Trend Micro documented a Russian-speaking threat actor who used a jailbroken Google Gemini CLI to build, operate, and migrate botnet infrastructure in real attacks. The AI performed 89% of the operational work.
Trend Micro documented a Russian-speaking threat actor who used a jailbroken Google Gemini CLI to build, operate, and migrate botnet infrastructure in real attacks. The AI performed 89% of the operational work.
A Huntress incident response investigation uncovered a PowerShell Active Directory recon script built by iteratively prompting an AI — the first documented case of 'vibe-coded' malware recovered from a live attack.
North Korea's FAMOUS CHOLLIMA operation has expanded beyond revenue generation into systematic AI intellectual property theft, placing fake engineers inside foundation model developers, GPU cloud providers, and AI safety organisations. CrowdStrike, Microsoft, and the DOJ have documented the mechanism. The AI industry has not caught up.
GhostCircuit is a RaaS operation that integrated LLM tooling into its post-compromise reconnaissance, dramatically reducing time from initial access to ransomware deployment.
A newly tracked cluster uses LLMs to automate spear phishing, accelerate vulnerability research, and generate disinformation targeting AI researchers and ML engineers.