The AI Attack Surface: How Threat Actors Abuse Trusted AI Platforms
Huntress, Thursday, August 27th, 2026
Huntress examines how attackers abuse trusted AI platforms such as Claude, ChatGPT, Grok and Gemini to deliver malware and steal data.
As more people use AI models including Claude, ChatGPT, Grok and Gemini, threat actors are abusing those trusted platforms as part of their operations.
Huntress examines this emerging attack surface, covering how the trust users and security tools place in well-known AI domains gets turned against them.
The techniques described include using AI platforms to deliver malware and to exfiltrate data, both benefiting from traffic to reputable destinations that raises no alarm.
The post is aimed at defenders who have not yet accounted for AI platform traffic in their monitoring and egress policy.