Cyber threat actors are increasingly exploiting generative AI tools such as ChatGPT and Google’s Gemini to enhance their cyberattack capabilities, recent reports reveal. These AI models, initially created for legitimate purposes like content creation and customer support, are now being manipulated to craft more convincing phishing emails, automate social engineering campaigns, and even generate malicious code snippets. This shift highlights a growing trend where cybercriminals leverage easily accessible AI technology to scale their operations with increased sophistication and efficiency.

The misuse of AI tools comes at a time when the cyber threat landscape is becoming more complex, fueled by the abundance of accessible AI APIs and open-source models. Groups like those behind the GreyVibe campaign reportedly use platforms like ChatGPT and Google Gemini to automate parts of their attack workflows, minimizing the need for extensive manual labor. Cybersecurity researchers note that these tactics allow attackers to produce more personalized and persuasive messages at a higher volume, boosting the likelihood of successful breaches. This trend signals a need for security teams to reevaluate their defenses against AI-enhanced threats and modify their detection strategies.

Advertisement

CyberTech Your brand belongs here. Reach the decision-makers who read CyberTech every day. Premium placements across the site and newsletter. Advertise with us

While detailed information on the scale of these operations is limited, some reports suggest that hacking groups have successfully integrated AI-generated content into their campaigns, leading to a spike in phishing attempts and malware distribution. The use of AI models for malicious purposes is facilitated by the widespread availability of AI APIs, which often lack strict usage controls. This raises concerns about the potential for AI to be weaponized on a large scale, with cybercriminals exploiting vulnerabilities in AI platforms or abusing open-access models. Defenders face the added challenge of distinguishing between human and AI-generated malicious communications.

A cybersecurity expert from a leading threat intelligence firm commented, “The adoption of AI tools by threat actors represents a significant escalation in their operational capabilities. We are seeing more automated, targeted, and convincing attacks that are harder to detect and block.” This development underscores the need for security operators to implement advanced behavioral analytics and AI-specific detection mechanisms capable of identifying anomalies in communication patterns and content authenticity. Organizations are also advised to bolster their training programs, focusing on awareness of AI-facilitated social engineering tactics.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

The growing exploitation of AI tools by cybercriminals presents a critical challenge for security practitioners: protecting AI platforms themselves from misuse. As AI models become more accessible, platform providers and organizations need to enforce stricter access controls, monitor API usage for suspicious activity, and create countermeasures to identify AI-generated malicious payloads. For security buyers, this means investing in layered defenses that incorporate not only traditional security controls but also AI-aware detection systems that can adapt to evolving threat vectors. This trend marks a new phase in cybercrime, where AI serves both as a tool for defenders and an instrument for attackers, requiring increased vigilance and proactive defense strategies.

Source: bleepingcomputer.com