AI Cyberattacks: How Threat Actors Use AI in Real Intrusions
TechTarget, Tuesday, August 19th, 2025
Three tracked groups used AI across reconnaissance, credential harvesting, and infrastructure upkeep.
A Gambit Security investigation identified three threat actor groups actively integrating AI into attack operations across multiple stages of intrusion.
They used tools including Claude Code for reconnaissance, high-value target identification, credential harvesting at scale, and maintaining attack infrastructure.
The campaigns collected nearly 3,000 validated credentials from more than 1,700 compromised systems, with AI acting as a force multiplier that compressed intrusion timelines. Recommended defenses are unglamorous and specific: strengthen identity controls, segment networks, rotate credentials regularly, and actually test incident response plans.