Adversaries Exploiting Proprietary AI Capabilities, API Traffic to Scale Cyberattacks
ID: 4c609cfc-fb9c-5c62-a212-e80a9c2d3957
STIX ID: report--4c609cfc-fb9c-5c62-a212-e80a9c2d3957
Feed Name: The Cyber Express
GTIG observed a significant increase in threat actors abusing large language models throughout 2025 for reconnaissance, social engineering, malware development, and intellectual-property theft via model extraction. State-linked APTs and criminal groups used LLMs to gather OSINT, craft targeted phishing, automate vulnerability analysis, and generate code for in-memory malware (e.g., HONESTCUE) and phishing kits (e.g., COINBAIT); underground services also resold AI-driven attack tooling, with Google mitigating exposed assets and monitoring repeated probing and exploitation attempts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
