How Is AI Being Used in Cyberattacks?
Every cybersecurity conversation right now seems to circle back to artificial intelligence — usually framed as the newest, sharpest tool in a defender’s kit. That framing is only half the story. The same technology reshaping detection and response is being weaponized on the other side of the fight, and the shift has happened faster than most security frameworks can keep pace with.
This isn’t speculative. It’s the documented threat environment of 2026.
From Experimental to Operational
AI in cybersecurity has moved from an experimental practice to an operational necessity — it now forms part of the backbone of how organizations detect attacks, predict threats, and respond before damage spreads. But that same capability cuts both ways. Attackers are using AI to craft more convincing phishing emails, build malware that evades detection, and automate attacks at machine speed.
Industry surveys reflect just how mainstream this has become: recent reporting citing World Economic Forum data found the overwhelming majority of organizations now consider AI the single biggest force shaping the cybersecurity landscape this year.
Where Attackers Are Actually Using It
Break it down into three categories, and a clearer picture emerges.
1. Reconnaissance and Exploit Development
This is where AI adoption among attackers is most mature. A recent Anthropic analysis of banned malicious accounts, mapped against the MITRE ATT&CK framework, found that roughly two-thirds of the threat actors studied used AI for initial reconnaissance and malware development. A smaller but meaningful share — around 6.5% — went further, using AI to assist with lateral movement once inside a compromised network.
That gap between “AI for recon” and “AI for post-exploitation” matters. It tells us attackers have largely automated the front end of an intrusion — finding weaknesses and building tools to exploit them — while the harder, more judgment-dependent stages still lean on human operators.
2. Social Engineering at Scale
Phishing used to be a numbers game: blast a generic message to as many inboxes as possible and wait for someone to click. AI has changed that math. Attacks are increasingly built on behavioral data, trained to mimic a specific person’s writing style, and in a growing number of cases, supported by deep-fake voice or video. The result is social engineering that’s harder to catch on instinct alone, because it no longer reads like the broken-English scam email your spam filter was trained on.
3. Autonomous Attack Chains
This is the development worth paying closest attention to. Security researchers are tracking a new generation of AI-augmented offensive tooling:
- Villager layers LLM-based automation on top of CobaltStrike, a widely used (and frequently abused) offensive security toolkit.
- HexStrike AI goes further — it’s not a single tool but a framework that orchestrates and automates roughly 150 other attack tools, effectively giving one operator the reach of a much larger team.
- Anthropic itself reported identifying a framework built by Chinese state-linked actors to run large-scale automated cyberattacks by abusing Claude — a notable example of a frontier AI lab publicly disclosing misuse of its own model.
How Worried Should You Actually Be?
It’s easy to read the above and picture fully autonomous malware sweeping the internet unsupervised. That’s not quite where things stand yet. Human-AI collaboration remains the dominant model for real-world cyber operations: humans still provide strategic direction, break complex operations into manageable subtasks, and intervene when the AI makes a mistake, while the AI handles narrower technical work like code generation or target identification.
Even threat intelligence experts disagree on how fast that changes. One threat intelligence lead at Armis has predicted a major enterprise breach caused by a fully autonomous agentic AI system by mid-2026. The UK’s National Cyber Security Centre takes a more measured view, assessing that fully automated, end-to-end advanced cyberattacks are unlikely before 2027 — though it agrees that skilled attackers will keep automating pieces of the attack chain in the meantime.
The Real Takeaway
AI hasn’t invented a new category of cyberattack. Phishing, malware, credential theft, and lateral movement are still phishing, malware, credential theft, and lateral movement. What’s changed is speed, scale, and accessibility — attacks that once required a skilled operator and real time investment can now be assembled faster, run with less expertise, and adapted on the fly based on how a target’s defenses respond.
For organizations still relying on static, once-a-year security training and legacy detection rules, that gap is the real exposure. The question isn’t whether your adversaries have started using AI — that’s already answered. It’s whether your defenses have caught up.
Queen City Cyber Consulting tracks developments like these every week. If your organization’s defenses haven’t kept pace with how attackers are actually operating in 2026, let’s talk.
Leave a Reply