report: Social Engineering Edition | CAPTCHA bypassIdentity fraud and impersonationReconnaissance and target research | Financial ServicesGovernmentRetailTelecommunicationsAnthropic | 65 | 16 | 0 |
| 2025-05-01 | Palo Alto Networks Unit 42 | AI Agents Are Here. So Are the Threats. | CAPTCHA bypassIdentity fraud and impersonation | Anthropic | 45 | 2 | 1 |
| 2026-08-25 | Palo Alto Networks Unit 42 | The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution | CAPTCHA bypassIdentity fraud and impersonationMalware developmentObfuscation and evasionReconnaissance and target research | Artificial IntelligenceCritical InfrastructureCryptocurrencyFunkSecAnthropicOpenAI | 61 | 13 | 12 |
| 2026-03-19 | Palo Alto Networks Unit 42 | Analyzing the Current State of AI Use in Malware | Autonomous or agentic intrusionCAPTCHA bypassMalware developmentObfuscation and evasionReconnaissance and target research | AnthropicOpenAI | 57 | 4 | 4 |
| 2026-07-30 | Palo Alto Networks Unit 42 | Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks | Autonomous or agentic intrusionCAPTCHA bypassExploit developmentPhishing and lure generation | GovernmentAnthropicDeepSeekOpenAI | 66 | 2 | 3 |
| 2026-08-04 | Palo Alto Networks Unit 42 | The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software | Autonomous or agentic intrusionCAPTCHA bypassExploit developmentVulnerability research | AnthropicOpenAI | 44 | 10 | 0 |
| 2025-08-19 | Palo Alto Networks Unit 42 | Fashionable Phishing Bait: GenAI on the Hook | CAPTCHA bypassDeepfake video or imageIdentity fraud and impersonationPhishing and lure generation | Legal ServicesTelecommunicationsAkiraLazarus Group | 40 | 7 | 0 |
| 2026-01-22 | Palo Alto Networks Unit 42 | The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time | CAPTCHA bypassIdentity fraud and impersonationMalware developmentObfuscation and evasionPhishing and lure generationTranslation and localization | CryptocurrencyDefenseAPT28 / Fancy BearAPT28AnthropicDeepSeekGoogle | 62 | 1 | 0 |
| 2026-07-15 | Palo Alto Networks Unit 42 | TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development | CAPTCHA bypassMalware development | CryptocurrencyAnthropic | 74 | 12 | 40 |
| 2025-11-13 | Anthropic | Disrupting the first reported AI-orchestrated cyber espionage campaign | Autonomous or agentic intrusionExploit developmentMalware developmentReconnaissance and target researchVulnerability research | Financial ServicesGovernmentManufacturingAnthropic | 50 | 6 | 0 |
| 2026-06-03 | Anthropic | What we learned mapping a year’s worth of AI-enabled cyber threats | Phishing and lure generation | Financial ServicesGovernmentAnthropic | 24 | 8 | 0 |
| 2025-04-23 | Anthropic | Detecting and countering malicious uses of Claude: March 2025 | Identity fraud and impersonationInfluence operationsMalware development | Artificial IntelligenceFinancial ServicesGovernmentAnthropic | 25 | 0 | 0 |
| 2025-08-27 | Anthropic | Detecting and countering misuse of AI: August 2025 | Reconnaissance and target research | CryptocurrencyFinancial ServicesGovernmentTechnologyTelecommunicationsAnthropic | 35 | 3 | 0 |
| 2026-06-03 | Anthropic | Mapping AI-enabled cyber threats: Insights from the LLM ATT&CK Navigator | Autonomous or agentic intrusionMalware developmentObfuscation and evasionReconnaissance and target research | Critical InfrastructureFinancial ServicesGovernmentAnthropic | 68 | 34 | 0 |
| 2025-04-30 | Check Point | AI Security Report 2025 | Financial ServicesGovernment | 20 | 3 | 2 | |
| 2026-06-23 | CISA | Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite | CISA | Obfuscation and evasionReconnaissance and target research | DefenseGovernmentNonprofit / NGOTA488 | 97 | 5 | 24 |
| 2026-06-23 | CISA | Defending Against an Active Threat to Siemens S7 Series PLCs | CISA | Exploit developmentObfuscation and evasionReconnaissance and target research | Critical InfrastructureEnergyGovernment | 37 | 0 | 0 |
| 2024-08-20 | CrowdStrike | CrowdStrike 2024 Threat Hunting Report: Executive Summary | Obfuscation and evasion | Financial ServicesGovernmentHealthcareHospitalityTechnologyTelecommunicationsTransportation and Logistics | 33 | 42 | 0 |
| 2025-08-04 | CrowdStrike | AI vs AI: The Cybersecurity Arms Race | Command and controlDeepfake video or imageDeepfake voiceIdentity fraud and impersonationObfuscation and evasionReconnaissance and target researchTranslation and localization | Financial ServicesGovernmentAnthropicMicrosoftOpenAI | 65 | 6 | 0 |
| 2024-02-21 | CrowdStrike | 2024 Global Threat Report Trends and Overview | Influence operationsObfuscation and evasionVulnerability research | Financial ServicesGovernmentAnthropicMicrosoftOpenAI | 41 | 12 | 0 |
| 2025-08-04 | CrowdStrike | CrowdStrike 2025 Threat Hunting Report: AI Becomes a Weapon and a Target | Deepfake video or imageIdentity fraud and impersonationMalware developmentObfuscation and evasionPhishing and lure generationVulnerability research | Financial ServicesGovernmentTelecommunicationsAPT42 / Charming KittenFamous ChollimaScattered SpiderAnthropic | 66 | 16 | 0 |
| 2024-09-26 | CrowdStrike | How CrowdStrike Hunts, Identifies and Defeats Cloud-Focused Threats | Obfuscation and evasionVulnerability research | Financial ServicesGovernmentAPT29 / Cozy BearScattered SpiderAnthropicMicrosoftOpenAI | 39 | 8 | 0 |
| 2025 | CrowdStrike | How cyber adversaries use GenAI in vulnerability research and cloud operations | Exploit developmentVulnerability research | Critical InfrastructureGovernment | 22 | 1 | 0 |
| 2025 | CrowdStrike | How adversaries are using GenAI for social engineering attacks | Deepfake video or imagePhishing and lure generation | Famous ChollimaAnthropicGoogleOpenAI | 39 | 4 | 0 |
| 2024-02-21 | CrowdStrike | CrowdStrike 2024 Global Threat Report: Executive Summary | Exploit development | GovernmentAPT28 / Fancy BearAPT29 / Cozy BearScattered Spider | 37 | 18 | 0 |
| 2024-06-27 | ESET | ESET Threat Report: Infostealers using AI & banking malware creating deepfake videos to steal money | Deepfake video or imageIdentity fraud and impersonationTranslation and localization | Critical InfrastructureFinancial ServicesGoogleOpenAI | 25 | 3 | 0 |
| 2024-01 | Europol | Facing reality? Law enforcement and the challenge of deepfakes | Europol | Deepfake video or imageInfluence operations | 13 | 3 | 0 | |
| 2025-12-19 | FBI | Senior U.S. Officials Continue To Be Impersonated in Malicious Messaging Campaign | Federal Bureau of Investigation | Deepfake voiceIdentity fraud and impersonation | CryptocurrencyFinancial ServicesGovernment | 22 | 0 | 0 |
| 2024-11-13 | FinCEN | FinCEN Issues Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions | FinCEN.gov | Deepfake video or image | Financial ServicesGovernment | 13 | 0 | 0 |
| 2023-11-09 | Fortinet | Threat Predictions for 2024: Chained AI and CaaS Operations Give Attackers More “Easy” Buttons Than Ever | FortiGuard Labs | Reconnaissance and target research | EnergyTransportation and Logistics | 18 | 1 | 0 |
| 2025-04-28 | Fortinet | Key Takeaways from the 2025 Global Threat Landscape Report | FortiGuard Labs | Deepfake video or imageMalware developmentReconnaissance and target research | Artificial IntelligenceCritical Infrastructure | 52 | 9 | 0 |
| 2024-11-21 | Fortinet | Cyberthreat Predictions for 2025: An Annual Perspective from FortiGuard Labs | Deepfake video or imageIdentity fraud and impersonationMalware developmentReconnaissance and target research | Critical InfrastructureDefenseEducationEnergyFinancial ServicesGovernmentHealthcare | 61 | 11 | 0 |
| 2025-10-22 | UK Government | International scientific report on the safety of advanced AI: interim report - GOV.UK | Deepfake video or imageDeepfake voiceIdentity fraud and impersonationInfluence operationsObfuscation and evasionTranslation and localizationVulnerability research | Artificial IntelligenceDefenseEducationEnergyFinancial ServicesGovernmentHealthcare | 87 | 50 | 26 |
| 2025-04-02 | IBM X-Force | X-Force Threat Intelligence Index 2024 reveals stolen credentials as top risk, with AI attacks on the horizon | IBM | 18 | 13 | 0 | ||
| 2026-04-30 | IBM X-Force | The adversary didn’t wait. Neither should you. | IBM | Reconnaissance and target researchVulnerability research | 15 | 2 | 0 | |
| 2025-04-04 | IBM X-Force | Hive0137 on an AI journey | IBM | Malware developmentObfuscation and evasionPhishing and lure generationTranslation and localization | HospitalityTA571TA577 | 39 | 4 | 8 |
