How Threat Actors Are Using AI in Cyberattacks: What Defenders Need to Know in 2026
Artificial intelligence is changing cyber operations, but not quite in the way sensational headlines often suggest.
Threat actors initially used generative AI primarily as a productivity tool—for translation, reconnaissance, phishing content and coding assistance. More recent threat intelligence shows a shift toward deeper operational use, including malware interacting with large language models during execution, AI-assisted vulnerability research and increasingly adaptive attack workflows.
Google Threat Intelligence Group (GTIG) reported in May 2026 that it had identified, for the first time, a threat actor using a zero-day exploit that GTIG believes was developed with AI.
This does not mean traditional cyberattacks have disappeared. Mandiant's incident-response research emphasizes that fundamental weaknesses remain responsible for most successful compromises.
For defenders, the challenge is therefore twofold: prepare for emerging AI-enabled techniques while continuing to fix the security weaknesses attackers already exploit successfully.
1. AI-Assisted Reconnaissance
Reconnaissance is one of the most natural uses of generative AI for threat actors.
GTIG has observed state-sponsored actors using LLMs for research, translation, vulnerability investigation and support across different phases of attack activity. AI can help an operator organise information or understand unfamiliar technologies more quickly.
This matters because reconnaissance is often time-consuming. Reducing that workload may allow attackers to investigate more targets or move through preparation stages faster.
However, AI does not magically provide access to a target. Attackers still need exploitable vulnerabilities, compromised credentials, social-engineering success or another viable entry point.
2. Social Engineering at Greater Scale
Generative AI is particularly well suited to producing and adapting written content.
Attackers can use these capabilities to improve grammar, translate messages and customise social-engineering material for different targets.
M-Trends 2026 also highlights the continuing importance of human-targeted attacks. Mandiant reported that voice phishing represented 11% of observed initial infection vectors in its 2025 investigations, making it the second-most commonly observed vector after exploits.
AI therefore does not need to invent an entirely new attack technique to be dangerous. Improving the speed, quality or personalisation of an existing technique can itself increase operational effectiveness.
3. AI Is Moving Into Malware
One of the more significant developments is the integration of LLM functionality into malicious tooling.
Mandiant describes malware families including PROMPTFLUX and PROMPTSTEAL that interact with LLMs. PROMPTFLUX was observed using an LLM API to assist with self-modification, while PROMPTSTEAL was used in operations to generate commands for malicious activity.
This represents an important shift.
Traditional malware generally executes logic prepared by its developer. LLM integration creates the possibility for some behaviour or instructions to be generated dynamically.
For defenders, that reinforces the importance of behavioural detection. Security controls that rely entirely on recognising a static file or signature may have difficulty with software whose implementation changes over time.
4. AI-Assisted Vulnerability Research
Perhaps one of the most consequential developments involves vulnerability discovery and exploit development.
In May 2026, GTIG reported identifying a threat actor using a zero-day exploit that it believes was developed with AI—the first such case GTIG had identified.
This deserves attention, but it should not be exaggerated into a claim that AI now automatically discovers and weaponises every vulnerability.
The more defensible conclusion is that AI is becoming another capability available to skilled attackers and vulnerability researchers.
At the same time, defensive teams are exploring AI-assisted vulnerability discovery and remediation. Mandiant reported in July 2026 that the mean time-to-exploit had fallen to -7 days, meaning exploitation can sometimes occur before a patch exists.
That creates pressure for defenders to improve asset visibility, prioritisation and compensating controls rather than depending entirely on the traditional cycle of waiting for a patch.
5. AI Inside a Compromised Environment
AI can also become useful after an attacker gains access.
M-Trends describes the QUIETVAULT credential stealer checking targeted systems for local AI command-line tools and using predefined prompts to help locate configuration files containing valuable secrets such as GitHub and NPM tokens.
This is an important defensive lesson.
AI security is not only about protecting public chatbots or preventing prompt injection. Organisations increasingly need visibility into AI tooling installed on endpoints and development systems.
An AI tool with legitimate access to sensitive resources may become useful to an attacker who compromises the environment.
6. AI Systems Are Becoming Targets Too
Attackers are not only using AI—they are also targeting AI ecosystems.
