The same artificial intelligence platforms that businesses use to draft emails, develop software, and automate routine tasks are increasingly being leveraged by cybercriminals. These tools are helping threat actors create malware, launch highly convincing phishing campaigns at scale, and automate attacks that previously required the resources and expertise of entire teams. This is no longer a theoretical concern or a future scenario—it is an operational reality unfolding today.
In early 2025, three teenagers with no prior programming experience used an AI-powered chatbot to develop an automated attack tool that generated approximately 220,000 requests against a major telecommunications provider. The operation was reportedly successful enough to fund purchases of gaming equipment and other consumer goods. Just a few months later, a lone threat actor used an AI coding assistant to conduct an extortion campaign targeting 17 organizations within a single month. The AI system was used throughout the operation to generate malicious code, organize and analyze stolen data, review financial records to determine ransom amounts, and even draft the extortion communications sent to victims. In both cases, sophisticated criminal infrastructure was unnecessary. Advanced technical skills were largely absent. Artificial intelligence filled the gap.
These incidents are not isolated events. Instead, they illustrate a broader transformation that cybersecurity researchers have been observing since generative AI and large language models became widely available. Historically, successful cyberattacks demanded significant technical expertise. Attackers needed a deep understanding of programming languages, operating systems, networking technologies, exploitation techniques, and methods for evading security controls. Developing custom malware often required weeks of specialized work, while large-scale phishing operations depended on teams of developers, content creators, and language specialists. Artificial intelligence is steadily removing many of these barriers, enabling less experienced individuals to perform activities that once required seasoned cybercriminals and well-organized groups. As a result, the barrier to entry for cybercrime continues to fall while the scale, speed, and sophistication of attacks continue to rise.
Is Anyone Can Write Malware Now?
The technical hurdles that once limited the development of malicious software have been significantly reduced by advances in artificial intelligence. Modern large language models are capable of generating functional PowerShell scripts, Python-based attack frameworks, JavaScript downloaders, Visual Basic macros, and code that interacts directly with Windows APIs within seconds. Tasks that previously required extensive programming knowledge and experience can now be performed with simple natural-language instructions. Although leading AI providers have implemented safeguards designed to prevent misuse, threat actors have demonstrated numerous methods for circumventing these controls. These include jailbreaking commercial models, modifying open-source models with fewer restrictions, and adopting AI systems specifically developed for offensive cyber activities.
As demand for these capabilities has grown, an underground ecosystem has emerged to support cybercriminal operations. Specialized AI platforms such as WormGPT and FraudGPT have been openly marketed within criminal forums as tools for offensive cyber activity. Unlike legitimate AI assistants, these systems are designed to respond without the ethical and security restrictions imposed by mainstream providers. Early versions of WormGPT were reportedly based on open-source language models and trained using datasets containing malware development techniques, phishing content, and other cybercrime-related material. Threat actors have used these tools to generate convincing phishing lures, create business email compromise content, automate social engineering campaigns, and assist in the development of malware capable of changing its characteristics to evade detection.
The evolution of these criminal AI platforms has accelerated rapidly. Security researchers have identified newer variants of WormGPT that leverage the capabilities of commercial-grade models while removing the safeguards intended to prevent abuse. In some cases, operators have repackaged powerful mainstream AI technologies, customized them for malicious use, and made them available through subscription-based services at relatively low cost. Rather than representing entirely new technological breakthroughs, many of these underground offerings are effectively modified versions of widely available AI systems, optimized to support cybercrime. The result is a growing marketplace where sophisticated offensive capabilities can be acquired with minimal investment, further lowering the barrier to entry for aspiring threat actors and enabling cybercriminal operations to scale faster than ever before.
WormGPT, FraudGPT, DarkBERT, and their successors form a growing market of AI tools sold specifically to criminals. They do not require technical expertise to use. They come with subscription models, customer support, and continuous updates, mirroring the same software-as-a-service model used by legitimate technology companies. Trend Micro describes this shift as moving from experimentation to industrialization: criminals no longer build the weapon, they rent it.
For malware developers already working in this space, AI serves as an accelerator. Instead of spending days researching Windows internals, persistence mechanisms, or network communication protocols, a developer can generate a working foundation and modify it for their specific operation. This compresses development cycles dramatically and allows for much more rapid experimentation with new techniques.
Phishing Campaigns Become More Convincing
Before AI, phishing emails were easy to spot if you knew what to look for. Awkward grammar, generic greetings, mistranslations, and implausible scenarios gave them away. Security awareness training was built around teaching people to notice these signals. That playbook is now significantly less reliable.
Language models produce professionally written text by default. Criminals can generate phishing messages that read exactly like internal company communications, match the tone and vocabulary of specific industries, and incorporate details scraped from public sources including LinkedIn profiles, corporate websites, press releases, and previously breached data. A target might receive a message that references a real colleague by name, mentions an ongoing project, and uses the company’s actual internal formatting conventions. Everbridge’s 2026 threat analysis confirmed that in 2025, AI-generated phishing began outperforming human red teams entirely in terms of click-through rates.
The personalization that used to define high-value spear-phishing campaigns targeting executives is now available at scale. What required a dedicated analyst and hours of research per target can be automated across thousands of victims simultaneously.
AI-generated phishing is not limited to text. Deepfake audio and video are increasingly being used to impersonate executives in business email compromise (BEC) scams. Employees receive what sounds like a real phone call or video message from a known senior leader, asking them to authorize a transfer or share credentials. These AI-supported campaigns operate at a level of apparent authenticity that is difficult for both humans and traditional security tools to detect.
Malware That Adapts During Execution
One of the most important technical developments highlighted in recent research is the appearance of malware that leverages artificial intelligence during an attack, rather than relying solely on AI during its development phase.
Researchers from Google’s Threat Intelligence Group identified malware families known as PROMPTFLUX and PROMPTSTEAL that interact with language models while actively running on compromised systems. Instead of depending entirely on pre-programmed logic, these threats can request new instructions or generate modified code in response to the environment they encounter. This enables them to adjust their behavior dynamically and potentially reduce the effectiveness of traditional detection and analysis techniques. For defenders, this represents a fundamentally different challenge from conventional malware, which typically operates according to a fixed and predictable set of instructions.

A similar trend was documented in Mandiant’s M-Trends 2026 report with the discovery of QUIETVAULT, a credential-stealing malware family that searches compromised systems for locally installed AI command-line tools. Once identified, the malware uses predefined prompts to locate sensitive configuration files, credentials, and other valuable information. In this case, artificial intelligence effectively serves as an automated search and analysis mechanism operating within the victim’s own environment, helping the malware identify and extract data more efficiently.
Google Threat Intelligence Group identified PROMPTFLUX and PROMPTSTEAL as the first confirmed malware families to query language models during execution. This represents a new operational phase of AI abuse. Instead of static code that defenders can analyze, reverse-engineer, and write signatures for, these tools generate their behavior dynamically. The implications for detection and analysis are significant, because the malware that arrives on a system is not the malware that executes.
Traditional malware families often remained relatively stable because rewriting them took substantial effort. AI-assisted development changes that. A developer can generate many versions of the same tool while varying the code structure, variable names, execution sequence, and communication methods. Each variant may perform identical functions but look completely different to a detection system. Security vendors have increasingly observed malicious scripts with coding patterns inconsistent with human-authored malware, characterized by unusual stylistic mixing and structural choices that reflect AI generation rather than a single developer’s habits.
Constructing Entire Deceptive Ecosystems
Successful cyber operations require far more than malware development. Attackers often need convincing phishing websites, realistic login portals for credential harvesting, fabricated organizations to create an appearance of legitimacy, social media profiles to build trust, and supporting documentation to reinforce their campaigns. Historically, creating and maintaining this infrastructure demanded a range of specialized skills, including web development, content creation, graphic design, translation, and social engineering expertise.
