Artificial intelligence tools have become integrated into real-world cyberattacks, spanning from initial reconnaissance to the creation of malicious code. This is highlighted in a report by F6, which covers the years 2025 and the first half of 2026.
AI in Attacks
According to analysts, at least 18 advanced persistent threat (APT) groups have conducted attacks utilizing AI over the past 18 months. The F6 report details several documented instances of AI's application in these attacks.
The GTG-1002 group employed language models to generate phishing emails, tailoring the text to specific victims in a way that bypassed standard spam filters. Meanwhile, the TAT26-12 cluster utilized AI to automate reconnaissance, gathering information about employees, infrastructure, and organizational vulnerabilities.
Additionally, a specialized software called PromptSpy was noted for its ability to autonomously take control of devices for malicious actions, built upon large language models (LLM). Another tool, LAMEHUG, was used to generate malicious code with minimal human intervention.
Discussions on Forums
Researchers have observed an uptick in discussions among hackers regarding various AI models on specialized forums.
While OpenAI's ChatGPT has emerged as the most popular choice among novice hackers, Google’s Gemini is more frequently utilized in actual attacks.
Frequency of AI solutions mentioned on dark forums. Source: F6.Forum participants are actively discussing methods to bypass restrictions on these models, with some attempting to create malicious applications using publicly available AI.
Source: F6.Evolving Ransomware Tactics
During the monitored period, over 50 new groups distributing ransomware emerged, alongside more than 9,300 related incidents.
A notable trend is the shift away from data locking as a primary pressure tactic. Instead, attackers are now focusing on the threat of publishing stolen information, which lowers the technical demands of the attack and complicates defenses.
Over the last 18 months, six major shadow marketplaces for data trading were shut down, but five new ones have since appeared.
Current card shops are reported to have over 16.5 million compromised payment cards available for sale.
In August, OpenAI slowed down the development of advanced AI systems following an incident involving Hugging Face and a preliminary assessment from Astra.