| 2024-12-03 | FBI IC3 | Internet Crime Complaint Center (IC3) | Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud | Identity fraud and impersonation | CryptocurrencyFinancial ServicesGovernment | 19 | 0 | 0 |
| 2026-08-03 | INTERPOL | INTERPOL report finds AI linked to more than half of cybercrime in Africa | Deepfake video or imageReconnaissance and target research | Financial ServicesMediaTelecommunications | 31 | 1 | 0 |
| 2024-05-22 | Kroll | Q1 2024 Threat Landscape Report: Insider Threat & Phishing Evolve Under AI Auspices | Deepfake video or imageDeepfake voiceIdentity fraud and impersonation | Financial ServicesTelecommunicationsAkiraAPT43 / Kimsuky | 43 | 12 | 0 |
| 2024-02-14 | Microsoft | Staying ahead of threat actors in the age of AI | CAPTCHA bypassIdentity fraud and impersonationMalware developmentObfuscation and evasionReconnaissance and target researchTranslation and localizationVulnerability research | DefenseEducationFinancial ServicesGovernmentNonprofit / NGOTechnologyTransportation and Logistics | 70 | 1 | 0 |
| 2023-11 | Microsoft | Cyber Signals Issue 6: AI Cyber Defense for Threats | Security Insider | Deepfake video or imageDeepfake voiceIdentity fraud and impersonationMalware developmentObfuscation and evasionReconnaissance and target research | DefenseFinancial ServicesGovernmentNonprofit / NGOTechnologyTransportation and LogisticsAPT43 / Kimsuky | 58 | 3 | 1 |
| 2025-05-07 | UK Government | Impact of AI on cyber threat from now to 2027 | National Cyber Security Centre | Exploit developmentInfluence operationsMalware developmentObfuscation and evasionReconnaissance and target researchVulnerability research | EducationGovernment | 42 | 0 | 0 |
| 2024-01-24 | UK Government | The near-term impact of AI on the cyber threat | National Cyber Security Centre | Exploit developmentMalware developmentObfuscation and evasionReconnaissance and target researchTranslation and localizationVulnerability research | EducationGovernment | 36 | 0 | 0 |
| 2025-11-12 | Proofpoint | Operation Endgame Quakes Rhadamanthys | Identity fraud and impersonationObfuscation and evasion | CryptocurrencyFinancial ServicesGovernmentTransportation and LogisticsTA547TA2541TA571 | 55 | 4 | 39 |
| 2024-05-14 | Proofpoint | SugarGh0st RAT Targets American AI Experts | Artificial IntelligenceEducationFinancial ServicesGovernmentMediaTelecommunicationsSweetSpecter | 40 | 4 | 6 | |
| 2024-04-03 | Proofpoint | TA547 Targets German Organizations: Rhadamanthys Stealer | Identity fraud and impersonationMalware developmentPhishing and lure generation | Financial ServicesGovernmentTA547AnthropicGoogleMicrosoftOpenAI | 48 | 0 | 3 |
| 2024-01-22 | Proofpoint | Cyber Threat Landscape 2024: What to Expect | Financial ServicesGovernmentTA473TA577Anthropic | 29 | 0 | 0 | |
| 2025-07-02 | Rapid7 | How Social Engineering Attacks Are Evolving in 2025 | Identity fraud and impersonation | Transportation and LogisticsBlack BastaScattered Spider | 25 | 0 | 0 |
| 2025-06-26 | Rapid7 | How LLMs Like WormGPT Are Reshaping Cybercrime in 2025 | Deepfake video or imageExploit developmentIdentity fraud and impersonationInfluence operationsMalware developmentObfuscation and evasionReconnaissance and target research | Critical InfrastructureHugging FaceMistral AIOpenAIxAI | 52 | 2 | 0 |
| 2025-06-23 | Rapid7 | Emerging Trends in AI-Related Cyberthreats in 2025 - Rapid7 Blog | Deepfake video or imageIdentity fraud and impersonationInfluence operationsMalware developmentObfuscation and evasionReconnaissance and target research | APT28 / Fancy BearAPT31CyberAv3ngersFunkSecLazarus GroupRansomHubSweetSpecter | 55 | 0 | 0 |
| 2025-11-12 | Rapid7 | The Q3 2025 Threat Landscape Report | Deepfake video or imageDeepfake voiceIdentity fraud and impersonationInfluence operationsMalware developmentObfuscation and evasionReconnaissance and target research | Critical InfrastructureCryptocurrencyDefenseFinancial ServicesGovernmentHealthcareLegal Services | 130 | 10 | 0 |
| 2024 | Recorded Future | 2024 Threat Analysis and 2025 Predictions │ Recorded Future Annual Threat Report | Identity fraud and impersonationInfluence operationsObfuscation and evasion | Critical InfrastructureCryptocurrencyTelecommunications | 29 | 2 | 0 |
