logo

Cybercriminal abuse of large language models

ID: 7d699e57-166f-5096-84cd-076a162f6ad8

STIX ID: report--7d699e57-166f-5096-84cd-076a162f6ad8

Feed Name: Cisco Talos

Threat Score
55/100

Date Published: 2025-06-25

Date Updated: 2026-04-27

Author: Jaeson Schultz

...
...

This Cisco Talos report explains that cybercriminals are increasingly leveraging LLMs—via uncensored models, criminally marketed LLMs, and jailbreak techniques—to generate phishing content, write malware, validate stolen cards, and automate reconnaissance, while attackers also target the LLM supply chain (e.g., backdoored models, pickle deserialization risks) and RAG datasets to poison outputs; the technology acts as a force multiplier rather than introducing wholly novel cyberweapons.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.