GTIG reports that attackers have increasingly focused on components surrounding AI systems, including integration libraries, API connectors and configuration components.
Rather than necessarily defeating the security of frontier models directly, attackers can use familiar supply-chain and software-compromise techniques against the infrastructure connecting AI to real business systems.
This distinction is important.
An organisation may deploy a highly capable and secure model while still exposing risk through:
Weak API credentials
Excessive agent permissions
Vulnerable third-party integrations
Poorly protected secrets
Unsanctioned AI tools
Insecure connectors
Weak access controls
Mandiant's AI security assessments similarly found that traditional security hygiene problems frequently remain present inside AI initiatives.
Hype vs Evidence
Cybersecurity discussions around AI can easily become exaggerated.
Hype: AI has replaced hackers
Evidence: Threat actors still depend heavily on traditional vulnerabilities, credentials, social engineering and security misconfigurations.
Exploitation remained the leading initial infection vector in Mandiant's 2025 investigations, accounting for 32% of observed intrusions.
Hype: Every AI-generated attack is autonomous
Evidence: There is growing evidence of adaptive malware and agent-like workflows, but levels of human involvement vary considerably.
Hype: Traditional security no longer works
Evidence: Mandiant reaches almost the opposite conclusion. Fundamental security failures remain central to successful compromises, meaning patching, identity security, visibility, monitoring and access control remain essential.
What Defenders Should Prioritise
Strengthen vulnerability management
Attackers continue to rely heavily on exploitable vulnerabilities.
Maintain accurate asset inventories, identify internet-facing systems and prioritise vulnerabilities using exposure and exploitation evidence rather than severity scores alone.
Protect identities and credentials
Enforce strong authentication, least privilege and appropriate controls around OAuth applications, API tokens and developer credentials.
Monitor behaviour, not only signatures
As malicious tooling becomes more adaptive, behavioural analytics become increasingly important.
Look for unusual process behaviour, unexpected network activity, suspicious credential access and abnormal API usage.
Build visibility into enterprise AI use
Organisations should understand what AI applications, agents and integrations are operating in their environment.
Mandiant identifies shadow AI—unsanctioned AI tools deployed without appropriate oversight—as an important governance and security challenge.
Review AI agent permissions
An AI agent should not automatically receive broad access simply because it needs to automate tasks.
Apply least privilege to agents, integrations and service accounts, and monitor sensitive tool use.
Test AI-enabled systems
Traditional application testing remains necessary, but AI applications may introduce additional concerns involving prompts, data access, connected tools and agent permissions.
Mandiant recommends proactive AI threat modelling and red-team testing to identify these weaknesses.
HimalCyberX Analysis
The most important development in AI-enabled cybercrime is not that artificial intelligence has suddenly created an entirely new class of unbeatable attacker.
The more immediate change is acceleration.
AI can reduce the effort required for reconnaissance, content creation, coding assistance and information analysis. More advanced implementations can also introduce adaptive behaviour into malicious tooling.
That potentially allows attackers to perform existing activities faster and at greater scale.
But defenders should avoid making the opposite mistake: spending heavily on futuristic AI threats while leaving ordinary security weaknesses unresolved.
Mandiant's frontline findings are particularly important here. Despite growing adversarial AI adoption, it says the vast majority of successful intrusions continue to originate from fundamental human and systemic failures.
The practical strategy therefore isn't:
AI security instead of traditional cybersecurity.
It is:
Strong cybersecurity fundamentals + visibility into AI systems + preparation for AI-enabled attacker acceleration.
That distinction should guide security investment in 2026.
Conclusion
Artificial intelligence is becoming a genuine component of modern cyber operations.
Documented activity now extends beyond generating phishing messages. Threat intelligence has identified AI-assisted reconnaissance, malware interacting with LLMs, credential-focused activity, vulnerability research and growing interest in adaptive or agent-like attack workflows.
At the same time, conventional weaknesses remain responsible for most successful compromises.
Organisations therefore need a balanced response: strengthen existing security fundamentals while improving visibility, governance and testing around AI-enabled systems.
AI may change how quickly attackers operate and how their tools adapt, but strong security fundamentals remain one of the most important barriers between an attempted attack and a successful breach.
References
Add these as clickable references in the article:



