Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-enabled-threat-activityphishing-campaign-intelligenceidentity-impersonation-frauddefense-evasion-method

Surge in AI-Driven Cybercrime and Fraud Tactics

Updated 3mo agoFirst seen Nov 26, 20254 sources

Cybercriminals are increasingly leveraging generative AI and large language models (LLMs) to enhance the sophistication, scale, and impact of their attacks. Reports highlight a dramatic rise in advanced phishing, digital fraud, and malware development, with AI enabling attackers to automate social engineering, generate convincing fake identities, and bypass traditional security controls. The use of AI has led to a significant increase in phishing email volume and a 180% surge in advanced fraud attacks, as criminals deploy autonomous bots and deepfake technologies to evade detection and inflict greater damage.

Security researchers have observed malware authors integrating LLMs directly into their tools, allowing malicious code to rewrite itself or generate new commands at runtime, further complicating detection efforts. These developments mark a shift from low-effort, opportunistic attacks to highly engineered campaigns that require more resources to execute but yield far greater impact. The rapid adoption of AI by threat actors underscores the urgent need for organizations to reassess their defenses and adapt to the evolving threat landscape.

Share:
Surge in AI-Driven Cybercrime and Fraud Tactics
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Nov 27, 20257mo ago

Visa report details industrialized payment fraud playbooks and AI abuse

A Visa report described criminal fraud networks operating like coordinated businesses, using automation, credential dumps, repeatable scam playbooks, and AI-generated content to scale payment fraud. It also outlined a two-phase model of stealthy credential acquisition followed by rapid monetization through instant payments, mobile wallets, cross-border transfers, and token provisioning fraud.

Nov 26, 20257mo ago

Google identifies malware samples using LLMs to aid evasion and operations

Google Threat Intelligence Group identified malware samples including PROMPTFLUX, PROMPTSTEAL, FRUITSHELL, and QUIETVAULT that used LLMs such as Google Gemini and Hugging Face for code rewriting, command generation, and data exfiltration support. The activity showed attackers experimenting with AI-enhanced malware, though most samples remained at a prototype stage.

AI-driven digital fraud surges during 2025

Sumsub's 2025 analysis found advanced digital fraud attacks rose by 180%, with criminals increasingly using generative AI for fake identities, deepfakes, forged documents, and autonomous fraud bots. The findings described a shift from high-volume, low-skill fraud to more precise, AI-powered operations.

Jun 30, 20251y ago

First half of 2025 sees increased payment-ecosystem exposures and ransomware

Visa reported that the first half of 2025 included increased ransomware incidents and large-scale account exposures affecting processors, service providers, merchants, and the broader payment ecosystem. The report highlighted growing systemic third-party risk in payment fraud operations.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

20 LINKEDOpen in app
Affected products
2 linked
ChatgptChatgpt
Organizations
14 linked
VisaGoogleHugging FaceCisco SystemsPalo Alto NetworksForcepointHitachi CyberDark ReadingOpenaiDeepStrikeNational Institute of Standards and TechnologyHitachiSumsubKDM Analytics
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.