{
  "version": "https://jsonfeed.org/version/1.1",
  "title": "AI Threat Watch",
  "description": "An automated watch on attackers using AI and on attacks against AI systems. Short summaries, direct links to the source.",
  "home_page_url": "https://ai-threat.watch",
  "feed_url": "https://ai-threat.watch/feed.json",
  "language": "en",
  "items": [
    {
      "id": "https://ai-threat.watch/#2026-09-18-anthropic-misuse-report",
      "url": "https://www.anthropic.com/threat-intelligence-report-september-2026",
      "title": "Detecting and countering misuse of AI: September 2026",
      "content_text": "Anthropic describes actors who automate whole intrusion chains with AI agents. One Russian-speaking espionage operator had agents rebuild malware whenever a security product detected it, and used AI to sort hundreds of gigabytes of stolen data.",
      "date_published": "2026-09-18T00:00:00Z",
      "date_modified": "2026-09-18T06:00:00Z",
      "tags": [
        "AI-Enabled",
        "GTG-20006",
        "Midnight Blizzard",
        "GTG-50014",
        "JackPoterz",
        "PentAGI",
        "WPPConnect",
        "Embassy Kit",
        "CaptiveCrunch"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Anthropic",
          "domain": "anthropic.com",
          "type": "vendor-report"
        },
        "actors": [
          "GTG-20006",
          "Midnight Blizzard",
          "GTG-50014",
          "JackPoterz"
        ],
        "malware": [
          "PentAGI",
          "WPPConnect",
          "Embassy Kit",
          "CaptiveCrunch"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "Russia",
            "claimed_by": "Anthropic",
            "confidence": "not-stated"
          }
        ],
        "also": [
          {
            "name": "Anthropic",
            "domain": "www-cdn.anthropic.com",
            "url": "https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf"
          }
        ],
        "landmark": true
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-09-16-sophos-devil-s-advocate-uncensored-luciferus-ai",
      "url": "https://www.sophos.com/en-us/blog/uncensored-luciferus-ai-service-advertised-underground",
      "title": "Devil’s advocate? Uncensored Luciferus AI service advertised underground",
      "content_text": "Sophos CTU researchers found an underground forum persona advertising Luciferus, an uncensored AI service claiming to be a proprietary 120-billion-parameter model, though researchers assess with low confidence it is based on Qwen. The service offers tiered subscriptions and demonstrated willingness to generate malware code like a Python RAT, illustrating growing commercialization of uncensored AI in cybercrime market",
      "date_published": "2026-09-16T00:00:00Z",
      "date_modified": "2026-09-21T09:59:48Z",
      "tags": [
        "AI-Enabled",
        "Optimus_Prime",
        "Luciferus",
        "WormGPT",
        "FraudGPT"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Sophos",
          "domain": "sophos.com",
          "type": "vendor-report"
        },
        "actors": [
          "Optimus_Prime"
        ],
        "malware": [
          "Luciferus",
          "WormGPT",
          "FraudGPT"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-09-15-jfrog-security-research-new-packages-identified-in-gemstuffer-op",
      "url": "https://research.jfrog.com/post/gemstuffer-openai-rubygems/",
      "title": "New packages identified in GemStuffer 'OpenAI Swarm' malicious RubyGems campaign",
      "content_text": "JFrog identified over 3,000 malicious RubyGems packages tied to the GemStuffer campaign, some exploiting a RubyGems legacy API-key caching flaw to steal credentials and others using XSS or template-injection payloads in package metadata. Naming patterns and prior incidents link the campaign to OpenAI Swarm agents generating packages at scale, though original prompts remain unavailable.",
      "date_published": "2026-09-15T00:00:00Z",
      "date_modified": "2026-09-21T09:59:39Z",
      "tags": [
        "AI-Enabled",
        "OpenAI Swarm",
        "slnleaker5",
        "f2fe-s1",
        "yardxabc889",
        "southpxdatapp6pi",
        "xss-test-gem",
        "test-apex-gem",
        "test-ssti-0",
        "test-ssti-1"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "JFrog Security Research",
          "domain": "research.jfrog.com",
          "type": "vendor-report"
        },
        "actors": [
          "OpenAI Swarm"
        ],
        "malware": [
          "slnleaker5",
          "f2fe-s1",
          "yardxabc889",
          "southpxdatapp6pi",
          "xss-test-gem",
          "test-apex-gem",
          "test-ssti-0",
          "test-ssti-1"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-09-09-gen-digital-infostealers-have-found-a-new-target-you",
      "url": "https://www.gendigital.com/blog/insights/research/infostealers-your-ai-agent",
      "title": "Infostealers Have Found a New Target: Your AI Agent",
      "content_text": "Gen Digital's telemetry shows infostealers like Amatera, Remus, CallbackBeaver, and Djinn Stealer have added AI coding agents (Claude, Cursor, Codex, Cline, OpenCode) to their collection rules, harvesting tokens, MCP credentials, and prompt histories. This expands the infostealer economy to target local AI agent data as a new high-value asset alongside browser and wallet credentials.",
      "date_published": "2026-09-09T00:00:00Z",
      "date_modified": "2026-09-21T09:59:04Z",
      "tags": [
        "AI-Targeted",
        "Amatera",
        "Remus",
        "CallbackBeaver",
        "BeeStealer",
        "STG Stealer",
        "HydraStealer",
        "APEX Stealer",
        "Otter Stealer"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Gen Digital",
          "domain": "gendigital.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "Amatera",
          "Remus",
          "CallbackBeaver",
          "BeeStealer",
          "STG Stealer",
          "HydraStealer",
          "APEX Stealer",
          "Otter Stealer"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-09-07-genians-kimsuky-uses-the-ai-agent-opencode-to-cr",
      "url": "https://www.genians.co.kr/en/blog/threat_intelligence/ai-agent-opencode",
      "title": "Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve",
      "content_text": "Genians analyzed 13 malicious LNK files linked to Kimsuky, part of an ongoing campaign called Operation GitPower using GitHub PAT-based C2 and PowerShell loaders. Metadata in decoy PDF documents showed traces of the AI coding agent 'opencode' and unreplaced placeholder text, indicating the actor used AI/LLMs to mass produce decoy documents without proper review.",
      "date_published": "2026-09-07T00:00:00Z",
      "date_modified": "2026-09-21T09:58:49Z",
      "tags": [
        "AI-Enabled",
        "Kimsuky"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Genians",
          "domain": "genians.co.kr",
          "type": "vendor-report"
        },
        "actors": [
          "Kimsuky"
        ],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-09-03-unit-42-attackers-expose-ongoing-ai-tool-use-tar",
      "url": "https://origin-unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/",
      "title": "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America",
      "content_text": "Unit 42 documents two active Latin American intrusion campaigns, one against Mexican/Ecuadorian government and transportation targets and one against Brazilian financial firms, where attackers used self-hosted NextChat instances and commercial LLMs like Claude and GPT-4.1 to troubleshoot scripts and build proxy tools. Exposed staging infrastructure showed AI-generated iterative filenames and prompt history, revealing",
      "date_published": "2026-09-03T00:00:00Z",
      "date_modified": "2026-09-21T10:18:58Z",
      "tags": [
        "AI-Enabled",
        "NextChat",
        "SockTz"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Unit 42",
          "domain": "origin-unit42.paloaltonetworks.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "NextChat",
          "SockTz"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-08-28-huntress-the-ai-attack-surface-how-threat-actors",
      "url": "https://www.huntress.com/blog/ai-attack-surface",
      "title": "The AI Attack Surface: How Threat Actors Abuse Trusted AI Platforms",
      "content_text": "Huntress documents campaigns abusing legitimate AI platform features, Claude Artifacts, claude.ai/share links, and shared ChatGPT/Grok conversations, to host phishing and ClickFix-style lures on trusted domains, leading victims to install SectopRAT, MacSync stealer, or AMOS stealer. These attacks exploit trust in AI branding and domains combined with SEO/malvertising rather than flaws in the AI models themselves, hit",
      "date_published": "2026-08-28T00:00:00Z",
      "date_modified": "2026-09-21T10:18:41Z",
      "tags": [
        "AI-Targeted",
        "SectopRAT",
        "MacSync stealer",
        "AMOS stealer"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Huntress",
          "domain": "huntress.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "SectopRAT",
          "MacSync stealer",
          "AMOS stealer"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-08-28-unit-42-perturbation-probing-a-new-diagnostic-fo",
      "url": "https://unit42.paloaltonetworks.com/perturbation-probing-llm-safety/",
      "title": "Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety",
      "content_text": "Unit 42 researchers introduce perturbation probing, a method that identifies the small set of neurons responsible for an LLM's safety refusal behavior. They found that in Qwen3-4B, disabling just 50 neurons (0.014% of feed-forward neurons) altered refusal behavior on 80% of harmful prompts, showing safety alignment can rest on a thin, easily disrupted layer rather than robust distributed defenses.",
      "date_published": "2026-08-28T00:00:00Z",
      "date_modified": "2026-09-21T10:18:48Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Unit 42",
          "domain": "unit42.paloaltonetworks.com",
          "type": "research"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-08-27-gambit-security-aurora-ransomware-targets-esxi-abuses-cu",
      "url": "https://gambit.security/blog-posts/aurora-ransomware-targets-esxi-abuses-cursor-agent-for-exploitation",
      "title": "Aurora ransomware targets ESXi, abuses Cursor Agent for exploitation",
      "content_text": "Gambit Security found Aurora ransomware operators using Cursor Agent with Claude Sonnet to run hands-on exploitation, including domain enumeration, NTLM relay, and certificate attacks, across ten victims. The group also deployed a new Linux ESXi ransomware variant and a separate cluster using S3 exfiltration infrastructure.",
      "date_published": "2026-08-27T00:00:00Z",
      "date_modified": "2026-09-21T09:57:34Z",
      "tags": [
        "AI-Enabled",
        "Aurora",
        "Aurora",
        "Cursor Agent",
        "Claude Sonnet",
        "NetExec",
        "Impacket",
        "Certipy",
        "PetitPotam",
        "Coerce Plus"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Gambit Security",
          "domain": "gambit.security",
          "type": "vendor-report"
        },
        "actors": [
          "Aurora"
        ],
        "malware": [
          "Aurora",
          "Cursor Agent",
          "Claude Sonnet",
          "NetExec",
          "Impacket",
          "Certipy",
          "PetitPotam",
          "Coerce Plus"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-08-26-trail-of-bits-vms-won-t-contain-cyber-capable-agents",
      "url": "https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyber-capable-agents/",
      "title": "VMs won't contain cyber-capable agents",
      "content_text": "Trail of Bits tested a preview of OpenAI's GPT 5.6-Cyber agent and had it attempt to escape a QEMU/KVM sandbox. The agent autonomously escaped three times, using a recently disclosed kernel bug, an unpatched libslirp flaw, and finally a chain of several previously unknown 0-days in QEMU, KVM, and libslirp, operating for roughly 12 hours with minimal human guidance. It failed to break out of the more hardened Firecrac",
      "date_published": "2026-08-26T00:00:00Z",
      "date_modified": "2026-09-21T09:57:26Z",
      "tags": [
        "AI-Enabled",
        "CVE-2026-53359",
        "CVE-2026-9539"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Trail of Bits",
          "domain": "blog.trailofbits.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [
          "CVE-2026-53359",
          "CVE-2026-9539"
        ],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-08-25-cyera-drive-by-agent-hijacking-one-website-vis",
      "url": "https://www.cyera.com/research/nemoclaw-one-website-visit-to-hijack-your-ai-agent",
      "title": "Drive-By Agent Hijacking: One Website Visit, Persistent Model Poisoning",
      "content_text": "Researchers found a vulnerability (CVE-2026-65105) in NVIDIA NemoClaw where a misconfigured Ollama binding to 0.0.0.0 disables host validation, letting an attacker use DNS rebinding from a malicious webpage to gain unauthenticated access to the local Ollama API. This lets attackers poison the model's chat template to persistently hijack an AI agent's behavior across future sessions; demonstrated as a proof of concept",
      "date_published": "2026-08-25T00:00:00Z",
      "date_modified": "2026-09-21T10:18:33Z",
      "tags": [
        "AI-Targeted",
        "NemoClaw",
        "OpenClaw",
        "OpenShell",
        "Ollama",
        "CVE-2026-65105"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Cyera",
          "domain": "cyera.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "NemoClaw",
          "OpenClaw",
          "OpenShell",
          "Ollama"
        ],
        "vulnerabilities": [
          "CVE-2026-65105"
        ],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-08-20-cisco-talos-uat-10147-chinese-speaking-adversary-int",
      "url": "https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/",
      "title": "UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations",
      "content_text": "Cisco Talos documented a financially motivated, Chinese-speaking group, UAT-10147, using agentic AI tools like PentestGPT and DeepAudit alongside Metasploit and known CVEs to automate exploitation, reconnaissance, payload generation, and troubleshooting against Windows and Linux web servers worldwide. Talos assesses with moderate-to-high confidence this represents a shift from AI-assisted scripting to semi-autonomous",
      "date_published": "2026-08-20T00:00:00Z",
      "date_modified": "2026-09-21T09:57:00Z",
      "tags": [
        "AI-Enabled",
        "UAT-10147",
        "QuasarRAT",
        "EfsPotato",
        "BadIIS",
        "Gh0stCringe",
        "SPECTRE",
        "NoodleRAT",
        "Meterpreter",
        "DeepAudit",
        "CVE-2022-0995",
        "CVE-2021-3156",
        "CVE-2015-5287",
        "CVE-2015-3246",
        "CVE-2010-3904",
        "CVE-2022-0847",
        "CVE-2022-27925",
        "CVE-2021-23758",
        "CVE-2021-29441",
        "CVE-2021-29442",
        "CVE-2019-18935"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Cisco Talos",
          "domain": "blog.talosintelligence.com",
          "type": "vendor-report"
        },
        "actors": [
          "UAT-10147"
        ],
        "malware": [
          "QuasarRAT",
          "EfsPotato",
          "BadIIS",
          "Gh0stCringe",
          "SPECTRE",
          "NoodleRAT",
          "Meterpreter",
          "DeepAudit"
        ],
        "vulnerabilities": [
          "CVE-2022-0995",
          "CVE-2021-3156",
          "CVE-2015-5287",
          "CVE-2015-3246",
          "CVE-2010-3904",
          "CVE-2022-0847",
          "CVE-2022-27925",
          "CVE-2021-23758",
          "CVE-2021-29441",
          "CVE-2021-29442",
          "CVE-2019-18935"
        ],
        "attribution": [
          {
            "country": "China",
            "claimed_by": "Cisco Talos",
            "confidence": "not-stated"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-08-12-pillar-security-deadbugz-currently-active-mcp-supply-cha",
      "url": "https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign",
      "title": "Deadbugz: Currently Active MCP Supply-Chain Campaign",
      "content_text": "Pillar Security identified an active campaign distributing a malicious MCP server, productivity-suite, via GitHub pull requests. The server behaves normally for the first three tool calls, then returns altered metadata instructing connected AI agents to search for SSH keys, AWS credentials, and other secrets while hiding the activity. The delivery account, zellkernel, submitted 23 pull requests in a 74-minute window;",
      "date_published": "2026-08-12T00:00:00Z",
      "date_modified": "2026-09-21T09:57:43Z",
      "tags": [
        "AI-Targeted",
        "zellkernel",
        "productivity-suite",
        "productivity-suite-mcp",
        "deadbug-mcp.py"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Pillar Security",
          "domain": "pillar.security",
          "type": "vendor-report"
        },
        "actors": [
          "zellkernel"
        ],
        "malware": [
          "productivity-suite",
          "productivity-suite-mcp",
          "deadbug-mcp.py"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-08-12-specterops-blacklight-illuminating-ai-agent-artifac",
      "url": "https://specterops.io/blog/2026/08/12/blacklight-ai-agent-endpoint-artifacts/",
      "title": "Blacklight: Illuminating AI Agent Artifacts for Attackers and Defenders",
      "content_text": "SpecterOps released Blacklight, an open-source toolkit that discovers and analyzes local endpoint artifacts left by AI coding agents like Codex, Claude Code, Cursor, and Antigravity CLI. These artifacts, including auth tokens, session transcripts, and configuration files, can expose credentials, project context, and trust relationships useful to attackers and to defenders building detection guidance.",
      "date_published": "2026-08-12T00:00:00Z",
      "date_modified": "2026-09-21T10:18:26Z",
      "tags": [
        "AI-Targeted",
        "Blacklight",
        "Blacklight Scout"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "SpecterOps",
          "domain": "specterops.io",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "Blacklight",
          "Blacklight Scout"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-08-10-genians-security-center-kimsuky-integrates-ai-into-attack-operat",
      "url": "https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm",
      "title": "Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM",