Generative AI has dramatically simplified this process. A single threat actor can now create a highly convincing website impersonating a government agency, financial institution, or corporate brand, complete with professional privacy policies, support portals, terms of service, and frequently asked questions. The same individual can generate social media content, produce employment advertisements that enhance the credibility of a fictitious organization, and create realistic email conversations that support long-term deception campaigns. Tasks that once required multiple specialists can now be accomplished through a series of carefully crafted prompts.
This capability has attracted significant attention from the cybersecurity research community. Researchers at the Indian Institute of Technology (IIT) Kanpur evaluated the ability of large language models, including ChatGPT and Google’s Bard, to generate attack-related content aligned with widely observed adversary techniques. Their findings indicated that these systems were capable of producing functional code associated with many commonly used attack methods. The researchers concluded that large language models can substantially expand the capabilities of less experienced attackers while also accelerating the development of more sophisticated offensive tools, including those used in ransomware operations.
Social Engineering Through Persistent Adaptive Conversations
Traditional social engineering attacks typically depended on a single interaction. A target would receive an email, text message, or phone call, and the success of the operation often hinged on an immediate decision—whether the recipient clicked a link, opened an attachment, or responded to a request. Artificial intelligence is enabling a different and far more dynamic approach.
Modern AI systems allow threat actors to conduct long-running conversations that can continue across email, chat platforms, messaging applications, and other communication channels for days or even weeks. Rather than relying on a fixed script, these systems can continuously adapt their responses based on the victim’s reactions, communication style, and level of engagement. The objective is to gradually establish credibility, build trust, and create a believable context before ultimately requesting something of value, such as login credentials, sensitive documents, financial transfers, or interaction with a malicious link.
Because AI-generated responses can be highly contextual and conversational, these interactions often appear authentic and natural. The system can answer questions, address concerns, and modify its approach in real time, creating an experience that closely resembles communication with a legitimate person. This level of adaptability makes such campaigns significantly more convincing than traditional social engineering techniques based on static templates and prewritten messages.
Security researchers have identified this trend as one of the most challenging developments for awareness and training programs. Unlike conventional phishing attempts that often contain obvious warning signs, AI-driven conversational attacks can remain consistent, responsive, and believable throughout the entire engagement. As a result, individuals may find it increasingly difficult to distinguish between legitimate communications and carefully orchestrated deception campaigns that evolve continuously over time.
Attribution Is Becoming More Difficult
One of the lesser-discussed consequences of AI-assisted cybercrime is its impact on threat attribution. Security researchers have traditionally identified threat actors by examining coding styles, infrastructure reuse, language patterns, and other operational characteristics that remain consistent across campaigns. AI-generated content is weakening many of these indicators.
When multiple threat actors rely on the same language models, their code, phishing content, and operational artifacts can appear remarkably similar despite having no direct connection. Conversely, a single attacker can generate substantially different outputs from one campaign to another simply by changing prompts, coding styles, or languages. The distinctive fingerprints that developers typically leave behind—such as naming conventions, coding habits, and structural preferences—are often absent or intentionally obscured in AI-generated output.
As AI tools continue to proliferate within the cybercriminal ecosystem, distinguishing one threat actor from another is becoming increasingly challenging, complicating efforts to accurately attribute attacks and track adversary activity.
What This Means for Defenders
The primary concern for defenders is not that artificial intelligence will replace cybercriminals, but that it will dramatically increase their reach, efficiency, and scale. Small groups and even individual threat actors can now execute campaigns with a level of sophistication and volume that previously required large, well-resourced organizations. This acceleration is evident in Mandiant’s observation that the median time between initial compromise and handoff to another threat actor dropped from eight hours in 2022 to just 22 seconds by 2025, illustrating how rapidly modern attacks can now progress.