| 2025-10-24 | Recorded Future | 2025 Cloud Threat Hunting and Defense Landscape | Identity fraud and impersonationObfuscation and evasionReconnaissance and target researchTranslation and localizationVulnerability research | CryptocurrencyEducationFinancial ServicesGovernmentTelecommunicationsTransportation and LogisticsAPT28 / Fancy Bear | 112 | 7 | 4 |
| 2025 | Recorded Future | 2025 Year in Review: Malicious Infrastructure | 17 | 1 | 0 | ||
| Unknown | Recorded Future | Adversarial Intelligence: Red Teaming Malicious Use Cases for AI | Deepfake video or imageIdentity fraud and impersonationInfluence operationsObfuscation and evasionReconnaissance and target researchTranslation and localization | 21 | 0 | 0 | |
| Unknown | Recorded Future | Emerging Enterprise Security Risks of AI | Malware development | 22 | 3 | 0 | |
| 2022-11-30 | Recorded Future | I, Chatbot | Recorded Future | Influence operationsMalware developmentTranslation and localization | MediaOpenAI | 33 | 0 | 0 |
| 2023-01-26 | Recorded Future | I Have No Mouth, and I Must Do Crime | Recorded Future | Deepfake video or imageDeepfake voiceIdentity fraud and impersonationInfluence operations | 20 | 0 | 1 | |
| 2025-04-09 | SentinelOne | AkiraBot | AI-Powered Bot Bypasses CAPTCHAs, Spams Websites At Scale | SentinelOne | CAPTCHA bypass | Financial ServicesTelecommunicationsAkiraOpenAI | 33 | 6 | 64 |
| 2023-11-07 | SentinelOne | Predator AI | ChatGPT-Powered Infostealer Takes Aim at Cloud Platforms | SentinelOne | TelecommunicationsOpenAI | 28 | 0 | 2 | |
| 2025-09-19 | SentinelOne | Prompts as Code & Embedded Keys | The Hunt for LLM-Enabled Malware | SentinelOne | Malware developmentObfuscation and evasionTranslation and localizationVulnerability research | EducationTelecommunicationsAPT28 / Fancy BearAPT28AnthropicDeepSeekGoogle | 55 | 2 | 39 |
| 2025-04-16 | Sophos | The Sophos Annual Threat Report: Cybercrime on Main Street 2025 | Obfuscation and evasion | CryptocurrencyAkiraRansomHubOpenAI | 73 | 13 | 0 |
| 2025-02-04 | ThreatDown / Malwarebytes | ThreatDown State of Malware Report 2025: Autonomous AI and Ransomware | HealthcareOpenAIxAI | 19 | 6 | 0 | |
| 2026-04-16 | Trend Micro | 2025 APT Report: Staying Ahead of the Modern Threat Landscape | Reconnaissance and target research | Government | 30 | 1 | 0 |
| 2023-08 | Trend Micro | Back to the Hype: An Update on How Cybercriminals Are Using GenAI | Deepfake video or imageIdentity fraud and impersonationTranslation and localization | CryptocurrencyEducationFinancial ServicesGovernmentHugging FaceOpenAI | 30 | 5 | 0 |
| 2023-04-17 | Trend Micro | Hype vs. Reality: AI in the Cybercriminal Underground | Deepfake video or imageMalware development | GoogleMetaOpenAI | 30 | 11 | 0 |
| 2025-09 | UNODC | Emerging threats: The intersection of criminal and technological innovation in the use of automation and artificial intelligence in the cybercrime landscape of Southeast Asia | CAPTCHA bypassDeepfake video or imageDeepfake voiceIdentity fraud and impersonationInfluence operationsMalware developmentObfuscation and evasion | CryptocurrencyEducationFinancial ServicesGovernmentHealthcareHospitalityTechnology | 85 | 11 | 0 |
| Unknown | USENIX | Malla: Demystifying Real-world Large Language Model Integrated Malicious Services | USENIX | EducationHospitality | 4 | 0 | 0 | |
| 2025-03-20 | Zscaler ThreatLabz | ThreatLabz 2025 AI Security Report | Autonomous or agentic intrusionDeepfake video or imageDeepfake voiceIdentity fraud and impersonationObfuscation and evasionPhishing and lure generationReconnaissance and target research | Artificial IntelligenceFinancial ServicesGovernmentHealthcareTransportation and LogisticsAnthropicDeepSeek | 92 | 143 | 0 |
| No publications match the current filters. | |||||||
Reproducible research
Use the publication table for analysis-ready records and the long-form tables for reproducible aggregation. Candidate tags, metrics, and IOCs remain analyst-review inputs rather than validated operational intelligence. Review the governed dataset landing page for schemas, provenance, file sizes, spreadsheet safeguards, and interpretation limits.