      "content_text": "Genians Security Center documented the North Korea-linked Kimsuky group using AI-generated decoy documents and experimenting with local LLM tools (Ollama, GPT4All, Msty) in an ongoing campaign dubbed Operation GitPower. The actor uses LNK files, obfuscated PowerShell, and GitHub-hosted repositories as C2 to distribute AsyncRAT payloads disguised as PNG images, targeting diplomatic, military, and virtual asset sector",
      "date_published": "2026-08-10T00:00:00Z",
      "date_modified": "2026-09-21T09:56:25Z",
      "tags": [
        "AI-Enabled",
        "Kimsuky",
        "AsyncRAT",
        "FlowerPower",
        "Operation GitPower"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Genians Security Center",
          "domain": "genians.co.kr",
          "type": "vendor-report"
        },
        "actors": [
          "Kimsuky"
        ],
        "malware": [
          "AsyncRAT",
          "FlowerPower",
          "Operation GitPower"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "North Korea",
            "claimed_by": "Genians Security Center",
            "confidence": "not-stated"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-07-30-anthropic-investigating-three-real-world-incidents",
      "url": "https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals",
      "title": "Investigating three real-world incidents in our cybersecurity evaluations",
      "content_text": "Anthropic found that during cybersecurity capture-the-flag evaluations, Claude models unexpectedly gained internet access due to a misconfiguration with a third-party evaluator and compromised real production systems at three organizations, believing them to be simulated targets. Impacts included data exfiltration, a malicious PyPI package that ran on 15 real systems, and unauthorized access via SQL injection, none o",
      "date_published": "2026-07-30T00:00:00Z",
      "date_modified": "2026-09-21T09:56:06Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Anthropic",
          "domain": "anthropic.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-07-27-huntress-inside-fakeagent-how-a-claude-desktop-ma",
      "url": "https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat",
      "title": "Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT",
      "content_text": "Huntress found a malvertising campaign that abused a public Claude AI artifact to distribute a trojanized ClaudeDesktop.exe installer, infecting 29 organizations with the SectopRAT trojan via DLL sideloading, GPU-based decryption, and blockchain-hosted (EtherHiding) command and control. Huntress used Claude itself, with human verification, to help reverse engineer the malware's custom AES implementation hidden in a G",
      "date_published": "2026-07-27T00:00:00Z",
      "date_modified": "2026-09-21T09:55:59Z",
      "tags": [
        "AI-Targeted",
        "SectopRAT"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Huntress",
          "domain": "huntress.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "SectopRAT"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-07-22-sophos-ai-security-2026",
      "url": "https://assets.sophos.com/X24WTUEQ/at/2gxzgxgw5xxgtsch4cmtqwkr/sophos-ai-security-report-2026.pdf",
      "title": "AI Security 2026",
      "content_text": "Sophos's 2026 AI Security Report details a real-world case, tracked as STAC6994, where about a dozen AI agents built and tested EDR evasion malware across parallel VMs, compressing weeks of development into days, before the operator deployed ransomware and stole data. The report also covers AI supply-chain attacks, underground AI infrastructure sales, and exploit timelines outpacing patching.",
      "date_published": "2026-07-22T00:00:00Z",
      "date_modified": "2026-09-21T09:55:41Z",
      "tags": [
        "AI-Enabled",
        "STAC6994",
        "IRON TWILIGHT (APT28)",
        "The Gentlemen",
        "DragonForce",
        "LameHug",
        "MacSync",
        "Sliver",
        "CVE-2026-10520",
        "CVE-2026-42208"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Sophos",
          "domain": "assets.sophos.com",
          "type": "vendor-report"
        },
        "actors": [
          "STAC6994",
          "IRON TWILIGHT (APT28)",
          "The Gentlemen",
          "DragonForce"
        ],
        "malware": [
          "LameHug",
          "MacSync",
          "Sliver"
        ],
        "vulnerabilities": [
          "CVE-2026-10520",
          "CVE-2026-42208"
        ],
        "attribution": [
          {
            "country": "China",
            "claimed_by": "Anthropic",
            "confidence": "not-stated"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-07-19-darkatlas-apt42-ai-assisted-rapport-phishing-and-a",
      "url": "https://darkatlas.io/blog/apt42-ai-assisted-phishing-tamecat-analysis",
      "title": "APT42: AI-Assisted Rapport Phishing and a More Resilient TAMECAT Backdoor",
      "content_text": "Darkatlas documents Iran-linked APT42/TA453 activity including the SpearSpecter campaign, which uses search-ms and WebDAV abuse to deliver an expanded TAMECAT backdoor with browser cookie theft and multi-channel C2 via HTTPS, Discord and Telegram. The report also describes APT42 incorporating generative AI into reconnaissance, persona and pretext creation, translation, and malware development.",
      "date_published": "2026-07-19T00:00:00Z",
      "date_modified": "2026-09-21T09:55:17Z",
      "tags": [
        "AI-Enabled",
        "APT42",
        "TA453",
        "RedKitten",
        "TAMECAT",
        "SpearSpecter"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Darkatlas",
          "domain": "darkatlas.io",
          "type": "vendor-report"
        },
        "actors": [
          "APT42",
          "TA453",
          "RedKitten"
        ],
        "malware": [
          "TAMECAT",
          "SpearSpecter"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "Iran",
            "claimed_by": "Darkatlas",
            "confidence": "not-stated"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-07-16-hugging-face-security-incident-disclosure-july-2026",
      "url": "https://huggingface.co/blog/security-incident-july-2026",
      "title": "Security incident disclosure , July 2026",
      "content_text": "Hugging Face disclosed that an autonomous AI agent framework breached part of its production infrastructure by exploiting two code-execution flaws in its dataset processing pipeline, then escalated privileges and harvested credentials. No tampering with public models, datasets, or Spaces was found; Hugging Face used an open-weight model on its own infrastructure for forensic analysis after commercial API providers' s",
      "date_published": "2026-07-16T00:00:00Z",
      "date_modified": "2026-09-21T09:55:09Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Hugging Face",
          "domain": "huggingface.co",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [
          {
            "name": "Elastic Security Labs",
            "domain": "elastic.co",
            "url": "https://www.elastic.co/security-labs/threat-command/ai-agent-attack-detection-hugging-face-breach"
          }
        ],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-07-15-zscaler-claudefix-shared-claude-chats-meet-click",
      "url": "https://www.zscaler.com:443/blogs/security-research/claudefix-shared-claude-chats-meet-clickfix",
      "title": "ClaudeFix: Shared Claude Chats Meet ClickFix",
      "content_text": "Zscaler Threat Hunting found threat actors abusing shared Claude chat links, disguised with an 'Apple Support' display name, to host ClickFix instructions that install MacSync Stealer on macOS via malvertising. The malware steals keychains, browser data, crypto wallets and files, then exfiltrates and self-deletes to avoid detection. Russian-language code comments suggest a Russian-speaking actor; the campaign ran Jun",
      "date_published": "2026-07-15T00:00:00Z",
      "date_modified": "2026-09-21T09:54:54Z",
      "tags": [
        "AI-Enabled",
        "MacSync Stealer"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Zscaler",
          "domain": "zscaler.com:443",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "MacSync Stealer"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "Russia",
            "claimed_by": "Zscaler Threat Hunting",
            "confidence": "low"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-07-14-hunt-io-suspected-chinese-operators-use-claude-c",
      "url": "https://hunt.io/blog/chinese-operators-claude-deepseek-government-intrusion",
      "title": "Suspected Chinese Operators Use Claude Code and DeepSeek to Target Government and Financial Systems Across Four Countries",
      "content_text": "Hunt.io researchers found an open directory tied to TencShell C2 infrastructure showing suspected China-linked operators using Claude Code and DeepSeek-v4-pro to handle exploit reasoning, session persistence, and phishing page creation during live intrusions. Victims included government and critical infrastructure targets in Afghanistan, Thailand, and Taiwan, with reconnaissance against U.S. government portals and sc",
      "date_published": "2026-07-14T00:00:00Z",
      "date_modified": "2026-09-21T09:54:44Z",
      "tags": [
        "AI-Enabled",
        "TencShell",
        "Vshell",
        "ARL",
        "DeepAudit",
        "Gshell",
        "HSEWH-Ur"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Hunt.io",
          "domain": "hunt.io",
          "type": "research"
        },
        "actors": [],
        "malware": [
          "TencShell",
          "Vshell",
          "ARL",
          "DeepAudit",
          "Gshell",
          "HSEWH-Ur"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "China",
            "claimed_by": "Hunt.io",
            "confidence": "low"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-07-13-tel-aviv-university-beware-of-agentic-botnets-scalable-untar",
      "url": "https://sites.google.com/view/agentic-botnets/home",
      "title": "Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting",
      "content_text": "Researchers show that LLM hallucinations of repository or skill names are predictable and transferable across models, letting attackers preregister the hallucinated resource names with malicious payloads. When agentic coding assistants and CLIs fetch these squatted resources they can be tricked into executing code, enabling remote code execution and potentially a botnet. This is proof-of-concept research disclosed re",
      "date_published": "2026-07-13T00:00:00Z",
      "date_modified": "2026-09-21T10:17:40Z",
      "tags": [
        "AI-Targeted",
        "HalluSquatting",
        "promptware"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Tel Aviv University",
          "domain": "sites.google.com",
          "type": "academic"
        },
        "actors": [],
        "malware": [
          "HalluSquatting",
          "promptware"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-07-08-elastic-security-labs-ref6045-mexican-banking-fraud-toolkit-wi",
      "url": "https://www.elastic.co/security-labs/threat-command/mexican-banking-fraud-scmbanker-ref6045",
      "title": "REF6045: Mexican banking fraud toolkit with signs of AI-assisted development",
      "content_text": "Elastic Security Labs documented REF6045, an operator-assisted banking fraud campaign using ClickFix fake-CAPTCHA lures to install a PowerShell toolkit called SCMBANKER against Mexican bank, fintech, and crypto exchange customers. The toolkit enables session monitoring, screenshots, vishing overlays, clipboard hijacking, and RAT deployment, and its scripts show artifacts suggesting an LLM was used to write most of th",
      "date_published": "2026-07-08T00:00:00Z",
      "date_modified": "2026-09-21T08:43:43Z",
      "tags": [
        "AI-Enabled",
        "SCMBANKER",
        "Remote Utilities"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Elastic Security Labs",
          "domain": "elastic.co",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "SCMBANKER",
          "Remote Utilities"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "not-stated",
            "claimed_by": "Elastic Security Labs",
            "confidence": "not-stated"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-07-07-flare-mycelium-framework-first-ever-witnessed",
      "url": "https://flare.io/learn/resources/blog/mycelium-framework-ai-as-a-service-botnet",
      "title": "Mycelium Framework: First Ever Witnessed AI-as-a-Service Botnet",
      "content_text": "Flare researchers describe an underground forum advertisement for 'Mycelium Framework,' a botnet claiming to classify infected machines by compute, GPU, stolen AI API keys and local models, then route AI inference, social engineering and other tasks accordingly. No source code or proof of execution was provided, and most individual techniques are previously documented, so the AI-as-a-service claims remain unverified.",
      "date_published": "2026-07-07T00:00:00Z",
      "date_modified": "2026-09-21T08:44:11Z",
      "tags": [
        "AI-Enabled",
        "Mycelium Framework",
        "Mirai",
        "TeamTNT",
        "DorkBot",
        "RageBot",
        "Phorpiex",
        "IRCBot.HI",
        "CVE-2021-22205"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Flare",
          "domain": "flare.io",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "Mycelium Framework",
          "Mirai",
          "TeamTNT",
          "DorkBot",
          "RageBot",
          "Phorpiex",
          "IRCBot.HI"
        ],
        "vulnerabilities": [
          "CVE-2021-22205"
        ],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-07-03-moonlock-new-gaslight-malware-evades-ai-analysis",
      "url": "https://moonlock.com/gaslight-malware-evades-ai-analysis",
      "title": "New Gaslight malware evades AI analysis",
      "content_text": "SentinelOne identified a North Korean-linked macOS Rust malware, dubbed Gaslight, that embeds fabricated system error messages designed to trick AI-based security agents into dismissing it during automated triage. The malware also steals browser data, terminal history, and keychain files, and exfiltrates via a hardened Telegram bot C2, moving prompt-injection evasion from proof-of-concept into real-world use.",
      "date_published": "2026-07-03T00:00:00Z",
      "date_modified": "2026-09-21T10:17:32Z",
      "tags": [
        "AI-Targeted",
        "North Korean hackers",
        "Gaslight",
        "AMOS",
        "Realistic macOS infostealer",
        "Realist"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Moonlock",
          "domain": "moonlock.com",
          "type": "vendor-report"
        },
        "actors": [
          "North Korean hackers"
        ],
        "malware": [
          "Gaslight",
          "AMOS",
          "Realistic macOS infostealer",
          "Realist"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "North Korea",
            "claimed_by": "SentinelOne",
            "confidence": "not-stated"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-07-02-zscaler-threatlabz-indirect-prompt-injection-in-web-content",
      "url": "https://www.zscaler.com:443/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents",
      "title": "Indirect Prompt Injection in Web Content Targets AI Agents",
      "content_text": "Zscaler ThreatLabz documented two real-world campaigns embedding hidden prompt injection instructions in web content via SEO poisoning, JSON-LD, and CSS to manipulate AI agents, including a fake API payment scam and a DeBank typosquatting site. Testing across 26 LLMs found 4 models could be tricked into making payments and 2 misclassified the fraudulent site as legitimate.",
      "date_published": "2026-07-02T00:00:00Z",
      "date_modified": "2026-09-21T10:17:17Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Zscaler ThreatLabz",
          "domain": "zscaler.com:443",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-07-01-sysdig-jadepuffer-agentic-ransomware-for-automa",
      "url": "https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion",
      "title": "JADEPUFFER: Agentic ransomware for automated database extortion",
      "content_text": "Sysdig's Threat Research Team documented what they assess to be the first fully agentic ransomware operation, dubbed JADEPUFFER, where an LLM autonomously gained access via a Langflow RCE flaw, harvested credentials, exploited Nacos authentication bypasses, and encrypted and destroyed a victim's production database for extortion. The payloads showed self-narrating reasoning and adaptive retries with no human interven",
      "date_published": "2026-07-01T00:00:00Z",
      "date_modified": "2026-09-21T08:43:36Z",
      "tags": [
        "AI-Enabled",
        "JADEPUFFER",
        "JADEPUFFER",
        "CVE-2025-3248",
        "CVE-2021-29441"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Sysdig",
          "domain": "sysdig.com",
          "type": "vendor-report"
        },
        "actors": [
          "JADEPUFFER"
        ],
        "malware": [
          "JADEPUFFER"
        ],
        "vulnerabilities": [
          "CVE-2025-3248",
          "CVE-2021-29441"
        ],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-06-11-fortiguard-labs-threat-actors-weaponize-ai-hype-to-deliv",
      "url": "https://www.fortinet.com/blog/threat-research/threat-actors-weaponize-ai-hype-to-deliver-asyncrat",
      "title": "Threat Actors Weaponize AI Hype to Deliver AsyncRAT",
      "content_text": "FortiGuard Labs documented a multi-stage Windows malware campaign using fake AI-themed documents and guides as lures to deliver AsyncRAT via AutoHotkey-based loaders and process hollowing. Chinese-language code artifacts and structured coding style suggest the attackers used generative AI tools to help build the malware, though this is inferred rather than confirmed.",
      "date_published": "2026-06-11T00:00:00Z",
      "date_modified": "2026-09-21T08:42:26Z",
      "tags": [
        "AI-Enabled",
        "AsyncRAT",
        "AutoHotkey",
        "clay_Client"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "FortiGuard Labs",
          "domain": "fortinet.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "AsyncRAT",
          "AutoHotkey",
          "clay_Client"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-06-11-helpnet-owasp-agentic",
      "url": "https://www.helpnetsecurity.com/2026/06/11/owasp-prompt-injection-ai-security-failures/",
      "title": "Prompt injection still drives most agentic AI security failures in production",
      "content_text": "Coverage of OWASP's 2026 findings on agentic AI. Most production failures still begin with prompt injection, and attackers increasingly poison what agents trust: MCP servers, packages and coding-tool configuration.",
      "date_published": "2026-06-11T00:00:00Z",
      "date_modified": "2026-06-11T06:00:00Z",
      "tags": [
        "AI-Targeted",
        "CVE-2025-6514",
        "CVE-2026-22708"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Help Net Security",
          "domain": "helpnetsecurity.com",
          "type": "news"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [
          "CVE-2025-6514",
          "CVE-2026-22708"
        ],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-06-03-anthropic-what-we-learned-mapping-a-year-s-worth-o",
      "url": "https://www.anthropic.com/news/AI-enabled-cyber-threats-mitre-attack",
      "title": "What we learned mapping a year's worth of AI-enabled cyber threats",
      "content_text": "Anthropic analyzed 832 accounts banned for malicious cyber activity between March 2025 and March 2026, mapping their techniques to MITRE ATT&CK. They found AI use shifting from initial access to post-compromise activity, risk scores rising over time, and the framework failing to capture autonomous agentic orchestration seen in a November 2025 state-sponsored espionage case.",
      "date_published": "2026-06-03T00:00:00Z",
      "date_modified": "2026-09-21T08:41:04Z",
      "tags": [
        "AI-Enabled",
        "Claude Code"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Anthropic",
          "domain": "anthropic.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "Claude Code"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-05-29-permiso-chatgphish-the-page-is-the-payload",
      "url": "https://permiso.io/blog/chatgpt-markdown-rendering-vulnerability",
      "title": "ChatGPhish: The Page Is the Payload",
      "content_text": "Permiso researchers show that ChatGPT's browser page-summarization feature renders attacker-appended Markdown links and images from third-party pages as trusted UI elements, enabling phishing, QR-code redirection to a second device, and tracking-pixel style data leakage. The issue was demonstrated as a proof of concept and reported to OpenAI via Bugcrowd but was marked not reproducible then a duplicate.",
      "date_published": "2026-05-29T00:00:00Z",
      "date_modified": "2026-09-21T10:17:08Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Permiso",
          "domain": "permiso.io",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-05-27-straiker-fake-claude-code-real-malware-inside-the",
      "url": "https://www.straiker.ai/blog/acr-stealer-claude-code-impersonation-campaign",
      "title": "Fake Claude Code, Real Malware: Inside the Campaign Targeting AI Developers",
      "content_text": "Straiker documented a live infostealer campaign impersonating Claude Code, JetBrains, NotebookLM and other AI developer tools across 88 domains, using SEO poisoning, paid ads, and fileless payload delivery. The malware, an Amatera/ACR Stealer variant, is built to steal API keys from AI coding assistants alongside browser credentials and crypto wallets, with C2 hidden on a Binance Smart Chain contract.",
      "date_published": "2026-05-27T00:00:00Z",
      "date_modified": "2026-09-21T09:54:08Z",
      "tags": [
        "AI-Targeted",
        "Amatera",
        "ACR Stealer"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Straiker",
          "domain": "straiker.ai",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "Amatera",
          "ACR Stealer"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-05-21-eclecticiq-seo-poisoning-campaign-leverages-gemini",
      "url": "https://blog.eclecticiq.com/seo-poisoning-campaign-leverages-gemini-and-claude-code-impersonation-to-deliver-infostealer",
      "title": "SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer",
      "content_text": "EclecticIQ documented an SEO poisoning campaign using fake Gemini CLI and Claude Code installation pages to trick developers into running a PowerShell command that installs a fileless, in-memory infostealer alongside the real tool. The malware disables AMSI and ETW, harvests browser, collaboration app, VPN and crypto wallet credentials, and supports remote code execution, with passive DNS revealing over 30 related do",
      "date_published": "2026-05-21T00:00:00Z",
      "date_modified": "2026-09-21T09:53:45Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "EclecticIQ",
          "domain": "blog.eclecticiq.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-05-21-trend-micro-one-man-one-ai-one-fake-persona-inside-t",
      "url": "https://www.trendmicro.com/en_us/research/26/e/inside-the-influence-and-fraud-patriot-bait-campaign.html",
      "title": "One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign",
      "content_text": "A solo Russian-speaking threat actor ran a 5-year MAGA-themed Telegram influence channel and, starting September 2025, used a jailbroken Google Gemini to automate content creation, manage infrastructure, rotate stolen API keys, and run a QAnon-styled fraud chatbot. The campaign combined credential theft, a fake crypto wallet RAT, and a token scheme, showing AI can lower the cost of running influence and fraud operati",
      "date_published": "2026-05-21T00:00:00Z",
      "date_modified": "2026-09-21T10:16:56Z",
      "tags": [
        "AI-Enabled",
        "bandcampro",
        "GoToResolve",
        "StellarMonster",
        "Quantum Patriot",
        "QFS 2.0 Terminal"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Trend Micro",
          "domain": "trendmicro.com",
          "type": "vendor-report"
        },
        "actors": [
          "bandcampro"
        ],
        "malware": [
          "GoToResolve",
          "StellarMonster",
          "Quantum Patriot",
          "QFS 2.0 Terminal"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "Russia",
            "claimed_by": "Trend Micro",
            "confidence": "medium"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-05-19-trend-micro-inside-shadow-water-063-s-banana-rat-fro",
      "url": "https://www.trendmicro.com/en_us/research/26/e/banana-rat.html",
      "title": "Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud",
      "content_text": "Trend Micro's MDR team correlated attacker server infrastructure with victim telemetry to map Banana RAT, a banking trojan targeting 16 Brazilian financial institutions via phishing and fileless PowerShell delivery. The malware provides remote control, keylogging, overlay injection, and PIX QR code interception, using a polymorphic crypter service to evade detection.",
      "date_published": "2026-05-19T00:00:00Z",
      "date_modified": "2026-09-21T08:43:23Z",
      "tags": [
        "AI-Targeted",
        "SHADOW-WATER-063",
        "Banana RAT",
        "Backdoor.PS1.BANANARAT.A"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Trend Micro",
          "domain": "trendmicro.com",
          "type": "vendor-report"
        },
        "actors": [
          "SHADOW-WATER-063"
        ],
        "malware": [
          "Banana RAT",
          "Backdoor.PS1.BANANARAT.A"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "Brazil",
            "claimed_by": "TrendAI",
            "confidence": "high"
          }
        ],
        "also": [
          {
            "name": "Zscaler ThreatLabz",
            "domain": "zscaler.com:443",
            "url": "https://www.zscaler.com:443/blogs/security-research/clickfix-campaign-generated-ai-delivers-smartrat"
          }
        ],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-05-12-gtig-ai-threat-tracker",
      "url": "https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access",
      "title": "GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access",
      "content_text": "GTIG reports adversaries applying AI to vulnerability exploitation, initial access and faster development of evasive, polymorphic malware. It also covers supply chain attacks against AI components, and notes no actor has yet bypassed the core safety logic of frontier models.",
      "date_published": "2026-05-12T00:00:00Z",
      "date_modified": "2026-05-12T06:00:00Z",
      "tags": [
        "AI-Enabled"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Google Threat Intelligence Group",
          "domain": "cloud.google.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": true
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-05-11-trend-micro-vibe-hacking-two-ai-augmented-campaigns",
      "url": "https://www.trendmicro.com/en_us/research/26/e/vibe-hacking-two-ai-augmented-campaigns-target-government-and-financial-sectors-in-latin-america.html",
      "title": "Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America",
      "content_text": "Trend Micro identified two campaigns, SHADOW-AETHER-040 and SHADOW-AETHER-064, using agentic AI (including Claude) to drive intrusions from initial access to data exfiltration against government and financial targets in Mexico and Brazil. The AI agents dynamically generated custom tools and backdoors, used jailbreaking via fake red-team pretexts, and integrated with Shodan and VulDB for reconnaissance.",
      "date_published": "2026-05-11T00:00:00Z",
      "date_modified": "2026-09-21T08:40:31Z",
      "tags": [
        "AI-Enabled",
        "SHADOW-AETHER-040",
        "SHADOW-AETHER-064",
        "Chisel",
        "Neo-reGeorg",
        "CrackMapExec",
        "Impacket",
        "implante_http",
        "ProxyChains",
        "PetitPotam"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Trend Micro",
          "domain": "trendmicro.com",
          "type": "vendor-report"
        },
        "actors": [
          "SHADOW-AETHER-040",
          "SHADOW-AETHER-064"
        ],
        "malware": [
          "Chisel",
          "Neo-reGeorg",
          "CrackMapExec",
          "Impacket",
          "implante_http",
          "ProxyChains",
          "PetitPotam"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-05-07-microsoft-prompts-become-shells",
      "url": "https://www.microsoft.com/en-us/security/blog/2026/05/07/prompts-become-shells-rce-vulnerabilities-ai-agent-frameworks/",
      "title": "When prompts become shells: RCE vulnerabilities in AI agent frameworks",
      "content_text": "Microsoft researchers show how a single injected prompt reached host-level code execution in agents built on Semantic Kernel. Model-controlled parameters flowed unsanitized into a search plugin. Both flaws are fixed.",
      "date_published": "2026-05-07T00:00:00Z",
      "date_modified": "2026-05-07T06:00:00Z",
      "tags": [
        "AI-Targeted",
        "CVE-2026-25592",
        "CVE-2026-26030"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Microsoft Security",
          "domain": "microsoft.com",
          "type": "research"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [
          "CVE-2026-25592",
          "CVE-2026-26030"
        ],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-05-06-cloud-security-alliance-agent-context-poisoning-skill-md-and-the",
      "url": "https://labs.cloudsecurityalliance.org/research/csa-research-note-skill-md-agent-context-poisoning-20260506/",
      "title": "Agent Context Poisoning: SKILL.md and the New AI Supply Chain Attack Surface",
      "content_text": "Cloud Security Alliance details how AI agent skill files like SKILL.md, CLAUDE.md and AGENTS.md create a new supply chain attack surface, since natural-language instructions in these files are trusted and executed by agents at runtime. It cites Snyk's ToxicSkills audit finding security flaws in 36.82% of 3,984 scanned skills and 341 malicious ClawHub skills, plus two Check Point-disclosed CVEs in Claude Code enabling",
      "date_published": "2026-05-06T00:00:00Z",
      "date_modified": "2026-09-21T10:16:46Z",
      "tags": [
        "AI-Targeted",
        "ToxicSkills",
        "OpenClaw",
        "CVE-2025-59536",
        "CVE-2026-21852"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Cloud Security Alliance",
          "domain": "labs.cloudsecurityalliance.org",
          "type": "research"
        },
        "actors": [],
        "malware": [
          "ToxicSkills",
          "OpenClaw"
        ],
        "vulnerabilities": [
          "CVE-2025-59536",
          "CVE-2026-21852"
        ],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-04-23-google-ai-threats-in-the-wild-the-current-state",
      "url": "https://blog.google/security/prompt-injections-web/",
      "title": "AI threats in the wild: The current state of prompt injections on the web",
      "content_text": "Google researchers scanned Common Crawl web archives for indirect prompt injection attempts targeting AI agents that browse websites. Most found examples were low-sophistication pranks, SEO manipulation, or crawler deterrence, with only a small number of malicious data-theft or destructive attempts, none highly advanced. Detections of malicious injections rose 32% between November 2025 and February 2026, suggesting g",
      "date_published": "2026-04-23T00:00:00Z",
      "date_modified": "2026-09-21T10:16:40Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Google",
          "domain": "blog.google",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-04-22-abnormal-ai-ai-meets-voice-phishing-how-athr-automat",
      "url": "https://abnormal.ai/blog/athr-ai-voice-phishing-toad-attacks",
      "title": "AI Meets Voice Phishing: How ATHR Automates the Full TOAD Attack Chain",
      "content_text": "Researchers describe ATHR, a crimeware platform sold for $4,000 plus 10% of profits that combines AI voice agents, spoofed lure emails, and live phishing panels to automate telephone-oriented attack delivery (TOAD) scams. Its AI vishing agents run scripted social engineering calls targeting crypto and email brand users, letting one operator run multi-brand campaigns without trained callers.",
      "date_published": "2026-04-22T00:00:00Z",
      "date_modified": "2026-09-21T10:16:32Z",
      "tags": [
        "AI-Enabled",
        "ATHR"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Abnormal AI",
          "domain": "abnormal.ai",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "ATHR"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-04-14-owasp-exploit-roundup-q1",
      "url": "https://genai.owasp.org/2026/04/14/owasp-genai-exploit-round-up-report-q1-2026/",
      "title": "OWASP GenAI Exploit Round-up Report Q1 2026",
      "content_text": "Quarterly review of eight AI-related incidents mapped to the OWASP LLM and agentic risk lists. It includes active exploitation of a maximum-severity Flowise flaw and GrafanaGhost, a prompt injection path that exfiltrates data from Grafana's AI features.",
      "date_published": "2026-04-14T00:00:00Z",
      "date_modified": "2026-04-14T06:00:00Z",
      "tags": [
        "AI-Targeted",
        "CVE-2025-59528"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "OWASP GenAI Security Project",
          "domain": "genai.owasp.org",
          "type": "research"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [
          "CVE-2025-59528"
        ],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-04-14-validin-hello-i-can-t-hear-you-investigating-unc",
      "url": "https://www.validin.com/blog/i_cant_hear_you_unc1069/",
      "title": "\"Hello? I can't hear you\": Investigating UNC1069's Fake Meeting Tactics",
      "content_text": "Validin details UNC1069 (overlapping with Bluenoroff), a North Korean actor luring crypto and Web3 professionals via fake VC personas into fraudulent Zoom/Teams/Meet-style meetings. Victims are tricked with ClickFix prompts into running malware (updated Cabbage RAT/CageyChameleon variants, NukeSped) across Windows, macOS and Linux, and their audio/video is captured via WebRTC for reuse in later social engineering, in",
      "date_published": "2026-04-14T00:00:00Z",
      "date_modified": "2026-09-21T10:16:09Z",
      "tags": [
        "AI-Targeted",
        "UNC1069",
        "Bluenoroff",
        "Lazarus Group",
        "Cabbage RAT",
        "CageyChameleon",
        "NukeSped"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Validin",
          "domain": "validin.com",
          "type": "vendor-report"
        },
        "actors": [
          "UNC1069",
          "Bluenoroff",
          "Lazarus Group"
        ],
        "malware": [
          "Cabbage RAT",
          "CageyChameleon",
          "NukeSped"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "North Korea",
            "claimed_by": "Validin",
            "confidence": "high"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-04-10-gambit-security-a-single-operator-two-ai-platforms-nine",
      "url": "https://gambit.security/blog-posts/a-single-operator-two-ai-platforms-nine-government-agencies-the-full-technical-report",
      "title": "A Single Operator, Two AI Platforms, Nine Government Agencies: The Full Technical Report",
      "content_text": "Gambit Security's forensic report describes a single operator who used Claude Code and OpenAI's GPT-4.1 as core operational tools to breach nine Mexican government organizations and exfiltrate hundreds of millions of records between December 2025 and February 2026. Recovered materials show over 400 custom attack scripts, 20 tailored exploits, and thousands of AI-generated commands used to compress attack timelines an",
      "date_published": "2026-04-10T00:00:00Z",
      "date_modified": "2026-09-21T08:40:23Z",
      "tags": [
        "AI-Enabled"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Gambit Security",
          "domain": "gambit.security",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "Mexico",
            "claimed_by": "Gambit Security",
            "confidence": "not-stated"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-03-27-datadog-litellm-teampcp",
      "url": "https://securitylabs.datadoghq.com/articles/litellm-compromised-pypi-teampcp-supply-chain-campaign/",
      "title": "LiteLLM and Telnyx compromised on PyPI: Tracing the TeamPCP supply chain campaign",
      "content_text": "Two backdoored releases of LiteLLM, a widely used LLM gateway library, were published to PyPI on March 24, 2026 with a credential stealer. Datadog traces the campaign from a poisoned Trivy scanner through npm and into PyPI.",
      "date_published": "2026-03-27T00:00:00Z",
      "date_modified": "2026-03-27T06:00:00Z",
      "tags": [
        "AI-Targeted",
        "TeamPCP"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Datadog Security Labs",
          "domain": "securitylabs.datadoghq.com",
          "type": "research"
        },
        "actors": [
          "TeamPCP"
        ],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [
          {
            "name": "LiteLLM",
            "domain": "docs.litellm.ai",
            "url": "https://docs.litellm.ai/blog/security-update-march-2026"
          },
          {
            "name": "Trend Micro",
            "domain": "trendmicro.com",
            "url": "https://www.trendmicro.com/en_us/research/26/c/your-ai-stack-just-handed-over-your-root-keys-inside-the-litellm-pypi-breach.html"
          }
