Skip to main content
Mallory
Back to intelligence
ai-enabled-threat-activitystate-sponsored-espionagebusiness-email-compromiserapid-weaponization

AI Tools Shift Into Live Cyber Operations Across Crime and Espionage

Updated 7d agoFirst seen May 26, 20267 sources

Check Point Research reported that AI use in offensive cyber operations advanced from planning support to direct execution during March and April, with commercial tools such as Claude Code appearing in live criminal, ransomware, mass-exploitation, and state-linked espionage activity. The report cites persistent AI-assisted operations tied to the breach of nine Mexican government agencies and the Bissa Scanner mass-exploitation platform, and says attackers are increasingly using AI to accelerate reconnaissance, exploitation, and post-compromise actions in ways that closely resemble skilled human operators.

The report also identifies new attack surfaces and scaling effects created by enterprise AI adoption. Agentic configuration artifacts including CLAUDE.md, hooks, settings files, and MCP-related files were described as targets for jailbreaks, supply-chain compromise, and credential theft, while the EvilTokens platform was highlighted for using LLMs to automate token theft, email analysis, business email compromise, and multilingual fraud. Check Point said AI is shrinking the patch window for defenders by speeding flaw discovery and weaponization, pointing to exploitation of an LMDeploy SSRF issue within 12 hours of disclosure, while warning that existing victim-side controls remain poorly suited to detecting AI-executed intrusions.

Share:
AI Tools Shift Into Live Cyber Operations Across Crime and Espionage
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Jun 3, 20269d ago

Intezer details attacker access routes to LLM inference services

On 2026-06-03, Intezer published research describing five ways threat actors obtain LLM inference access, including underground offensive LLMs, crypto-funded intermediaries, leaked API keys, free-tier APIs, and exposed self-hosted servers. The report said exposed self-hosted LLM servers were the most durable abuse path and documented open instances across multiple AI platforms, including signs of active compromise on 14 LocalAI hosts.

How attackers are gaining access to LLM inference - Intezer

Anthropic maps 832 AI-enabled cyber abuse cases to MITRE ATT&CK

On 2026-06-03, Anthropic published an analysis of 832 accounts banned for malicious cyber activity between March 2025 and March 2026, concluding that attackers are using AI deeper into the intrusion lifecycle, including post-compromise tasks such as account discovery and lateral movement. The report also said MITRE ATT&CK does not yet adequately capture AI-enabled behaviors like autonomous orchestration and agentic execution, and noted discussions with MITRE about evolving the framework.

What we learned mapping a year’s worth of AI-enabled cyber threats \ Anthropic
May 27, 202616d ago

ASEC highlights WormGPT-to-AI-malware expansion

An ASEC article described the evolution of AI-powered cybercrime from early malicious LLM services such as WormGPT into a broader ecosystem that included paid SaaS tools, open-source releases, local uncensored models, and AI-embedded malware such as Promptflux and Promptspy. The report said AI use had expanded beyond phishing content generation into reconnaissance, exploit validation, credential triage, attack orchestration, and malware self-modification.

The proliferation and evolution of AI-powered hacking tools - how generative AI has changed the cyber attack ecosystem and response strategies - ASEC
May 26, 202617d ago

Check Point publishes March-April 2026 AI threat landscape digest

On 2026-05-26, Check Point Research published a digest summarizing March–April 2026 AI-related cyber threat activity. The report concluded that agentic AI configuration files had become a persistent attack surface and that existing victim-side controls were poorly suited to detecting AI-executed operations.

Mar 1, 20263mo ago

LMDeploy SSRF exploited within 12 hours of disclosure

In the March–April 2026 period, attackers were reported to have exploited an LMDeploy SSRF vulnerability within 12 hours of its disclosure. The case was presented as evidence that AI is compressing the time between vulnerability disclosure and weaponization.

EvilTokens phishing platform enabled AI-driven token theft and BEC

During March–April 2026, the EvilTokens platform was described as operationalizing LLMs for token theft, email analysis, business email compromise generation, and multilingual fraud at scale. This marked a concrete example of AI-enabled phishing infrastructure being used in the wild.

Bissa Scanner mass-exploitation platform operationalized AI tooling

During March–April 2026, the Bissa Scanner mass-exploitation platform was highlighted as another case where commercial AI tooling was used in active offensive operations. The activity illustrated AI use in scalable criminal exploitation rather than only pre-attack assistance.

Breach of nine Mexican government agencies used Claude Code

During March–April 2026, attackers reportedly used the commercial AI tool Claude Code persistently in a live intrusion affecting nine Mexican government agencies. The case was cited as evidence that AI had moved from planning support into real-time operational deployment.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

119 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

AI Tools Shift Into Live Cyber Operations Across Crime and Espionage | Mallory