Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-enabled-threat-activityai-platform-security

AI-Driven Threats and Security Operations in 2025

Updated 3mo agoFirst seen Dec 22, 20257 sources

The cybersecurity landscape in 2025 saw a significant evolution in both the use and abuse of artificial intelligence. Threat actors increasingly leveraged AI-powered tools, such as uncensored darknet assistants like DIG AI, to automate and scale malicious activities, including cybercrime, extremism, and privacy violations. Security researchers observed a surge in the adoption of "dark LLMs" and jailbroken AI chatbots, which lowered the barrier for cybercriminals and enabled more sophisticated attacks. At the same time, defenders began integrating generative AI and agentic systems into security operations centers (SOCs), with AI agents handling alert triage and detection tasks, but also introducing new risks related to trust, explainability, and operational complexity.

Security leaders and experts highlighted the need for transparency, traceability, and risk-based prioritization in AI-powered SOC platforms, as well as the importance of addressing alert fatigue and ensuring that AI outputs are auditable. Looking ahead to 2026, the security of AI models and the potential for agentic AI to introduce insider risks are expected to become key challenges. The rapid adoption of AI in both offensive and defensive cyber operations underscores the urgency for organizations to adapt their security strategies, focusing on the unique risks and opportunities presented by AI technologies.

Share:
AI-Driven Threats and Security Operations in 2025
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Dec 25, 20256mo ago

Trend Micro researcher warns of shift toward fully AI-operated attacks

In interviews published on December 25, 2025, Trend Micro's David Sancho said autonomous AI agents are becoming capable of independently scanning, exploiting, and phishing at scale. He also warned that nation-state actors are already experimenting with these methods and that collaboration between cybercrime groups and states is increasing the risk.

Dec 22, 20256mo ago

Resecurity identifies rise of DIG AI and other darknet AI assistants

By late 2025, Resecurity identified growing criminal adoption of uncensored darknet AI assistants such as DIG AI, accessible over Tor without registration. The tool was reported as enabling malicious code generation, fraud, and synthetic CSAM creation, highlighting a broader rise in 'dark LLMs' used by cybercriminals and organized crime groups.

Dec 21, 20256mo ago

Security leaders define key CISO requirements for AI-powered SOCs

At a 2025 roundtable, security leaders from organizations including BNP Paribas, the NFL, and ION Group agreed that AI SOC platforms must be transparent, auditable, explainable, and measurable. They also emphasized contextual prioritization, broad telemetry integration, safe automation with human oversight, and clear accountability for AI-driven actions.

Nov 18, 20257mo ago

Darktrace detects and blocks ClearFake activity in a customer environment

On November 18, 2025, Darktrace observed likely ClearFake activity involving mshta.exe contacting a DGA-like domain and JavaScript making eth_call requests to Smart Chain infrastructure. Darktrace's Autonomous Response blocked suspicious outbound connections and prevented remote HTA execution, interrupting the likely delivery chain before an information stealer could be deployed.

Nov 1, 20258mo ago

ClearFake adopts EtherHiding via BNB Smart Chain infrastructure

Recent ClearFake activity incorporated EtherHiding, using BNB Smart Chain endpoints and smart contracts to retrieve configuration and loader code. This change made the campaign more resilient and harder to track than earlier delivery methods.

Jan 1, 20251y ago

AI adoption in security operations reaches production-scale use

During 2025, organizations moved AI in security operations from theory into practical, production-level deployments. The shift reshaped SOC workflows and intensified industry focus on guardrails, prompt injection risk, automation bias, and platform architecture.

Chinese state-backed group conducts AI-orchestrated espionage campaign

In 2025, the first documented AI-orchestrated cyber espionage campaign was reported, with a Chinese state-sponsored group using Anthropic's Claude AI for most attack operations against about 30 global targets. The case marked a notable shift from AI-assisted activity to AI-driven operational use in espionage.

Jun 1, 20233y ago

ClearFake campaign begins compromising websites with fake browser updates

From mid-2023 onward, the ClearFake campaign used malicious JavaScript on compromised websites to trick visitors into installing fake browser updates, often via SEO-poisoned WordPress pages. The infection chain commonly relied on fake CAPTCHA prompts and PowerShell-based payload delivery.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

30 LINKEDOpen in app
Malware
1 linked
Affected products
5 linked
WindowsGithubPowershellChatgptGithub
Organizations
23 linked
Trend MicroAnthropicMicrosoft CorporationKrollPantherBNP ParibasBinanceBlockPalo Alto NetworksMeta PlatformsCrowdStrikeOpenaiResecurityDarktraceGuidePoint SecurityGitHubIONIntezerNFLTexas Health ResourcesCritical StartGooglePacketLabs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.