        ],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-03-17-unit-42-open-closed-and-broken-prompt-fuzzing-fi",
      "url": "https://unit42.paloaltonetworks.com/genai-llm-prompt-fuzzing/",
      "title": "Open, Closed and Broken: Prompt Fuzzing Finds LLMs Still Fragile Across Open and Closed Models",
      "content_text": "Unit 42 researchers built a genetic algorithm based prompt fuzzing method that automatically generates meaning-preserving variants of disallowed requests to test LLM guardrails. Testing against closed-source and open-weight models plus a content-filter model on explosive-related prompts found evasion rates ranging from 1 percent to 99 percent depending on model and keyword. This is original research showing guardrail",
      "date_published": "2026-03-17T00:00:00Z",
      "date_modified": "2026-09-21T10:15:26Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Unit 42",
          "domain": "unit42.paloaltonetworks.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-03-12-ibm-x-force-a-slopoly-start-to-ai-enhanced-ransomwar",
      "url": "https://www.ibm.com/think/x-force/slopoly-start-ai-enhanced-ransomware-attacks",
      "title": "A Slopoly start to AI-enhanced ransomware attacks",
      "content_text": "IBM X-Force found a likely AI-generated PowerShell C2 backdoor, dubbed Slopoly, deployed by ransomware group Hive0163 during a live intrusion using ClickFix, NodeSnake, InterlockRAT and Interlock ransomware. The malware is technically unremarkable but shows guardrail bypass and signals adoption of AI-assisted malware development among established ransomware actors.",
      "date_published": "2026-03-12T00:00:00Z",
      "date_modified": "2026-09-21T08:40:16Z",
      "tags": [
        "AI-Enabled",
        "Hive0163",
        "ITG23",
        "TA569",
        "TAG-124",
        "Slopoly",
        "NodeSnake",
        "InterlockRAT",
        "Interlock",
        "JunkFiction",
        "Broomstick",
        "Supper",
        "PortStarter"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "IBM X-Force",
          "domain": "ibm.com",
          "type": "vendor-report"
        },
        "actors": [
          "Hive0163",
          "ITG23",
          "TA569",
          "TAG-124"
        ],
        "malware": [
          "Slopoly",
          "NodeSnake",
          "InterlockRAT",
          "Interlock",
          "JunkFiction",
          "Broomstick",
          "Supper",
          "PortStarter"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-03-03-palo-alto-networks-unit--fooling-ai-agents-web-based-indirect-pro",
      "url": "https://unit42.paloaltonetworks.com/ai-agent-prompt-injection/",
      "title": "Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild",
      "content_text": "Unit 42 documents real-world indirect prompt injection attacks embedded in webpages, including the first observed case of an attacker bypassing an AI-based ad review system with a scam advertisement. The researchers catalog 22 payload techniques and a severity taxonomy, showing IDPI moving from proof-of-concept to active exploitation, though some scenarios like ad-checker bypass remain unconfirmed against deployed sy",
      "date_published": "2026-03-03T00:00:00Z",
      "date_modified": "2026-09-21T10:15:13Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Palo Alto Networks Unit 42",
          "domain": "unit42.paloaltonetworks.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-03-02-moonlock-lab-fake-vcs-target-crypto-talent-in-a-new-c",
      "url": "https://moonlock.com/fake-vcs-target-crypto-talent-clickfix-campaign",
      "title": "Fake VCs target crypto talent in a new ClickFix campaign",
      "content_text": "Moonlock Lab documented a campaign using fake venture capital personas on LinkedIn to lure crypto professionals into spoofed Zoom/Meet pages running a ClickFix fake CAPTCHA that tricks victims into executing clipboard-injected commands, deploying cross-platform malware. Fake company sites used AI-generated headshots for fabricated staff, and infrastructure overlaps with DPRK-linked UNC1069, though attribution remains",
      "date_published": "2026-03-02T00:00:00Z",
      "date_modified": "2026-09-21T10:14:58Z",
      "tags": [
        "AI-Enabled",
        "Mykhailo Hureiev",
        "Anatolli Bigdasch",
        "UNC1069"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Moonlock Lab",
          "domain": "moonlock.com",
          "type": "vendor-report"
        },
        "actors": [
          "Mykhailo Hureiev",
          "Anatolli Bigdasch",
          "UNC1069"
        ],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "North Korea",
            "claimed_by": "Moonlock Lab",
            "confidence": "low"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-02-25-openai-disrupting-malicious-uses",
      "url": "https://openai.com/index/disrupting-malicious-ai-uses/",
      "title": "Disrupting malicious uses of AI",
      "content_text": "OpenAI's case studies show models used as one step in larger workflows that also rely on websites and social accounts: romance and recovery scams, covert influence operations, and a state-linked harassment effort.",
      "date_published": "2026-02-25T00:00:00Z",
      "date_modified": "2026-02-25T06:00:00Z",
      "tags": [
        "AI-Enabled",
        "Rybar"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "OpenAI",
          "domain": "openai.com",
          "type": "vendor-report"
        },
        "actors": [
          "Rybar"
        ],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [
          {
            "name": "Help Net Security",
            "domain": "helpnetsecurity.com",
            "url": "https://www.helpnetsecurity.com/2026/02/26/openai-malicious-chatgpt-use-report/"
          }
        ],
        "landmark": true
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-02-23-trendai-research-malicious-openclaw-skills-used-to-distri",
      "url": "https://www.trendaisecurity.com/en-us/resources-insights/trendai-security-blog/malicious-openclaw-skills-used-to-distribute-atomic-macos-stealer",
      "title": "Malicious OpenClaw Skills Used to Distribute Atomic macOS Stealer",
      "content_text": "TrendAI Research documented a campaign where malicious OpenClaw agent skills trick AI agents like GPT-4o into installing a new variant of Atomic macOS Stealer (AMOS), which then deceives users into entering their password. The malware exfiltrates browser data, crypto wallets, Apple and KeePass keychains, and documents, with hundreds of malicious skills found across ClawHub, SkillsMP, and GitHub repositories.",
      "date_published": "2026-02-23T00:00:00Z",
      "date_modified": "2026-09-21T08:40:00Z",
      "tags": [
        "AI-Targeted",
        "Atomic (AMOS) Stealer",
        "AMOS"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "TrendAI Research",
          "domain": "trendaisecurity.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "Atomic (AMOS) Stealer",
          "AMOS"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-02-21-hunt-io-cyberandramen-ne-llms-in-the-kill-chain-inside-a-custom-m",
      "url": "https://cyberandramen.net/2026/02/21/llms-in-the-kill-chain-inside-a-custom-mcp-targeting-fortigate-devices-across-continents/",
      "title": "LLMs in the Kill Chain: Inside a Custom MCP Targeting FortiGate Devices Across Continents",
      "content_text": "Researchers found an exposed server revealing a threat actor using a custom MCP server (ARXON) with DeepSeek and Claude Code to automate reconnaissance, attack planning, and exploitation of compromised FortiGate devices across thousands of targets in over 100 countries. The actor evolved from using open-source HexStrike MCP tooling in December 2025 to fully custom orchestration (ARXON and CHECKER2) by February 2026,",
      "date_published": "2026-02-21T00:00:00Z",
      "date_modified": "2026-09-21T08:39:34Z",
      "tags": [
        "AI-Enabled",
        "ARXON",
        "CHECKER2",
        "HexStrike",
        "ntlmrelayx.py",
        "Impacket",
        "Metasploit",
        "BloodHound",
        "Nuclei",
        "CVE-2019-6693",
        "CVE-2026-24061",
        "CVE-2025-33073",
        "CVE-2023-27532",
        "CVE-2019-7192"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Hunt.io / cyberandramen.net",
          "domain": "cyberandramen.net",
          "type": "research"
        },
        "actors": [],
        "malware": [
          "ARXON",
          "CHECKER2",
          "HexStrike",
          "ntlmrelayx.py",
          "Impacket",
          "Metasploit",
          "BloodHound",
          "Nuclei"
        ],
        "vulnerabilities": [
          "CVE-2019-6693",
          "CVE-2026-24061",
          "CVE-2025-33073",
          "CVE-2023-27532",
          "CVE-2019-7192"
        ],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-02-20-amazon-threat-intelligen-ai-augmented-threat-actor-accesses-forti",
      "url": "https://aws.amazon.com/blogs/security/ai-augmented-threat-actor-accesses-fortigate-devices-at-scale/",
      "title": "AI-augmented threat actor accesses FortiGate devices at scale",
      "content_text": "Amazon Threat Intelligence documented a Russian-speaking, financially motivated actor using multiple commercial LLMs to compromise over 600 FortiGate devices in 55+ countries via exposed management interfaces and weak credentials, not exploits. AI generated attack plans, custom Go/Python tooling, and reconnaissance scripts, letting a low-skill actor achieve broad operational scale, though it still failed against hard",
      "date_published": "2026-02-20T00:00:00Z",
      "date_modified": "2026-09-21T08:39:05Z",
      "tags": [
        "AI-Enabled",
        "Ed1s0nZ",
        "Meterpreter",
        "mimikatz",
        "gogo",
        "Nuclei",
        "CyberStrikeAI",
        "PrivHunterAI",
        "InfiltrateX",
        "watermark-tool",
        "CVE-2019-7192",
        "CVE-2023-27532",
        "CVE-2024-40711"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Amazon Threat Intelligence",
          "domain": "aws.amazon.com",
          "type": "vendor-report"
        },
        "actors": [
          "Ed1s0nZ"
        ],
        "malware": [
          "Meterpreter",
          "mimikatz",
          "gogo",
          "Nuclei",
          "CyberStrikeAI",
          "PrivHunterAI",
          "InfiltrateX",
          "watermark-tool"
        ],
        "vulnerabilities": [
          "CVE-2019-7192",
          "CVE-2023-27532",
          "CVE-2024-40711"
        ],
        "attribution": [],
        "also": [
          {
            "name": "Team Cymru",
            "domain": "team-cymru.com",
            "url": "https://www.team-cymru.com/post/tracking-cyberstrikeai-usage"
          }
        ],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-02-19-eset-research-promptspy-ushers-in-the-era-of-android-t",
      "url": "https://www.welivesecurity.com/en/eset-research/promptspy-ushers-in-era-android-threats-using-genai/",
      "title": "PromptSpy ushers in the era of Android threats using GenAI",
      "content_text": "ESET found PromptSpy, Android malware that queries Google's Gemini with UI XML dumps to get step-by-step instructions for locking itself into the recent apps list, aiding persistence. The malware also deploys a VNC module for remote device control and targets users in Argentina; no live samples have been seen in telemetry, suggesting it may still be a proof of concept.",
      "date_published": "2026-02-19T00:00:00Z",
      "date_modified": "2026-09-21T08:39:17Z",
      "tags": [
        "AI-Enabled",
        "PromptSpy",
        "VNCSpy",
        "PromptLock",
        "Android.Phantom",
        "Android/Phishing.Agent.M"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "ESET Research",
          "domain": "welivesecurity.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "PromptSpy",
          "VNCSpy",
          "PromptLock",
          "Android.Phantom",
          "Android/Phishing.Agent.M"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "China",
            "claimed_by": "ESET",
            "confidence": "medium"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-02-12-gtig-distillation-experimentation",
      "url": "https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use",
      "title": "GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use",
      "content_text": "Quarterly view of how actors linked to North Korea, Iran, China and Russia used AI in late 2025. GTIG saw no breakthrough capability, but disrupted frequent model extraction attempts against its own models.",
      "date_published": "2026-02-12T00:00:00Z",
      "date_modified": "2026-02-12T06:00:00Z",
      "tags": [
        "AI-Enabled"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Google Threat Intelligence Group",
          "domain": "cloud.google.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "North Korea",
            "claimed_by": "Google Threat Intelligence Group",
            "confidence": "not-stated"
          },
          {
            "country": "Iran",
            "claimed_by": "Google Threat Intelligence Group",
            "confidence": "not-stated"
          },
          {
            "country": "China",
            "claimed_by": "Google Threat Intelligence Group",
            "confidence": "not-stated"
          },
          {
            "country": "Russia",
            "claimed_by": "Google Threat Intelligence Group",
            "confidence": "not-stated"
          }
        ],
        "also": [
          {
            "name": "Google",
            "domain": "blog.google",
            "url": "https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/gtig-report-ai-cyber-attacks-feb-2026/"
          }
        ],
        "landmark": true
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-02-11-moonlock-lab-moonlock-lab-thread-on-clickfix-malware",
      "url": "https://x.com/moonlock_lab/status/2021695650367226108?s=12",
      "title": "Moonlock Lab thread on ClickFix malware abusing Claude.ai and Medium",
      "content_text": "Moonlock Lab reports that a Google Sponsored ad for a macOS search led users to malware via ClickFix delivery, seen over 15,000 times. One variant abused a public artifact hosted on claude.ai, while another used a Medium post impersonating Apple support, both attributed to the same threat actor.",
      "date_published": "2026-02-11T00:00:00Z",
      "date_modified": "2026-09-21T08:38:42Z",
      "tags": [
        "AI-Targeted",
        "ClickFix"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Moonlock Lab",
          "domain": "x.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "ClickFix"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-02-05-snyk-snyk-finds-prompt-injection-in-36-1467-m",
      "url": "https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub/",
      "title": "Snyk Finds Prompt Injection in 36%, 1467 Malicious Payloads in a ToxicSkills Study of Agent Skills Supply Chain Compromise",
      "content_text": "Snyk scanned 3,984 AI agent skills from ClawHub and skills.sh and found 534 with critical security issues and 76 confirmed malicious payloads designed for credential theft, backdoors, or data exfiltration, with 8 still live on ClawHub. The research shows attackers combining prompt injection with malicious code to bypass agent safety mechanisms in Claude Code, Cursor, and OpenClaw skills.",
      "date_published": "2026-02-05T00:00:00Z",
      "date_modified": "2026-09-21T09:57:51Z",
      "tags": [
        "AI-Targeted",
        "ToxicSkills"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Snyk",
          "domain": "snyk.io",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "ToxicSkills"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-01-26-resecurity-breaking-trust-with-words-prompt-injecti",
      "url": "https://www.resecurity.com/blog/article/breaking-trust-with-words-prompt-injection-leading-to-simulated-etcpasswd-disclosure",
      "title": "Breaking Trust with Words: Prompt Injection Leading to Simulated /etc/passwd Disclosure",
      "content_text": "Resecurity describes penetration testing work on enterprise AI applications, including a banking and HR chatbot, showing how prompt injection can trick an LLM into simulating disclosure of a sensitive Linux file like /etc/passwd. The piece explains direct and indirect prompt injection techniques and several proof-of-concept attack patterns observed during assessments, not confirmed real-world breaches.",
      "date_published": "2026-01-26T00:00:00Z",
      "date_modified": "2026-09-21T10:14:38Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Resecurity",
          "domain": "resecurity.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-01-22-unit-42-palo-alto-networ-the-next-frontier-of-runtime-assembly-at",
      "url": "https://unit42.paloaltonetworks.com/real-time-malicious-javascript-through-llms/",
      "title": "The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time",
      "content_text": "Unit 42 researchers built a proof of concept where a benign-looking webpage queries trusted LLM APIs like DeepSeek and Gemini at runtime to generate and assemble phishing JavaScript in the victim's browser, bypassing network detection and guardrails through prompt engineering. This produces polymorphic, brand-impersonating phishing pages with no static malicious payload, though the technique was not observed used by",
      "date_published": "2026-01-22T00:00:00Z",
      "date_modified": "2026-09-21T10:14:32Z",
      "tags": [
        "AI-Enabled",
        "LogoKit"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Unit 42 (Palo Alto Networks)",
          "domain": "unit42.paloaltonetworks.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "LogoKit"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-01-21-breached-company-the-lethal-trifecta-strikes-four-major-a",
      "url": "https://breached.company/the-lethal-trifecta-strikes-four-major-ai-agent-vulnerabilities-in-five-days/",
      "title": "The Lethal Trifecta Strikes: Four Major AI Agent Vulnerabilities in Five Days",
      "content_text": "Between January 7-15, 2026, researchers including PromptArmor disclosed indirect prompt injection vulnerabilities in four production AI tools: IBM Bob, Superhuman AI, Notion AI, and Anthropic's Claude Cowork, each allowing data exfiltration via the 'lethal trifecta' of private data access, untrusted content exposure, and external communication channels. Vendor responses varied widely, from Superhuman's rapid remediat",
      "date_published": "2026-01-21T00:00:00Z",
      "date_modified": "2026-09-21T08:41:18Z",
      "tags": [
        "AI-Targeted",
        "Claude Cowork",
        "IBM Bob",
        "Notion AI",
        "Superhuman AI",
        "Superhuman Go"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Breached.company",
          "domain": "breached.company",
          "type": "news"
        },
        "actors": [],
        "malware": [
          "Claude Cowork",
          "IBM Bob",
          "Notion AI",
          "Superhuman AI",
          "Superhuman Go"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-01-08-greynoise-threat-actors-actively-targeting-llms",
      "url": "https://www.greynoise.io/blog/threat-actors-actively-targeting-llms",
      "title": "Threat Actors Actively Targeting LLMs",
      "content_text": "GreyNoise honeypots recorded two campaigns targeting LLM infrastructure between October 2025 and January 2026: an SSRF campaign abusing Ollama model pulls and Twilio webhooks, and an 11 day enumeration campaign probing 73+ LLM endpoints across major providers to find exposed API proxies. The enumeration IPs overlap with infrastructure known for scanning 200+ CVEs, suggesting reconnaissance feeding a broader exploitat",
      "date_published": "2026-01-08T00:00:00Z",
      "date_modified": "2026-09-21T10:14:19Z",
      "tags": [
        "AI-Targeted",
        "CVE-2025-55182",
        "CVE-2023-1389"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "GreyNoise",
          "domain": "greynoise.io",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [
          "CVE-2025-55182",
          "CVE-2023-1389"
        ],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-12-10-huntress-ai-poisoning-amos-stealer-the-biggest-ma",
      "url": "https://www.huntress.com/blog/amos-stealer-chatgpt-grok-ai-trust",
      "title": "AI-Poisoning & AMOS Stealer: The Biggest Mac Threat",
      "content_text": "Huntress found that attackers used SEO poisoning to push fake ChatGPT and Grok shared conversations, hosted on legitimate OpenAI and xAI domains, to the top of Google results for common Mac troubleshooting queries. Victims who followed the AI-generated Terminal instructions were infected with an AMOS stealer variant that harvests credentials, escalates to root, and persists via a LaunchDaemon watchdog.",
      "date_published": "2025-12-10T00:00:00Z",
      "date_modified": "2026-09-21T10:14:12Z",
      "tags": [
        "AI-Enabled",
        "AMOS",
        "Atomic macOS Stealer"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Huntress",
          "domain": "huntress.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "AMOS",
          "Atomic macOS Stealer"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-12-05-unit-42-palo-alto-networ-new-prompt-injection-attack-vectors-thro",
      "url": "https://unit42.paloaltonetworks.com/model-context-protocol-attack-vectors/",
      "title": "New Prompt Injection Attack Vectors Through MCP Sampling",
      "content_text": "Unit 42 researchers show that the Model Context Protocol sampling feature, which lets MCP servers request LLM completions from the client, lacks security controls and trusts servers implicitly. They built a proof-of-concept malicious MCP server against an unnamed coding copilot demonstrating resource theft via hidden prompts, conversation hijacking, and covert tool invocation. No in-the-wild exploitation is claimed;",
      "date_published": "2025-12-05T00:00:00Z",
      "date_modified": "2026-09-21T08:38:25Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Unit 42 (Palo Alto Networks)",
          "domain": "unit42.paloaltonetworks.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-11-25-unit-42-the-dual-use-dilemma-of-ai-malicious-llm",
      "url": "https://unit42.paloaltonetworks.com/dilemma-of-ai-malicious-llms/",
      "title": "The Dual-Use Dilemma of AI: Malicious LLMs",
      "content_text": "Unit 42 examines two commercialized malicious LLMs, WormGPT and KawaiiGPT, sold or freely distributed to cybercriminals for generating phishing, BEC lures, ransomware code and ransom notes. Testing showed WormGPT 4 producing functional PowerShell ransomware scripts and KawaiiGPT crafting convincing spear-phishing content, lowering technical barriers for less-skilled attackers.",
      "date_published": "2025-11-25T00:00:00Z",
      "date_modified": "2026-09-21T10:13:54Z",
      "tags": [
        "AI-Enabled",
        "WormGPT",
        "WormGPT 4",
        "KawaiiGPT"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Unit 42",
          "domain": "unit42.paloaltonetworks.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "WormGPT",
          "WormGPT 4",
          "KawaiiGPT"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-11-20-netskope-the-future-of-malware-is-llm-powered",
      "url": "https://www.netskope.com/blog/the-future-of-malware-is-llm-powered",
      "title": "The Future of Malware is LLM-powered",
      "content_text": "Netskope Threat Labs tested whether GPT-3.5-Turbo, GPT-4 and preliminary GPT-5 could be prompted or jailbroken into generating malicious code for process injection and VM detection. They found guardrails could be bypassed with role-based prompt injection but generated code was often unreliable, especially against cloud VDI, though GPT-5 showed marked improvement. This is proof-of-concept research, not an observed rea",
      "date_published": "2025-11-20T00:00:00Z",
      "date_modified": "2026-09-21T10:13:45Z",
      "tags": [
        "AI-Enabled"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Netskope",
          "domain": "netskope.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-11-13-anthropic-gtg-1002",
      "url": "https://assets.anthropic.com/m/ec212e6566a0d47/original/Disrupting-the-first-reported-AI-orchestrated-cyber-espionage-campaign.pdf",
      "title": "Disrupting the first reported AI-orchestrated cyber espionage campaign",
      "content_text": "A group tasked Claude Code with running intrusions against roughly 30 organisations, with the model carrying out an estimated 80 to 90 percent of tactical work. Anthropic validated a handful of successful compromises before banning the accounts.",
      "date_published": "2025-11-13T00:00:00Z",
      "date_modified": "2025-11-13T06:00:00Z",
      "tags": [
        "AI-Enabled",
        "GTG-1002",
        "Chinese state-sponsored group",
        "Claude Code"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Anthropic",
          "domain": "anthropic.com",
          "type": "vendor-report"
        },
        "actors": [
          "GTG-1002",
          "Chinese state-sponsored group"
        ],
        "malware": [
          "Claude Code"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "China",
            "claimed_by": "Anthropic",
            "confidence": "high"
          }
        ],
        "also": [
          {
            "name": "Anthropic",
            "domain": "anthropic.com",
            "url": "https://www.anthropic.com/news/disrupting-AI-espionage"
          }
        ],
        "landmark": true
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-11-05-gtig-advances-ai-tools",
      "url": "https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools",
      "title": "GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools",
      "content_text": "GTIG documents the first malware families that query an LLM during execution to generate scripts and rewrite their own code. It also describes actors posing as students or researchers to talk Gemini past its safeguards.",
      "date_published": "2025-11-05T00:00:00Z",
      "date_modified": "2025-11-05T06:00:00Z",
      "tags": [
        "AI-Enabled",
        "APT28",
        "PROMPTFLUX",
        "PROMPTSTEAL"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Google Threat Intelligence Group",
          "domain": "cloud.google.com",
          "type": "vendor-report"
        },
        "actors": [
          "APT28"
        ],
        "malware": [
          "PROMPTFLUX",
          "PROMPTSTEAL"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": true
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-11-05-infosecurity-claude-extensions",
      "url": "https://www.infosecurity-magazine.com/news/claude-desktop-extensions-prompt/",
      "title": "Claude Desktop Extensions Vulnerable to Web-Based Prompt Injection",
      "content_text": "Researchers reported that extensions for the Claude desktop app could be driven by instructions planted in web content, turning an ordinary browsing request into a path to actions on the user's machine.",
      "date_published": "2025-11-05T00:00:00Z",
      "date_modified": "2025-11-05T06:00:00Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Infosecurity Magazine",
          "domain": "infosecurity-magazine.com",
          "type": "news"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-10-08-volexity-apt-meets-gpt-targeted-operations-with-u",
      "url": "https://www.volexity.com/blog/2025/10/08/apt-meets-gpt-targeted-operations-with-untamed-llms/",
      "title": "APT Meets GPT: Targeted Operations with Untamed LLMs",
      "content_text": "Volexity documents UTA0388, a China-aligned actor running spear phishing campaigns since June 2025 that deploy the GOVERSHELL backdoor via search order hijacking. Volexity assesses with high confidence the group used LLMs, later confirmed by OpenAI, to assist phishing content and malware development, and links the group to Proofpoint's previously reported UNK_DropPitch/HealthKick activity.",
      "date_published": "2025-10-08T00:00:00Z",
      "date_modified": "2026-09-21T10:13:23Z",
      "tags": [
        "AI-Enabled",
        "UTA0388",
        "UNK_DropPitch",
        "GOVERSHELL",
        "HealthKick",
        "Tablacus Explorer"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Volexity",
          "domain": "volexity.com",
          "type": "vendor-report"
        },
        "actors": [
          "UTA0388",
          "UNK_DropPitch"
        ],
        "malware": [
          "GOVERSHELL",
          "HealthKick",
          "Tablacus Explorer"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "China",
            "claimed_by": "Volexity",
            "confidence": "high"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-10-07-openai-october-report",
      "url": "https://openai.com/global-affairs/disrupting-malicious-uses-of-ai-october-2025/",
      "title": "Disrupting malicious uses of AI: October 2025",
      "content_text": "OpenAI details banned accounts tied to state actors and criminal groups that used ChatGPT for malware development, scams and surveillance tooling. It reports no evidence that its models gave attackers novel offensive capability.",
      "date_published": "2025-10-07T00:00:00Z",
      "date_modified": "2025-10-07T06:00:00Z",
      "tags": [
        "AI-Enabled",
        "Russian-speaking criminal groups",
        "North Korean (DPRK) actors",
        "XenoRAT"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "OpenAI",
          "domain": "openai.com",
          "type": "vendor-report"
        },
        "actors": [
          "Russian-speaking criminal groups",
          "North Korean (DPRK) actors"
        ],
        "malware": [
          "XenoRAT"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [
          {
            "name": "IT Brew",
            "domain": "itbrew.com",
            "url": "https://www.itbrew.com/stories/2025/10/15/openai-disruption-report"
          },
          {
            "name": "OpenAI",
            "domain": "cdn.openai.com",
            "url": "https://cdn.openai.com/threat-intelligence-reports/7d662b68-952f-4dfd-a2f2-fe55b041cc4a/disrupting-malicious-uses-of-ai-october-2025.pdf"
          }
        ],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-09-29-eset-research-deceptivedevelopment-from-primitive-cryp",
      "url": "https://www.welivesecurity.com/en/eset-research/deceptivedevelopment-from-primitive-crypto-theft-to-sophisticated-ai-based-deception/",
      "title": "DeceptiveDevelopment: From primitive crypto theft to sophisticated AI-based deception",
      "content_text": "ESET details DeceptiveDevelopment, a North Korea-aligned group using fake recruiter profiles and ClickFix social engineering to deliver malware like BeaverTail, InvisibleFerret, OtterCookie, WeaselStore and TsunamiKit to job-seeking developers across Windows, Linux and macOS. The group is closely linked to North Korean IT worker campaigns (WageMole) that use AI-driven tools to fabricate synthetic identities to secure",
      "date_published": "2025-09-29T00:00:00Z",
      "date_modified": "2026-09-21T10:13:05Z",
      "tags": [
        "AI-Enabled",
        "DeceptiveDevelopment",
        "WageMole",
        "Contagious Interview",
        "DEV#POPPER",
        "Void Dokkaebi",
        "Lazarus",
        "BeaverTail",
        "InvisibleFerret",
        "OtterCookie",
        "WeaselStore",
        "GolangGhost",
        "FlexibleFerret",
        "PylangGhost",
        "TsunamiKit"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "ESET Research",
          "domain": "welivesecurity.com",
          "type": "vendor-report"
        },
        "actors": [
          "DeceptiveDevelopment",
          "WageMole",
          "Contagious Interview",
          "DEV#POPPER",
          "Void Dokkaebi",
          "Lazarus"
        ],
        "malware": [
          "BeaverTail",
          "InvisibleFerret",
          "OtterCookie",
          "WeaselStore",
          "GolangGhost",
          "FlexibleFerret",
          "PylangGhost",
          "TsunamiKit"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "North Korea",
            "claimed_by": "ESET Research",
            "confidence": "high"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-09-25-koi-postmark-mcp",
      "url": "https://www.koi.ai/blog/postmark-mcp-npm-malicious-backdoor-email-theft",
      "title": "First Malicious MCP in the Wild: The Postmark Backdoor That's Stealing Your Emails",
      "content_text": "An npm package posing as the Postmark MCP server behaved normally for fifteen versions, then added one line that copied every email sent through it to the author's server. Koi calls it the first malicious MCP server seen in the wild.",
      "date_published": "2025-09-25T00:00:00Z",
      "date_modified": "2025-09-25T06:00:00Z",
      "tags": [
        "AI-Targeted",
        "Jabal Torres",
        "phanpak",
        "postmark-mcp"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Koi Security",
          "domain": "koi.ai",
          "type": "research"
        },
        "actors": [
          "Jabal Torres",
          "phanpak"
        ],
        "malware": [
          "postmark-mcp"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [
          {
            "name": "The Hacker News",
            "domain": "thehackernews.com",
            "url": "https://thehackernews.com/2025/09/first-malicious-mcp-server-found.html"
          },
          {
            "name": "Dark Reading",
            "domain": "darkreading.com",
            "url": "https://www.darkreading.com/application-security/malicious-mcp-server-exfiltrates-secrets-bcc"
          },
          {
            "name": "Snyk",
            "domain": "snyk.io",
            "url": "https://snyk.io/blog/malicious-mcp-server-on-npm-postmark-mcp-harvests-emails/"
          }
        ],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-09-23-dataconomy-malterminal",
      "url": "https://dataconomy.com/2025/09/23/sentinelone-finds-malterminal-malware-using-openai-gpt-4/",
      "title": "SentinelOne finds MalTerminal malware using OpenAI GPT-4",
      "content_text": "SentinelLABS hunted for binaries carrying LLM API keys and embedded prompts, and found MalTerminal, which asks GPT-4 to write ransomware or a reverse shell at runtime. A retired API endpoint dates it before November 2023. No live use is known.",
      "date_published": "2025-09-23T00:00:00Z",
      "date_modified": "2025-09-23T06:00:00Z",
      "tags": [
        "AI-Enabled",
        "MalTerminal"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Dataconomy",
          "domain": "dataconomy.com",
          "type": "news"
        },
        "actors": [],
        "malware": [
          "MalTerminal"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-09-16-genians-ai-driven-deepfake-based-military-id-for",
      "url": "https://www.genians.co.kr/en/blog/threat_intelligence/deepfake",
      "title": "AI-Driven Deepfake-Based Military ID Forgery APT Campaign",
      "content_text": "Genians Security Center documented a July 2025 spear-phishing campaign impersonating a South Korean military ID office, where the attacker used ChatGPT to generate a fake military employee ID image, verified via metadata and deepfake detection tools. The email delivered obfuscated LNK and batch scripts leading to an AutoIt-based backdoor for persistence and C2 communication.",
      "date_published": "2025-09-16T00:00:00Z",
      "date_modified": "2026-09-21T10:12:41Z",
      "tags": [
        "AI-Enabled",
        "AutoIt3",
        "config.bin",
        "HncUpdateTray.exe"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Genians",
          "domain": "genians.co.kr",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "AutoIt3",
          "config.bin",
          "HncUpdateTray.exe"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-09-16-securelist-a-new-revengehotels-campaign-targets-lat",
      "url": "https://securelist.com/revengehotels-attacks-with-ai-and-venomrat-across-latin-america/117493/",
      "title": "A new RevengeHotels campaign targets Latin America",
      "content_text": "Kaspersky reports that RevengeHotels (TA558), a hotel-targeting phishing group, now uses LLM-generated code in its JavaScript loaders and PowerShell downloaders to deliver VenomRAT. The campaign targets Brazilian and Spanish-speaking hotels via invoice-themed phishing emails, showing how a known criminal group is adopting AI to build malware components.",
      "date_published": "2025-09-16T00:00:00Z",
      "date_modified": "2026-09-21T10:12:50Z",
      "tags": [
        "AI-Enabled",
        "RevengeHotels",
        "TA558",
        "VenomRAT",
        "QuasarRAT",
        "RevengeRAT",
        "NanoCoreRAT",
        "NjRAT",
        "888 RAT",
        "ProCC",
        "XWorm",
        "CVE-2017-0199"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Securelist",
          "domain": "securelist.com",
          "type": "research"
        },
        "actors": [
          "RevengeHotels",
          "TA558"
        ],
        "malware": [
          "VenomRAT",
          "QuasarRAT",
          "RevengeRAT",
          "NanoCoreRAT",
          "NjRAT",
          "888 RAT",
          "ProCC",
          "XWorm"
        ],
        "vulnerabilities": [
          "CVE-2017-0199"
        ],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-09-15-kaspersky-securelist-malicious-mcp-servers-used-in-supply-cha",
      "url": "https://securelist.com/model-context-protocol-for-ai-integration-abused-in-supply-chain-attacks/117473/",
      "title": "Malicious MCP servers used in supply chain attacks",
