In November 2025, Anthropic, the Amazon and Google-backed AI firm behind Claude, came out with a startling claim: a Chinese state-sponsored group was using its chatbot’s coding capabilities to execute cyberattacks almost autonomously.
Quite an accusation, with the tool believed to have been used to target other large tech firms, as well as financial institutions, and even government agencies. The AI firm claimed it was the first documented case of a large-scale cyberattack executed without substantial human intervention.
Anthropic contended the Claude Coding tool was “manipulated” into supporting the espionage campaign, an event preceded by a report from Google’s Threat Intelligence Group that both government-backed threat actors and generalist cyber criminals are experimenting with AI – including using large language models (LLMs) to execute malware.
Things further escalated when Anthropic reared its head once again, just a few weeks later, to reveal that researchers from its Frontier Red Team found that AI can be used to exploit the blockchain. Specifically, they found that AI agents can be used to uncover zero-day vulnerabilities and exploits in blockchain smart contracts collectively worth $4.6 million.
Each of these revelations was met with a range of reactions, from hype-induced prognoses of Terminator proportions to outright skepticism and assertions of balderdash.
But what’s the real deal? Are we getting to a point where hackers are going to use AI to slowly but surely circumvent every defense we throw at it? Is this more a case of actors simply using capabilities, as they have with past technical advances? Or is this entire concern overblown, meaning the money in our wallets is perfectly safe ... if only we could remember where we put the darned thing?
Attackers using AI: An abridged history
In the years prior to the dawn of the decade, cases of malicious uses of AI were largely as hypothetical as the technology itself, with early examples of automation distinctly different from the powerful capabilities of modern AI.
But with the proliferation of Transformer models and ChatGPT, malicious uses slowly but steadily began to rise.
Despite being banned in places like North Korea, Russia, and Iran by OpenAI, nation-state actors were found to have gained circumventive access to the chatbot as they sought to augment their attacking abilities.
Hackers linked to Iran’s Islamic Revolutionary Guard, for example, were found to have used large language models to create phishing emails in a Microsoft Threat Intelligence Center (MSTIC) report dated February 2024. While Kimsuky, a North Korean hacking group that also goes by Emerald Sleet or Black Banshee, was found to have used OpenAI services to identify potential defense targets from across Asia Pacific.
While these early examples stemmed from the spread of generative AI, the technology has been sprinkled across attacks as early as 2018. TaskRabbit, the commoditized services platform owned by Ikea, was the subject of a breach where AI was used to control a massive botnet that performed a distributed denial-of-service (DDoS) attack on its servers.
The result? Names, passwords, and payment details of both clients and ‘taskers’ were stolen in an attack that employed machine learning to make it more efficient and ultimately effective than a simple automated script.
In the geological timescale of AI-powered cyber threats, then, 2018’s TaskRabbit incident can be viewed as effectively the Precambrian age: the initial, foundational era of activity that set the stage for an explosive period set to follow.
Not quite the Cambrian explosion
So, after TaskRabbit and the rise of generative AI, have we quite reached the Cambrian explosion equivalent of threat actors using AI? Not quite.
According to Adam Meyers, head of counter adversary operations at CrowdStrike, the current landscape is more nuanced than headlines might suggest. “Right now, where we're at is where the more technically capable adversaries are benefiting from the use of AI,” he explained to SDxCentral.
The most sophisticated example Meyers pointed to comes from Fancy Bear, a group with links to Russia's military intelligence agency, the GRU. They developed something called LameHug, a Python installer with no malicious code embedded in it. Instead, it contained prompts that reached out to the Hugging Face API, instructing it to “write Python code to profile the system” or “go through the hosts and find interesting files and then bundle them up for data exfil,” with the generated code executing on target systems.
“Nothing really detectable in that,” Meyers noted. “And I think that's probably the most advanced use of AI in terms of malware operations that we've seen.”
LameHug was found to have targeted security and defense points in Ukraine. The CERT-UA, the country’s national computer emergency response team, caught the campaign, which sought to disseminate emails containing its malicious software. Even the command and control infrastructure that hosted LameHug was legitimate, but featured compromised resources.
“Certainly we've seen it for disinformation, misinformation,” he said, adding that North Korean actors were also using AI to support their Famous Chollima operation (also known as BadClone) in which operatives falsify identities to earn legitimate salaries from remote IT roles, which are then used to fund the regime.
The picture isn't uniformly alarming, however, with Meyers suggesting less sophisticated actors are actually using AI “to their detriment.” He pointed to a group that created malware called Funk Walker using an adversarial LLM called Worm GPT. “There was broken cryptography in that, and the adversary left their name in it,” he explained. “That's kind of on the lower end of the sophistication spectrum.”
The reality, then, is a split between highly capable state actors leveraging AI for genuine operational advantages, to less skilled criminals whose efforts to get a leg up via AI assistance have the potential to backfire through either technical failures or operational security mistakes that make them that bit easier to track.
But there’s another, more mundane way threat actors are using AI, essentially as a slightly more sophisticated replacement for Google searches during operations. They’ll ask chatbots to generate PowerShell scripts or other basic code snippets on the fly. These everyday uses, while less sensational, represent the bulk of how AI is currently being integrated into cybercriminal workflows.
From theory to practice
Meyers' observations about sophisticated attackers versus stumbling stooges proved prescient, as shortly after his conversation with SDxCentral, Anthropic would reveal its dramatic cyber espionage save.
Yet even this apparently sophisticated operation wasn't quite the autonomous apocalypse some headlines might suggest. According to a Forrester analysis of Anthropic's findings, humans were still providing direction at critical junctions, and significant limitations emerged.
“Claude frequently overstated findings and occasionally fabricated data during autonomous operations, claiming to have obtained credentials that didn't work or identifying critical discoveries that proved to be publicly available information,” the analysts quoted from Anthropic’s own report.
The AI lab even found that every claimed result required careful validation, presenting what Anthropic called “an obstacle to fully autonomous cyberattacks,” with the analyst report adding: “Ironically, this means that attackers may have to confront the same AI trust issues as defenders.”
The Forrester analysts did, however, emphasize that while the use of AI was novel, the underlying tactics and techniques were not. The real value lay in the potential for attacks to become constant, high-volume, and eventually automated to not require human oversight.
The campaign Anthropic disrupted leaned heavily on a “harvest credentials, test, pivot” loop, the kind of repetitive work where AI excels at scale. Such an approach aligns precisely with Meyers' assessment of the current threat landscape: sophisticated actors are gaining genuine operational advantages from AI, but we haven't reached full autonomy.
AI then amplifies existing capabilities rather than inventing entirely new attack vectors. The arms race Meyers described isn't hypothetical; it’s happening now with both attackers and defenders racing to leverage AI's speed and scale advantages.
While we may have moved past the Precambrian foundations laid only a few years ago, the eventual explosion hasn't quite yet detonated. So the question now shifts more towards whether defenders can keep pace to keep the inevitable at bay.
Comments