top of page

AI Is Making Cyberattacks Faster—and Harder to Stop

3 days ago
3 min read
Hacker at laptop with red alert screen reading Trojan Spyware detected, warning icons, and a dark moody desk scene

Cyberattacks have always had a built-in limitation: Time.

An attacker must investigate a network, find weaknesses, steal credentials, move between systems, locate valuable information, and decide what to do next. Even a highly skilled criminal can only work so fast.

AI is starting to remove that limitation.

A recently disclosed cyber-espionage campaign shows what that can look like. A Russian-linked attacker used AI to help build and operate phishing infrastructure, steal credentials, move through networks, process stolen information, and maintain access to compromised systems.

AI did not invent an entirely new way to hack someone. Instead, it automated work human attackers traditionally did themselves.

That difference could have enormous cybersecurity implications for everybody.

What Happened in the Cyber-Espionage Case Study?

In September 2026, Anthropic published a threat-intelligence report describing several cases in which criminals and state-linked attackers incorporated AI into real cyber operations.

One involved an actor Anthropic tracks as “GTG-20006,” whose activity the company said matched public reporting on the Russian-linked espionage group commonly known as Midnight Blizzard.

The attacker targeted military intelligence organizations in Ukraine and European governments, along with diplomatic and defense organizations and people connected to U.S. foreign policy. One of its primary methods was a technique called device-code phishing.

That means the attacker used AI to help build and operate the phishing infrastructure and other tools used during the intrusions. Once inside, AI became useful for much more than writing code.

According to Anthropic, it helped run commands against victim systems, harvest credentials, move laterally through networks, maintain access to compromised accounts, and organize stolen information. In some cases, AI helped process hundreds of gigabytes of stolen data.

This was no longer simply someone asking a chatbot: “How do I hack a company?”

AI had become part of the attack itself.

AI Does the Busywork, Humans Do the Dirty Work

Imagine trying to break into a large computer network manually. You find one system, investigate it, and hopefully discover some important credentials.

Then you test those credentials elsewhere, and hopefully identify another opportunity.

Then you repeat the process to look for more credentials and account access.

That takes time and a whole lot of effort.

AI can automate or accelerate significant portions of that cycle. The human attacker can still choose the target and decide what ultimately happens with the stolen information.

AI handles much of the repetitive work, meaning one attacker can now accomplish what previously required several people. Anthropic investigations found that individual operators were now running multi-victim campaigns that would previously have required entire teams of skilled operators.

Getting Detected Doesn’t Slow AI Down for Long

Another particularly interesting detail emerged in the Russian-linked campaign.

Security tools eventually detected some of the attacker’s malicious software. Normally, that creates a problem for the hacker. Once defenders recognize malicious software, they can create detection software that identifies and blocks it. The criminal then has to figure out why the malware was detected, modify it, test the new version, and deploy it again.

That costs time.

In this case, the attacker used AI to help with that process, too.

According to Anthropic, when security products flagged the attacker’s malicious tools, AI helped identify, modify, and redeploy the detected software.

Think about the implications. AI isn't only helping criminals attack faster; it could also help them react faster when defenders fight back.

Faster Attacks Change the Game

Cybersecurity advice often assumes time between the first mistake and the worst consequences. Someone clicks a phishing link, or a password gets stolen. The attacker logs into an account and starts exploring.

Comments


bottom of page