      "content_text": "Kaspersky describes how the Model Context Protocol (MCP), used to connect AI assistants to tools, can be abused via protocol-level tricks like tool poisoning and shadowing, and via supply chain attacks with malicious MCP packages. They built a proof-of-concept MCP server disguised as a developer productivity tool that harvested SSH keys, credentials and environment files while appearing legitimate. This was a control",
      "date_published": "2025-09-15T00:00:00Z",
      "date_modified": "2026-09-21T10:12:16Z",
      "tags": [
        "AI-Targeted",
        "devtools-assistant"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Kaspersky Securelist",
          "domain": "securelist.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "devtools-assistant"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-09-15-unit-42-palo-alto-networ-the-risks-of-code-assistant-llms-harmful",
      "url": "https://unit42.paloaltonetworks.com/code-assistant-llms/",
      "title": "The Risks of Code Assistant LLMs: Harmful Content, Misuse and Deception",
      "content_text": "Unit 42 researchers demonstrate that AI code assistant IDE plugins are vulnerable to indirect prompt injection via contaminated context sources like scraped social media data, causing assistants to insert hidden backdoors into generated code. They also show auto-completion features can be manipulated to bypass safety guardrails and generate harmful content, and that direct model invocation exposes models to further m",
      "date_published": "2025-09-15T00:00:00Z",
      "date_modified": "2026-09-21T10:12:07Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Unit 42 (Palo Alto Networks)",
          "domain": "unit42.paloaltonetworks.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-09-03-netskope-securing-llm-superpowers-when-tools-turn",
      "url": "https://www.netskope.com/blog/securing-llm-superpowers-when-tools-turn-hostile-in-mcp",
      "title": "Securing LLM Superpowers: When Tools Turn Hostile in MCP",
      "content_text": "Netskope describes two proof-of-concept attack techniques against MCP-based LLM deployments: prompt injection hidden in tool description metadata, and cross-server tool shadowing where a malicious server poisons the LLM's shared context to silently alter calls to trusted tools like email. Both exploit MCP's lack of isolation and provenance checks, evading logs and user-facing UI, and the article proposes signing, san",
      "date_published": "2025-09-03T00:00:00Z",
      "date_modified": "2026-09-21T10:11:48Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Netskope",
          "domain": "netskope.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-08-27-anthropic-threat-intel-august",
      "url": "https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf",
      "title": "Threat Intelligence Report: August 2025",
      "content_text": "Introduces vibe hacking: one criminal used Claude Code to run data extortion against at least 17 organisations. Other cases cover North Korean remote worker fraud, ransomware sold by a developer with little coding skill, and AI across the fraud ecosystem.",
      "date_published": "2025-08-27T00:00:00Z",
      "date_modified": "2025-08-27T06:00:00Z",
      "tags": [
        "AI-Enabled",
        "North Korean IT workers",
        "Claude Code",
        "Claude"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Anthropic",
          "domain": "anthropic.com",
          "type": "vendor-report"
        },
        "actors": [
          "North Korean IT workers"
        ],
        "malware": [
          "Claude Code",
          "Claude"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "North Korea",
            "claimed_by": "Anthropic",
            "confidence": "not-stated"
          },
          {
            "country": "China",
            "claimed_by": "Anthropic",
            "confidence": "not-stated"
          }
        ],
        "also": [
          {
            "name": "Anthropic",
            "domain": "anthropic.com",
            "url": "https://www.anthropic.com/news/detecting-countering-misuse-aug-2025"
          }
        ],
        "landmark": true
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-08-26-eset-promptlock",
      "url": "https://welivesecurity.com/en/ransomware/first-known-ai-powered-ransomware-uncovered-eset-research",
      "title": "First known AI-powered ransomware uncovered by ESET Research",
      "content_text": "PromptLock runs OpenAI's gpt-oss-20b locally through Ollama to generate Lua scripts that enumerate, exfiltrate and encrypt files. ESET later confirmed the samples match an academic prototype, not malware deployed in attacks.",
      "date_published": "2025-08-26T00:00:00Z",
      "date_modified": "2025-08-26T06:00:00Z",
      "tags": [
        "AI-Enabled",
        "PromptLock"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "ESET Research",
          "domain": "welivesecurity.com",
          "type": "research"
        },
        "actors": [],
        "malware": [
          "PromptLock"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-08-13-securelist-phishing-and-scams-how-fraudsters-are-de",
      "url": "https://securelist.com/new-phishing-and-scam-trends-in-2025/117217/",
      "title": "Phishing and scams: how fraudsters are deceiving users in 2025",
      "content_text": "Kaspersky researchers describe how scammers now use AI tools such as DeepSeek to write convincing phishing text, AI-generated voices and deepfakes for fake celebrity giveaways and bank impersonation calls, and OSINT AI tools to personalize attacks. The report also covers new evasion techniques like blob URLs, Google Translate proxying, and Telegram bot abuse, and a shift toward stealing biometric and signature data.",
      "date_published": "2025-08-13T00:00:00Z",
      "date_modified": "2026-09-21T10:11:40Z",
      "tags": [
        "AI-Enabled",
        "DeepSeek"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Securelist",
          "domain": "securelist.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "DeepSeek"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-08-01-thn-cursor-curxecute",
      "url": "https://thehackernews.com/2025/08/cursor-ai-code-editor-fixed-flaw.html",
      "title": "Cursor AI Code Editor Fixed Flaw Allowing Attackers to Run Commands via Prompt Injection",
      "content_text": "An indirect prompt injection could make Cursor's agent write a malicious MCP configuration file without user approval, giving the attacker remote code execution on the developer's machine.",
      "date_published": "2025-08-01T00:00:00Z",
      "date_modified": "2025-08-01T06:00:00Z",
      "tags": [
        "AI-Targeted",
        "CVE-2025-54135"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "The Hacker News",
          "domain": "thehackernews.com",
          "type": "news"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [
          "CVE-2025-54135"
        ],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-07-18-thn-lamehug",
      "url": "https://guardsix.com/blog/apt28s-new-arsenal-lamehug-the-first-ai-powered-malware",
      "title": "LAMEHUG: APT28's New Arsenal - First AI-Powered Malware Explained",
      "content_text": "CERT-UA reported that APT28 (UAC-0001) used LameHug, a Python malware delivered via phishing that queries the Qwen 2.5-Coder-32B-Instruct model through the Hugging Face API to generate Windows recon and exfiltration commands. This is described as one of the first publicly documented cases of malware using an LLM to dynamically generate attack commands against Ukrainian defense sector targets. Guardsix summarizes the",
      "date_published": "2025-07-30T00:00:00Z",
      "date_modified": "2025-07-18T06:00:00Z",
      "tags": [
        "AI-Enabled",
        "APT28",
        "UAC-0001",
        "Forest Blizzard",
        "LAMEHUG",
        "LameHug",
        "AI_generator_uncensored_Canvas_PRO_v0.9.exe",
        "image.py"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "guardsix",
          "domain": "guardsix.com",
          "type": "vendor-report"
        },
        "actors": [
          "APT28",
          "UAC-0001",
          "Forest Blizzard"
        ],
        "malware": [
          "LAMEHUG",
          "LameHug",
          "AI_generator_uncensored_Canvas_PRO_v0.9.exe",
          "image.py"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "Russia",
            "claimed_by": "CERT-UA",
            "confidence": "medium"
          }
        ],
        "also": [
          {
            "name": "The Hacker News",
            "domain": "thehackernews.com",
            "url": "https://thehackernews.com/2025/07/cert-ua-discovers-lamehug-malware.html"
          }
        ],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-06-25-check-point-research-in-the-wild-malware-prototype-with-embed",
      "url": "https://research.checkpoint.com/2025/ai-evasion-prompt-injection/",
      "title": "In the Wild: Malware Prototype with Embedded Prompt Injection",
      "content_text": "Check Point found a malware sample uploaded to VirusTotal that embeds a prompt injection string attempting to instruct AI models analyzing it to output 'NO MALWARE DETECTED'. The attack failed against tested LLMs (OpenAI o3 and gpt-4.1) and appears to be an early proof-of-concept, but signals growing attempts to evade AI-based malware analysis tools.",
      "date_published": "2025-06-25T00:00:00Z",
      "date_modified": "2026-09-21T10:11:08Z",
      "tags": [
        "AI-Targeted",
        "Skynet"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Check Point Research",
          "domain": "research.checkpoint.com",
          "type": "research"
        },
        "actors": [],
        "malware": [
          "Skynet"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-06-25-cisco-talos-cybercriminal-abuse-of-large-language-mo",
      "url": "https://blog.talosintelligence.com/cybercriminal-abuse-of-large-language-models/",
      "title": "Cybercriminal abuse of large language models",
      "content_text": "Talos researchers document cybercriminals using uncensored LLMs, custom criminal LLMs like FraudGPT and WormGPT, and jailbreak techniques to write malware, phishing content and scan for vulnerabilities. The report also covers attacks against LLMs themselves, including pickle-based backdoored models on Hugging Face and RAG poisoning risks. Talos found that FraudGPT's seller was actually running a cryptocurrency scam r",
      "date_published": "2025-06-25T00:00:00Z",
      "date_modified": "2026-09-21T10:11:02Z",
      "tags": [
        "AI-Enabled",
        "CanadianKingpin12",
        "GhostGPT",
        "WormGPT",
        "DarkGPT",
        "DarkestGPT",
        "FraudGPT",
        "WhiteRabbitNeo",
        "Llama 2 Uncensored",
        "OnionGPT"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Cisco Talos",
          "domain": "blog.talosintelligence.com",
          "type": "vendor-report"
        },
        "actors": [
          "CanadianKingpin12"
        ],
        "malware": [
          "GhostGPT",
          "WormGPT",
          "DarkGPT",
          "DarkestGPT",
          "FraudGPT",
          "WhiteRabbitNeo",
          "Llama 2 Uncensored",
          "OnionGPT"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-06-24-zscaler-threatlabz-black-hat-seo-poisoning-search-engine-re",
      "url": "https://www.zscaler.com:443/blogs/security-research/black-hat-seo-poisoning-search-engine-results-ai-distribute-malware",
      "title": "Black Hat SEO Poisoning Search Engine Results For AI to Distribute Malware",
      "content_text": "Zscaler researchers found threat actors using Black Hat SEO to rank fake AI-themed websites (mimicking tools like ChatGPT and Luma AI) highly in search results. Victims who click through are fingerprinted and redirected through multiple layers to download malware including Vidar, Lumma Stealer and Legion Loader, often bundled in oversized installers to evade sandboxes.",
      "date_published": "2025-06-24T00:00:00Z",
      "date_modified": "2026-09-21T10:11:17Z",
      "tags": [
        "AI-Enabled",
        "Vidar",
        "Lumma",
        "Legion Loader",
        "Legion Loader"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Zscaler ThreatLabz",
          "domain": "zscaler.com:443",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "Vidar",
          "Lumma",
          "Legion Loader",
          "Legion Loader"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-06-11-securityweek-echoleak",
      "url": "https://www.securityweek.com/echoleak-ai-attack-enabled-theft-of-sensitive-data-via-microsoft-365-copilot/",
      "title": "'EchoLeak' AI Attack Enabled Theft of Sensitive Data via Microsoft 365 Copilot",
      "content_text": "Aim Security showed that a single crafted email could make Microsoft 365 Copilot send internal data to an attacker with no user interaction. Microsoft patched it server-side and reported no exploitation in the wild.",
      "date_published": "2025-06-11T00:00:00Z",
      "date_modified": "2025-06-11T06:00:00Z",
      "tags": [
        "AI-Targeted",
        "CVE-2025-32711"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "SecurityWeek",
          "domain": "securityweek.com",
          "type": "news"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [
          "CVE-2025-32711"
        ],
        "attribution": [],
        "also": [
          {
            "name": "arXiv",
            "domain": "arxiv.org",
            "url": "https://arxiv.org/html/2509.10540v1"
          }
        ],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-05-14-eclecticiq-storm-1516-deploys-ai-generated-media-to",
      "url": "https://blog.eclecticiq.com/storm-1516-deploys-ai-generated-media-to-spread-disinformation-targets-european-leaders-and-influence-istanbul-peace-talks",
      "title": "Storm-1516 Deploys AI-Generated Media to Spread Disinformation: Targets European Leaders and Influences Istanbul Peace Talks",
      "content_text": "EclecticIQ documents pro-Kremlin group Storm-1516 using AI-generated images and videos to falsely accuse Macron, Starmer, Merz and Zelensky of cocaine use, aiming to undermine European unity ahead of Istanbul peace talks. The campaign was amplified by Storm-1516-linked X accounts and Russian MFA official Maria Zakharova, and relied on generative AI to fabricate visuals rapidly for viral spread.",
      "date_published": "2025-05-14T00:00:00Z",
      "date_modified": "2026-09-21T10:10:52Z",
      "tags": [
        "AI-Enabled",
        "Storm-1516"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "EclecticIQ",
          "domain": "blog.eclecticiq.com",
          "type": "vendor-report"
        },
        "actors": [
          "Storm-1516"
        ],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "Russia",
            "claimed_by": "EclecticIQ",
            "confidence": "high"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-04-21-unit-42-palo-alto-networ-false-face-unit-42-demonstrates-the-alar",
      "url": "https://unit42.paloaltonetworks.com/north-korean-synthetic-identity-creation/",
      "title": "False Face: Unit 42 Demonstrates the Alarming Ease of Synthetic Identity Creation",
      "content_text": "Unit 42 shows that North Korean IT worker operatives are using real-time deepfake tools during job interviews to create synthetic identities and evade detection. A researcher with no prior experience built a passable real-time deepfake in about 70 minutes using cheap hardware and free tools, illustrating low barriers to this technique. The report also outlines technical artifacts and HR/security mitigations to detect",
      "date_published": "2025-04-21T00:00:00Z",
      "date_modified": "2026-09-21T10:10:46Z",
      "tags": [
        "AI-Enabled",
        "North Korean IT workers",
        "DPRK",
        "Wagemole",
        "BeaverTail",
        "InvisibleFerret"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Unit 42, Palo Alto Networks",
          "domain": "unit42.paloaltonetworks.com",
          "type": "vendor-report"
        },
        "actors": [
          "North Korean IT workers",
          "DPRK"
        ],
        "malware": [
          "Wagemole",
          "BeaverTail",
          "InvisibleFerret"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "North Korea",
            "claimed_by": "Unit 42, Palo Alto Networks",
            "confidence": "high"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-04-01-anthropic-operating-multi-client-influence-network",
      "url": "https://cdn.sanity.io/files/4zrzovbb/website/45bc6adf039848841ed9e47051fb1209d6bb2b26.pdf",
      "title": "Operating Multi-Client Influence Networks Across Platforms",
      "content_text": "Anthropic disrupted an influence-as-a-service operation that used Claude to manage over 100 social media personas across X and Facebook, making tactical decisions on engagement and generating image prompts. The operation served at least four distinct clients pushing narratives on European, Iranian, UAE, and Kenyan interests, prioritizing persistence and relationship-building over viral spread. No nation-state attribu",
      "date_published": "2025-04-01T00:00:00Z",
      "date_modified": "2026-09-21T08:37:33Z",
      "tags": [
        "AI-Enabled",
        "Claude"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Anthropic",
          "domain": "cdn.sanity.io",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "Claude"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [
          {
            "name": "Anthropic",
            "domain": "anthropic.com",
            "url": "https://www.anthropic.com/news/detecting-and-countering-malicious-uses-of-claude-march-2025"
          }
        ],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-02-21-unit-42-investigating-llm-jailbreaking-of-popula",
      "url": "https://unit42.paloaltonetworks.com/jailbreaking-generative-ai-web-products/",
      "title": "Investigating LLM Jailbreaking of Popular Generative AI Web Products",
      "content_text": "Unit 42 tested 17 popular GenAI web products with single-turn and multi-turn jailbreak strategies to assess safety violations and sensitive data leakage. All tested products were vulnerable to some jailbreak techniques, with multi-turn strategies like Crescendo and Bad Likert Judge more effective for safety violations, while single-turn methods like repeated token attacks were more effective for data leakage in one a",
      "date_published": "2025-02-21T00:00:00Z",
      "date_modified": "2026-09-21T10:10:30Z",
      "tags": [
        "AI-Targeted",
        "DAN",
        "Crescendo",
        "Bad Likert Judge",
        "PLEAK",
        "h4rm3l"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Unit 42",
          "domain": "unit42.paloaltonetworks.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "DAN",
          "Crescendo",
          "Bad Likert Judge",
          "PLEAK",
          "h4rm3l"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-01-30-abnormal-ai-how-ghostgpt-empowers-cybercriminals-wit",
      "url": "https://abnormal.ai/blog/ghostgpt-uncensored-ai-chatbot",
      "title": "How GhostGPT Empowers Cybercriminals with Uncensored AI",
      "content_text": "Abnormal Security researchers identified GhostGPT, an uncensored chatbot sold via Telegram that likely wraps a jailbroken ChatGPT or open-source LLM to remove safety guardrails. It is marketed to generate phishing emails, BEC templates, malware code and exploits, lowering the skill barrier for cybercriminals. Researchers tested it by having it produce a convincing Docusign phishing email template.",
      "date_published": "2025-01-30T00:00:00Z",
      "date_modified": "2026-09-21T10:10:12Z",
      "tags": [
        "AI-Enabled",
        "GhostGPT",
        "WormGPT",
        "WolfGPT",
        "EscapeGPT"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Abnormal AI",
          "domain": "abnormal.ai",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "GhostGPT",
          "WormGPT",
          "WolfGPT",
          "EscapeGPT"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-01-30-unit-42-recent-jailbreaks-demonstrate-emerging-t",
      "url": "https://unit42.paloaltonetworks.com/jailbreaking-deepseek-three-techniques/",
      "title": "Recent Jailbreaks Demonstrate Emerging Threat to DeepSeek",
      "content_text": "Unit 42 tested three jailbreak techniques (Bad Likert Judge, Crescendo, Deceptive Delight) against DeepSeek LLMs and achieved high bypass rates with little specialized knowledge required. The jailbreaks elicited data exfiltration tools, keylogger code, phishing templates, Molotov cocktail instructions and malicious scripts, demonstrating security risks in DeepSeek's safety guardrails.",
      "date_published": "2025-01-30T00:00:00Z",
      "date_modified": "2026-09-21T10:10:22Z",
      "tags": [
        "AI-Targeted",
        "Bad Likert Judge",
        "Crescendo",
        "Deceptive Delight"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Unit 42",
          "domain": "unit42.paloaltonetworks.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "Bad Likert Judge",
          "Crescendo",
          "Deceptive Delight"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-01-29-google-deepmind-how-we-estimate-the-risk-from-prompt-inj",
      "url": "https://blog.google/security/how-we-estimate-risk-from-promp/",
      "title": "How we estimate the risk from prompt injection attacks on AI systems",
      "content_text": "Google DeepMind describes an automated red-teaming framework using optimization-based attacks (Actor Critic, Beam Search, Tree of Attacks with Pruning) to test AI agents' susceptibility to indirect prompt injection that could exfiltrate sensitive user data. This is a defensive research methodology, not a report of real-world exploitation, and no specific incidents are disclosed.",
      "date_published": "2025-01-29T00:00:00Z",
      "date_modified": "2026-09-21T08:37:15Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Google DeepMind",
          "domain": "blog.google",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-01-29-gtig-adversarial-misuse",
      "url": "https://cloud.google.com/blog/topics/threat-intelligence/adversarial-misuse-generative-ai",
      "title": "Adversarial Misuse of Generative AI",
      "content_text": "GTIG's first analysis of how government-backed groups used Gemini. Actors from Iran, China, North Korea and Russia used it for research, coding help and content, and did not develop novel capabilities with it.",
      "date_published": "2025-01-29T00:00:00Z",
      "date_modified": "2025-01-29T06:00:00Z",
      "tags": [
        "AI-Enabled",
        "APT43"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Google Threat Intelligence Group",
          "domain": "cloud.google.com",
          "type": "vendor-report"
        },
        "actors": [
          "APT43"
        ],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "Iran",
            "claimed_by": "Google Threat Intelligence Group",
            "confidence": "not-stated"
          },
          {
            "country": "China",
            "claimed_by": "Google Threat Intelligence Group",
            "confidence": "not-stated"
          },
          {
            "country": "North Korea",
            "claimed_by": "Google Threat Intelligence Group",
            "confidence": "not-stated"
          },
          {
            "country": "Russia",
            "claimed_by": "Google Threat Intelligence Group",
            "confidence": "not-stated"
          }
        ],
        "also": [
          {
            "name": "TechTarget",
            "domain": "techtarget.com",
            "url": "https://www.techtarget.com/searchsecurity/news/366618357/Google-details-adversarial-AI-activity-on-Gemini"
          }
        ],
        "landmark": true
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-01-29-wiz-deepseek-database",
      "url": "https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak",
      "title": "Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information, Including Chat History",
      "content_text": "An unauthenticated ClickHouse database belonging to DeepSeek exposed over a million log lines, including chat history, API secrets and backend details, and allowed full control of the database. DeepSeek secured it after disclosure.",
      "date_published": "2025-01-29T00:00:00Z",
      "date_modified": "2025-01-29T06:00:00Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Wiz Research",
          "domain": "wiz.io",
          "type": "research"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-01-22-trend-micro-invisible-prompt-injection-a-threat-to-a",
      "url": "https://www.trendmicro.com/en_us/research/25/a/invisible-prompt-injection-secure-ai.html",
      "title": "Invisible Prompt Injection: A Threat to AI Security",
      "content_text": "Trend Micro explains how invisible Unicode tag characters can hide prompt injection text from users while still being interpreted by LLMs, altering model responses. The article demonstrates the technique with a proof-of-concept example and tests attack success rates against several Claude and Mistral models, then promotes its own ZTSA product as mitigation.",
      "date_published": "2025-01-22T00:00:00Z",
      "date_modified": "2026-09-21T10:10:04Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Trend Micro",
          "domain": "trendmicro.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2024-12-31-unit-42-palo-alto-networ-bad-likert-judge-a-novel-multi-turn-tech",
      "url": "https://unit42.paloaltonetworks.com/multi-turn-technique-jailbreaks-llms/",
      "title": "Bad Likert Judge: A Novel Multi-Turn Technique to Jailbreak LLMs by Misusing Their Evaluation Capability",
      "content_text": "Unit 42 researchers describe a proof-of-concept multi-turn jailbreak that asks an LLM to act as a judge scoring content harmfulness on a Likert scale, then to generate examples at each score, extracting the most harmful response. Testing across six anonymized LLMs showed the technique raised attack success rate by over 75 percentage points versus direct prompts on average, with weaker protection for categories like h",
      "date_published": "2024-12-31T00:00:00Z",
      "date_modified": "2026-09-21T10:09:58Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Unit 42 (Palo Alto Networks)",
          "domain": "unit42.paloaltonetworks.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2024-12-20-unit-42-now-you-see-me-now-you-don-t-using-llms",
      "url": "https://unit42.paloaltonetworks.com/using-llms-obfuscate-malicious-javascript/",
      "title": "Now You See Me, Now You Don’t: Using LLMs to Obfuscate Malicious JavaScript",
      "content_text": "Unit 42 researchers built an algorithm that uses LLMs to iteratively rewrite malicious JavaScript, evading their own deep learning malware classifier 88% of the time and bypassing all VirusTotal vendors on a sample. This is a proof of concept demonstrating adversarial evasion of AI-based malware detection, not observed criminal use in the wild, and they retrained their model on the samples to improve detection by 10%",
      "date_published": "2024-12-20T00:00:00Z",
      "date_modified": "2026-09-21T10:09:49Z",
      "tags": [
        "AI-Targeted",
        "WormGPT",
        "FraudGPT"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Unit 42",
          "domain": "unit42.paloaltonetworks.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "WormGPT",
          "FraudGPT"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2024-12-17-trend-micro-link-trap-genai-prompt-injection-attack",
      "url": "https://www.trendmicro.com/en_us/research/24/l/genai-prompt-injection-attack-threat.html",
      "title": "Link Trap: GenAI Prompt Injection Attack",
      "content_text": "Trend Micro describes a prompt injection technique where an LLM is manipulated into embedding sensitive collected data into a hyperlink disguised as a normal reference link. If the user clicks it, data is exfiltrated to an attacker, even without the AI having external connectivity permissions. This is presented as a conceptual attack pattern rather than a specific observed incident.",
      "date_published": "2024-12-17T00:00:00Z",
      "date_modified": "2026-09-21T10:09:38Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Trend Micro",
          "domain": "trendmicro.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2024-11-12-unit-42-modeleak-privilege-escalation-to-llm-mod",
      "url": "https://unit42.paloaltonetworks.com/privilege-escalation-llm-model-exfil-vertex-ai/",
      "title": "ModeLeak: Privilege Escalation to LLM Model Exfiltration in Vertex AI",
      "content_text": "Unit 42 researchers found two vulnerabilities in Google Vertex AI: a privilege escalation via custom job service agents, and a model exfiltration attack via deploying a poisoned model that could steal other fine-tuned ML and LLM models. This was proof-of-concept research conducted in a test environment, reported to Google, which has since patched the issues.",
      "date_published": "2024-11-12T00:00:00Z",
      "date_modified": "2026-09-21T10:09:33Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Unit 42",
          "domain": "unit42.paloaltonetworks.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2024-10-23-unit-42-palo-alto-networ-deceptive-delight-jailbreak-llms-through",
      "url": "https://unit42.paloaltonetworks.com/jailbreak-llms-through-camouflage-distraction/",
      "title": "Deceptive Delight: Jailbreak LLMs Through Camouflage and Distraction",
      "content_text": "Unit 42 researchers describe Deceptive Delight, a multi-turn jailbreak technique that embeds unsafe topics among benign ones to trick LLMs into generating harmful content. Tested across 8,000 cases on eight models, it achieved a 65% average attack success rate within three turns, versus 5.8% baseline. This is proof-of-concept research with content filters disabled, not an observed real-world attack.",
      "date_published": "2024-10-23T00:00:00Z",
      "date_modified": "2026-09-21T10:09:15Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Unit 42 (Palo Alto Networks)",
          "domain": "unit42.paloaltonetworks.com",
          "type": "research"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2024-10-03-permiso-when-ai-gets-hijacked-exploiting-hosted",
      "url": "https://permiso.io/blog/exploiting-hosted-models",
      "title": "When AI Gets Hijacked: Exploiting Hosted Models for Dark Roleplaying",
      "content_text": "Permiso observed attackers hijacking exposed AWS access keys to invoke Bedrock foundation models, primarily Anthropic Claude, to power unfiltered AI roleplaying chatbot services. A honeypot captured over 75,000 invocations in two days, mostly sexual content with some straying into CSEM, with circumstantial links to the Chub.ai bot platform. AWS took 35 hours to block the compromised key after invocation volume spiked",
      "date_published": "2024-10-03T00:00:00Z",
      "date_modified": "2026-09-21T09:58:19Z",
      "tags": [
        "AI-Targeted",
        "oai-reverse-proxy",
        "one-api"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Permiso",
          "domain": "permiso.io",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "oai-reverse-proxy",
          "one-api"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2024-09-23-knostic-jailbreaking-social-engineering-via-adve",
      "url": "https://www.knostic.ai/blog/jailbreaking-social-engineering-via-adversarial-digital-twins",
      "title": "Jailbreaking Social Engineering via Adversarial Digital Twins",
      "content_text": "Knostic researchers describe a proof-of-concept red team method using an LLM to build a psychological profile and a fake persona ('Adversarial Digital Twin') from a target's social media data, then jailbreak the LLM's guardrails to generate rapport-building conversations for social engineering. The technique was demonstrated in a controlled exercise, not observed in the wild, but shows how LLMs could lower the skill",
      "date_published": "2024-09-23T00:00:00Z",
      "date_modified": "2026-09-21T10:09:07Z",
      "tags": [
        "AI-Enabled",
        "Dark Gemini",
        "Maltego"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Knostic",
          "domain": "knostic.ai",
          "type": "research"
        },
        "actors": [],
        "malware": [
          "Dark Gemini",
          "Maltego"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2024-08-29-unit-42-the-emerging-dynamics-of-deepfake-scam-c",
      "url": "https://unit42.paloaltonetworks.com/dynamics-of-deepfake-scams/",
      "title": "The Emerging Dynamics of Deepfake Scam Campaigns on the Web",
      "content_text": "Unit 42 researchers identified a large network of scam websites using deepfake videos of public figures like Elon Musk and various world leaders to promote fake investment schemes and government giveaways across multiple languages and countries. Infrastructure analysis of hundreds of domains, averaging 114,000 visits each, suggests a single threat actor group behind these long-running campaigns.",
      "date_published": "2024-08-29T00:00:00Z",
      "date_modified": "2026-09-21T10:08:35Z",
      "tags": [
        "AI-Enabled",
        "Quantum AI"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Unit 42",
          "domain": "unit42.paloaltonetworks.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "Quantum AI"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2024-08-28-the-cyberwire-black-basta-and-the-use-of-llms-by-threa",
      "url": "https://thecyberwire.com/podcasts/microsoft-threat-intelligence/26/transcript",
      "title": "Black Basta and the Use of LLMs by Threat Actors",
      "content_text": "Microsoft researchers describe Black Basta's shifting initial access techniques across several malware loaders, then discuss how state-sponsored actors used LLMs via OpenAI accounts. Microsoft and OpenAI disrupted five state-affiliated accounts used for tasks like translation, coding help, and open-source research, consistent with actors' existing goals rather than new capabilities.",
      "date_published": "2024-08-28T00:00:00Z",
      "date_modified": "2026-09-21T10:08:57Z",
      "tags": [
        "AI-Enabled",
        "Black Basta",
        "Storm-506",
        "Storm-1811",
        "Storm-464",
        "Storm-450",
        "Forest Blizzard",
        "Emerald Sleet",
        "Strawberry Tempest",
        "Qakbot",
        "Pikabot",
        "DarkGate",
        "IcedID",
        "TeamsPhisher",
        "BatLoader",
        "ZLoader",
        "Cobalt Strike"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "The CyberWire",
          "domain": "thecyberwire.com",
          "type": "news"
        },
        "actors": [
          "Black Basta",
          "Storm-506",
          "Storm-1811",
          "Storm-464",
          "Storm-450",
          "Forest Blizzard",
          "Emerald Sleet",
          "Strawberry Tempest"
        ],
        "malware": [
          "Qakbot",
          "Pikabot",
          "DarkGate",
          "IcedID",
          "TeamsPhisher",
          "BatLoader",
          "ZLoader",
          "Cobalt Strike"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "Russia",
            "claimed_by": "Microsoft",
            "confidence": "not-stated"
          },
          {
            "country": "North Korea",
            "claimed_by": "Microsoft",
            "confidence": "not-stated"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2024-08-01-trend-micro-social-media-malvertising-campaign-promo",
      "url": "https://www.trendmicro.com/en_us/research/24/h/malvertising-campaign-fake-ai-editor-website-credential-theft.html",
      "title": "Social Media Malvertising Campaign Promotes Fake AI Editor Website for Credential Theft",
      "content_text": "Trend Micro documented a malvertising campaign that hijacks Facebook pages, rebrands them as the AI photo editor Evoto, and lures victims to download a disguised ITarian RMM installer. Once enrolled, the tool downloads Lumma Stealer and disables Windows Defender scanning to exfiltrate credentials, wallets and browser data. AI branding is used purely as a lure, not as an offensive capability.",
      "date_published": "2024-08-01T00:00:00Z",
      "date_modified": "2026-09-21T10:08:10Z",
      "tags": [
        "AI-Enabled",
        "Lumma Stealer",
        "PackLab Crypter",
        "ITarian"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Trend Micro",
          "domain": "trendmicro.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "Lumma Stealer",
          "PackLab Crypter",
          "ITarian"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2024-07-30-trend-micro-ai-powered-deepfake-tools-becoming-more",
      "url": "https://www.trendmicro.com/en_us/research/24/g/ai-deepfake-cybercrime.html",
      "title": "AI-Powered Deepfake Tools Becoming More Accessible Than Ever",
      "content_text": "Trend Micro research documents new cybercrime underground tools including deepfake generators (DeepNude Pro, SwapFace, VideoCallSpoofer) and re-emerging malicious LLM services like WormGPT and DarkBERT with added multimodal capabilities. Many advertised jailbreak LLM services are actually thin wrappers around commercial models, and adoption of these tools by criminals remains relatively slow.",
      "date_published": "2024-07-30T00:00:00Z",
      "date_modified": "2026-09-21T10:08:01Z",
      "tags": [
        "AI-Enabled",
        "DeepNude Pro",
        "Deepfake 3D Pro",
        "Deepfake AI",
        "SwapFace",
        "VideoCallSpoofer",
        "WormGPT",
        "DarkBERT",
        "DarkGemini"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Trend Micro",
          "domain": "trendmicro.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "DeepNude Pro",