Researchers at Google’s Threat Intelligence Group note that AI has evolved from an occasional productivity aid into a technology embedded throughout the entire attack lifecycle. It is increasingly used for reconnaissance, social engineering, malware development, infrastructure management, and post-compromise data analysis. Trend Micro has characterized this shift as the difference between building offensive capabilities and simply renting them. As powerful AI-driven tools become inexpensive, widely accessible, and ready to use, the number of individuals capable of conducting sophisticated cyberattacks continues to grow, fundamentally reshaping the threat landscape.
AI has transformed cybercrime from a game of skill to a game of scale. Understanding how attackers are using these tools is now just as important as understanding the malware itself, because the malware is just one output of a much larger AI-assisted production pipeline.
Shawnee Delaney, CEO of Vaillance Group and former counterintelligence officer, at Rapid7’s Take Command Virtual Summit 2025
References
Industry threat reports
1. Google Cloud / Mandiant — M-Trends 2026: Data, Insights, and Strategies From the Frontlines (March 2026)
Documents PROMPTFLUX, PROMPTSTEAL, and QUIETVAULT; reports 22-second handoff collapse.
https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026/
2. Google Threat Intelligence Group (GTIG) — AI Threat Tracker: Advances in Threat Actor Usage of AI Tools (November 2025)
First identification of just-in-time AI malware families querying LLMs during execution.
https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools/
3. Trend Micro TrendAI Research — The State of Criminal AI: Crime as a Service, AI as the Multiplier (January 2026)
Comprehensive analysis of criminal LLM ecosystem, WormGPT variants, and industrialization of AI-powered cybercrime.
https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/the-state-of-criminal-ai
4. Rapid7 — AI Goes on Offense: How LLMs Are Redefining the Cybercrime Landscape (June 2025)
Covers WormGPT, FraudGPT, dark web subscription pricing, and democratization of attack capabilities.
https://www.rapid7.com/blog/post/ai-goes-on-offense-how-llms-are-redefining-the-cybercrime-landscape/
5. Everbridge — AI and the 2026 Threat Landscape (January 2026)
2025 AI-phishing vs red team performance data; deepfake-enabled BEC analysis; first large-scale AI-orchestrated attack campaigns.
https://www.everbridge.com/blog/ai-and-the-2026-threat-landscape/
6. The Hacker News — 2026: The Year of AI-Assisted Attacks (May 2026)
Documents the teenager attack case, the single-actor extortion campaign, and quantitative increases in AI-related cybercrime metrics.
https://thehackernews.com/2026/05/2026-year-of-ai-assisted-attacks.html
Academic research
7. P.V. Sai Charan et al., IIT Kanpur — From Text to MITRE Techniques: Exploring the Malicious Use of Large Language Models for Generating Cyber Attack Payloads (2023, arXiv:2305.15336) Systematically generated MITRE top-10 attack payloads using ChatGPT and Bard; concluded that LLMs significantly benefit ransomware operators.
https://arxiv.org/pdf/2305.15336
8. Zilong Lin, Zichuan Li et al., UIUC / UMKC — Consiglieres in the Shadow: Understanding the Use of Uncensored Large Language Models in Cybercrimes (arXiv:2508.12622) Identified 173 confirmed uncensored LLMs operating as backends for criminal services from 98 open-source base models.
https://arxiv.org/pdf/2508.12622
9. Guo W. et al. — A Survey on Malware Analysis with Large Language Models. In: Knowledge Science, Engineering and Management, KSEM 2025. Springer, Singapore (2026)
https://link.springer.com/chapter/10.1007/978-981-95-3072-4_4
This article is provided for informational and educational purposes. The named malware families PROMPTFLUX, PROMPTSTEAL, and QUIETVAULT are documented in publicly released Mandiant and Google Threat Intelligence Group research. Criminal LLM tools including WormGPT and FraudGPT are documented in published industry and academic reporting. The real-world attack cases cited are sourced from The Hacker News and Rapid7.