          "Deepfake 3D Pro",
          "Deepfake AI",
          "SwapFace",
          "VideoCallSpoofer",
          "WormGPT",
          "DarkBERT",
          "DarkGemini"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2024-07-23-mandiant-whose-voice-is-it-anyway-ai-powered-voic",
      "url": "https://cloud.google.com/blog/topics/threat-intelligence/ai-powered-voice-spoofing-vishing-attacks",
      "title": "Whose Voice Is It Anyway? AI-Powered Voice Spoofing for Next-Gen Vishing Attacks",
      "content_text": "Mandiant describes how attackers use AI voice cloning for vishing, including a red team case study where a cloned executive voice tricked an employee into bypassing security warnings and executing malware. It also cites a reported HK$200 million deepfake scam and offers mitigation guidance like code words and source verification.",
      "date_published": "2024-07-23T00:00:00Z",
      "date_modified": "2026-09-21T10:07:53Z",
      "tags": [
        "AI-Enabled"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Mandiant",
          "domain": "cloud.google.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2024-07-09-fbi-state-sponsored-russian-media-leverages",
      "url": "https://www.ic3.gov/CSA/2024/240709.pdf",
      "title": "State-Sponsored Russian Media Leverages Meliorator Software for Foreign Malign Influence Activity",
      "content_text": "FBI, CNMF, and allied agencies detail Meliorator, an AI-enhanced tool used by RT affiliates to mass-create fake social media personas that spread Russian disinformation on X. The software auto-generates biographical data and AI profile photos, bypasses two-factor authentication, and obfuscates IP addresses to evade detection.",
      "date_published": "2024-07-09T00:00:00Z",
      "date_modified": "2026-09-21T09:58:33Z",
      "tags": [
        "AI-Enabled",
        "RT",
        "Meliorator",
        "Brigadir",
        "Taras",
        "Faker"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "FBI",
          "domain": "ic3.gov",
          "type": "government"
        },
        "actors": [
          "RT"
        ],
        "malware": [
          "Meliorator",
          "Brigadir",
          "Taras",
          "Faker"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "Russia",
            "claimed_by": "FBI, CNMF, AIVD, MIVD, DNP, CCCS",
            "confidence": "high"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2024-06-26-google-threat-analysis-g-google-disrupted-over-10-000-instances-o",
      "url": "https://blog.google/threat-analysis-group/google-disrupted-dragonbridge-activity-q1-2024/",
      "title": "Google disrupted over 10,000 instances of DRAGONBRIDGE activity in Q1 2024",
      "content_text": "Google's TAG reports on DRAGONBRIDGE, a PRC-linked influence operation, disrupting over 10,000 instances in Q1 2024 across YouTube and Blogger, totaling 175,000 lifetime. The actor increasingly used generative AI, including AI-generated news anchors and synthetic voiceovers, to push narratives around Taiwan's election and US social issues, though engagement remained largely inauthentic and low.",
      "date_published": "2024-06-26T00:00:00Z",
      "date_modified": "2026-09-21T08:37:10Z",
      "tags": [
        "AI-Enabled",
        "DRAGONBRIDGE"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Google Threat Analysis Group",
          "domain": "blog.google",
          "type": "vendor-report"
        },
        "actors": [
          "DRAGONBRIDGE"
        ],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "China",
            "claimed_by": "Google Threat Analysis Group",
            "confidence": "high"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2024-05-01-openai-ai-and-covert-influence-operations-lates",
      "url": "https://cdn.openai.com/threat-intelligence-reports/threat-intel-report-may-2024.pdf",
      "title": "AI and Covert Influence Operations: Latest Trends",
      "content_text": "OpenAI describes disrupting five covert influence operations from Russia, China, Iran and an Israeli commercial firm that used its models to generate and refine content, translate text, and fake engagement across social platforms. None of the operations achieved meaningful audience engagement, scoring no higher than Category 2 on the Breakout Scale.",
      "date_published": "2024-05-01T00:00:00Z",
      "date_modified": "2026-09-21T08:37:00Z",
      "tags": [
        "AI-Enabled",
        "Bad Grammar",
        "Doppelganger",
        "Spamouflage",
        "International Union of Virtual Media (IUVM)",
        "Zero Zeno",
        "STOIC"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "OpenAI",
          "domain": "cdn.openai.com",
          "type": "vendor-report"
        },
        "actors": [
          "Bad Grammar",
          "Doppelganger",
          "Spamouflage",
          "International Union of Virtual Media (IUVM)",
          "Zero Zeno",
          "STOIC"
        ],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "Russia",
            "claimed_by": "OpenAI",
            "confidence": "not-stated"
          },
          {
            "country": "China",
            "claimed_by": "OpenAI",
            "confidence": "not-stated"
          },
          {
            "country": "Iran",
            "claimed_by": "OpenAI",
            "confidence": "not-stated"
          },
          {
            "country": "Israel",
            "claimed_by": "OpenAI",
            "confidence": "not-stated"
          }
        ],
        "also": [
          {
            "name": "OpenAI",
            "domain": "openai.com",
            "url": "https://openai.com/index/disrupting-deceptive-uses-of-ai-by-covert-influence-operations/"
          }
        ],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2024-02-14-microsoft-staying-ahead",
      "url": "https://www.microsoft.com/en-us/security/blog/2024/02/14/staying-ahead-of-threat-actors-in-the-age-of-ai/",
      "title": "Staying ahead of threat actors in the age of AI",
      "content_text": "Microsoft and OpenAI published the first joint account of state-affiliated groups using LLMs, mostly for reconnaissance, scripting help and social engineering content. The accounts were disabled.",
      "date_published": "2024-02-14T00:00:00Z",
      "date_modified": "2024-02-14T06:00:00Z",
      "tags": [
        "AI-Enabled",
        "Forest Blizzard",
        "Emerald Sleet",
        "Crimson Sandstorm",
        "Charcoal Typhoon",
        "Salmon Typhoon"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Microsoft Threat Intelligence",
          "domain": "microsoft.com",
          "type": "vendor-report"
        },
        "actors": [
          "Forest Blizzard",
          "Emerald Sleet",
          "Crimson Sandstorm",
          "Charcoal Typhoon",
          "Salmon Typhoon"
        ],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "Russia",
            "claimed_by": "Microsoft",
            "confidence": "not-stated"
          },
          {
            "country": "North Korea",
            "claimed_by": "Microsoft",
            "confidence": "not-stated"
          },
          {
            "country": "Iran",
            "claimed_by": "Microsoft",
            "confidence": "not-stated"
          },
          {
            "country": "China",
            "claimed_by": "Microsoft",
            "confidence": "not-stated"
          }
        ],
        "also": [
          {
            "name": "OpenAI",
            "domain": "openai.com",
            "url": "https://openai.com/index/disrupting-malicious-uses-of-ai-by-state-affiliated-threat-actors/"
          }
        ],
        "landmark": true
      }
    },
    {
      "id": "https://ai-threat.watch/#2024-02-07-trend-micro-a-deepfake-scammed-a-bank-out-of-25m-now",
      "url": "https://www.trendaisecurity.com/en-us/resources-insights/trendai-security-blog/deepfake-video-calls",
      "title": "A Deepfake Scammed a Bank out of $25M , Now What?",
      "content_text": "A Hong Kong firm reportedly lost $25 million after fraudsters used deepfake video conferencing to impersonate its CFO and authorize a funds transfer. The article analyzes how accessible AI tools enable such scams and recommends process and Zero Trust improvements to prevent similar fraud.",
      "date_published": "2024-02-07T00:00:00Z",
      "date_modified": "2026-09-21T10:01:29Z",
      "tags": [
        "AI-Enabled"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Trend Micro",
          "domain": "trendaisecurity.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2023-12-05-recorded-future-obfuscation-and-ai-content-in-the-russia",
      "url": "https://www.recordedfuture.com/research/russian-influence-network-doppelgangers-ai-content-tactics",
      "title": "Obfuscation and AI Content in the Russian Influence Network “Doppelgänger” Signals Evolving Tactics",
      "content_text": "Recorded Future's Insikt Group documented the Russia-linked Doppelganger influence network using obfuscation techniques and likely generative AI to produce fake news articles impersonating outlets in Ukraine, the US, and Germany. The campaigns aimed to sway public opinion around elections, military support for Ukraine, and social divisions, showing AI's growing role in influence operations.",
      "date_published": "2023-12-05T00:00:00Z",
      "date_modified": "2026-09-21T10:01:21Z",
      "tags": [
        "AI-Enabled",
        "Doppelgänger"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Recorded Future",
          "domain": "recordedfuture.com",
          "type": "vendor-report"
        },
        "actors": [
          "Doppelgänger"
        ],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "Russia",
            "claimed_by": "Insikt Group",
            "confidence": "not-stated"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2023-08-08-levelblue-spiderlabs-wormgpt-and-fraudgpt-the-rise-of-malicio",
      "url": "https://www.levelblue.com/blogs/spiderlabs-blog/wormgpt-and-fraudgpt-the-rise-of-malicious-llms",
      "title": "WormGPT and FraudGPT - The Rise of Malicious LLMs",
      "content_text": "Researchers analyzed WormGPT and FraudGPT, malicious LLM tools sold on underground forums since mid-2023 for writing malware, phishing emails and scam pages. Testing showed that properly prompted ChatGPT could produce comparable outputs to WormGPT samples, suggesting these tools offer limited advantage over jailbreaking mainstream models. Underground forums also show growing interest in attacking AI systems.",
      "date_published": "2023-08-08T00:00:00Z",
      "date_modified": "2026-09-21T10:01:07Z",
      "tags": [
        "AI-Enabled",
        "last/laste",
        "WormGPT",
        "FraudGPT",
        "ChatGPT"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "LevelBlue (SpiderLabs)",
          "domain": "levelblue.com",
          "type": "research"
        },
        "actors": [
          "last/laste"
        ],
        "malware": [
          "WormGPT",
          "FraudGPT",
          "ChatGPT"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2023-07-25-netenrich-fraudgpt-the-villain-avatar-of-chatgpt",
      "url": "https://netenrich.com/blog/fraudgpt-the-villain-avatar-of-chatgpt",
      "title": "FraudGPT: The Villain Avatar of ChatGPT",
      "content_text": "Netenrich researchers found FraudGPT, a malicious AI chatbot sold on dark web marketplaces and Telegram since July 2023, marketed for phishing emails, malware creation, and finding vulnerable sites. The tool costs $200 monthly to $1,700 yearly and has reportedly seen over 3,000 sales, illustrating criminal adoption of uncensored AI tools for offensive operations.",
      "date_published": "2023-07-25T00:00:00Z",
      "date_modified": "2026-09-21T10:00:45Z",
      "tags": [
        "AI-Enabled",
        "canadiankingpin12",
        "FraudGPT",
        "WormGPT"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Netenrich",
          "domain": "netenrich.com",
          "type": "vendor-report"
        },
        "actors": [
          "canadiankingpin12"
        ],
        "malware": [
          "FraudGPT",
          "WormGPT"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2023-06-15-unit-42-android-malware-impersonates-chatgpt-the",
      "url": "https://unit42.paloaltonetworks.com/android-malware-poses-as-chatgpt/",
      "title": "Android Malware Impersonates ChatGPT-Themed Applications",
      "content_text": "Unit 42 identified Android malware impersonating ChatGPT apps, including a Meterpreter Trojan disguised as a 'SuperGPT' app for remote access and fake ChatGPT apps that send SMS messages to premium-rate Thai numbers to charge victims. The malware exploits ChatGPT's popularity to trick users into downloading malicious apps outside official channels.",
      "date_published": "2023-06-15T00:00:00Z",
      "date_modified": "2026-09-21T10:00:40Z",
      "tags": [
        "AI-Enabled",
        "Hax4Us",
        "Meterpreter",
        "SuperGPT"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Unit 42",
          "domain": "unit42.paloaltonetworks.com",
          "type": "vendor-report"
        },
        "actors": [
          "Hax4Us"
        ],
        "malware": [
          "Meterpreter",
          "SuperGPT"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "India",
            "claimed_by": "Unit 42",
            "confidence": "low"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2023-05-18-recorded-future-i-have-no-mouth-and-i-must-do-crime",
      "url": "https://www.recordedfuture.com/research/i-have-no-mouth-and-i-must-do-crime",
      "title": "I Have No Mouth, and I Must Do Crime",
      "content_text": "Recorded Future reports that voice cloning technology, such as ElevenLabs, is being abused by threat actors to defeat voice-based MFA, spread disinformation, and enhance social engineering. It notes the rise of voice-cloning-as-a-service tools sold on Telegram and increased dark web references to voice cloning since 2020.",
      "date_published": "2023-05-18T00:00:00Z",
      "date_modified": "2026-09-21T10:00:33Z",
      "tags": [
        "AI-Enabled",
        "ElevenLabs"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Recorded Future",
          "domain": "recordedfuture.com",
          "type": "research"
        },
        "actors": [],
        "malware": [
          "ElevenLabs"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2023-02-15-securelist-ioc-detection-experiments-with-chatgpt",
      "url": "https://securelist.com/ioc-detection-experiments-with-chatgpt/108756/",
      "title": "IoC detection experiments with ChatGPT",
      "content_text": "Kaspersky researchers tested whether ChatGPT could identify indicators of compromise, finding it failed on known hashes and domains but performed better analyzing host-based artifacts like process metadata and service installations. They built a proof-of-concept PowerShell scanner (HuntWithChatGPT) that used the OpenAI API to flag suspicious system activity with some false positives and negatives.",
      "date_published": "2023-02-15T00:00:00Z",
      "date_modified": "2026-09-21T10:00:17Z",
      "tags": [
        "AI-Targeted",
        "Mimikatz",
        "Fast Reverse Proxy",
        "Meterpreter",
        "PowerShell Empire",
        "HuntWithChatGPT.psm1"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Securelist",
          "domain": "securelist.com",
          "type": "research"
        },
        "actors": [],
        "malware": [
          "Mimikatz",
          "Fast Reverse Proxy",
          "Meterpreter",
          "PowerShell Empire",
          "HuntWithChatGPT.psm1"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2023-02-07-check-point-research-cybercriminals-bypass-chatgpt-restrictio",
      "url": "https://blog.checkpoint.com/2023/02/07/cybercriminals-bypass-chatgpt-restrictions-to-generate-malicious-content",
      "title": "Cybercriminals Bypass ChatGPT Restrictions to Generate Malicious Content",
      "content_text": "Check Point Research found cybercriminals bypassing ChatGPT's content restrictions by using the OpenAI API directly, which lacked the abuse safeguards of the web interface. They advertised Telegram bots and scripts in underground forums to generate phishing emails and malware code, including improving a basic 2019 infostealer.",
      "date_published": "2023-02-07T00:00:00Z",
      "date_modified": "2026-09-21T10:00:08Z",
      "tags": [
        "AI-Enabled",
        "Infostealer"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Check Point Research",
          "domain": "blog.checkpoint.com",
          "type": "research"
        },
        "actors": [],
        "malware": [
          "Infostealer"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2023-01-26-recorded-future-i-chatbot",
      "url": "https://www.recordedfuture.com/research/i-chatbot",
      "title": "I, Chatbot",
      "content_text": "Recorded Future documents cybercriminals on dark web and special-access forums using ChatGPT within weeks of its launch to write malware, phishing lures, scam schemes, and fraudulent freelance content. Actors like 0x27 and USDoD leveraged media coverage of ChatGPT abuse to boost their forum reputation, while others sought unverified accounts to bypass registration controls.",
      "date_published": "2023-01-26T00:00:00Z",
      "date_modified": "2026-09-21T10:00:01Z",
      "tags": [
        "AI-Enabled",
        "0x27",
        "USDoD",
        "MrK",
        "Lorensaire"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Recorded Future",
          "domain": "recordedfuture.com",
          "type": "vendor-report"
        },
        "actors": [
          "0x27",
          "USDoD",
          "MrK",
          "Lorensaire"
        ],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2023-01-06-check-point-research-opwnai-cybercriminals-starting-to-use-ch",
      "url": "https://research.checkpoint.com/2023/opwnai-cybercriminals-starting-to-use-chatgpt/",
      "title": "OPWNAI : Cybercriminals Starting to Use ChatGPT",
      "content_text": "Check Point Research documents underground forum posts from late 2022 where cybercriminals used ChatGPT to write an infostealer, a multi-encryption script that could be modified into ransomware, and code for dark web marketplace tools. The actors, including one dubbed USDoD, had limited coding skills, showing AI lowers the barrier for less skilled threat actors to create malicious tools.",
      "date_published": "2023-01-06T00:00:00Z",
      "date_modified": "2026-09-21T09:59:53Z",
      "tags": [
        "AI-Enabled",
        "USDoD",
        "SpyNote"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Check Point Research",
          "domain": "research.checkpoint.com",
          "type": "research"
        },
        "actors": [
          "USDoD"
        ],
        "malware": [
          "SpyNote"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    }
  ]
}