SecureSky Insights | Cloud Security Blog

Your Attackers Hired AI. Have You?

Written by Jonah Delzell | Aug 18, 2026

The threat landscape did not gradually drift toward AI-augmented attacks. It sprinted. In the span of roughly five years, AI went from a Black Hat conference demo to a built-in feature of actual criminal platforms available by subscription with nearly zero skill required.

A Brief History

The story of AI in adversary tooling is a story about democratization. Capabilities that used to require nation-state resources or years of specialized expertise are now accessible to anyone willing to pay a monthly fee and navigate a social media channel.

In 2016, tools emerged that let AI automatically identify and exploit vulnerable systems at the Cyber Grand Challenge Final Event. Around 2018, security researchers demonstrated that AI could be embedded in malware to make it nearly undetectable, triggering only when it recognized a specific target's face.

By 2019, criminals had used AI voice cloning to impersonate a CEO and talk a subordinate into wiring $243,000 to a fraudulent account. No malware or technical exploit required. Just an AI-generated voice that sounded exactly right and a business process with no verification step. The following year, a similar attack netted $35 million.

By 2023, underground marketplaces were selling malicious LLMs trained or fine-tuned on malware datasets and adversary tooling. Toolkits designed to generate phishing emails, write malware code, and draft social engineering scripts. These weren't niche tools for sophisticated actors, they were subscription products marketed to the same criminal customer base that rents phishing kits.

And by 2026, the most advanced phishing platforms had LLMs embedded directly into their operational workflow not just for writing convincing emails, but for autonomously analyzing compromised accounts and tenants, identifying high-value financial conversations, and feeding that intelligence directly back into fraud execution and espionage.

Attackers Don't Have to Think Anymore

The attacker doesn't have to think anymore. The platform does it for them.

  • Scale went up and the cost went down. Running a high-quality, personalized phishing campaign used to require skilled operators, time, and research. Now it requires a credit card and a Telegram account.

  • Remember training employees to look for spelling errors and awkward phrasing? That worked because the people writing phishing emails often weren't fluent English speakers. AI-generated content is grammatically correct, tonally appropriate, and increasingly personalized.

  • Deepfake audio and video technology has matured to the point where synthetic voices are convincing enough to fool humans in real-time calls. The CEO fraud attack vector no longer requires a human actor on the phone, an AI model trained on a few minutes of publicly available audio can do it.

  • AI is being used to generate malware that rewrites portions of its own code at runtime, producing unique signatures every time it executes. A piece of malware that looks different on every execution is significantly harder to detect with tools designed to recognize known patterns.

  • AI-assisted reconnaissance means adversaries can process breach databases, public records, LinkedIn profiles, and credentials dumps to identify high-value targets and tailor attacks to them.

A threat actor can provision a fully equipped, AI-augmented attack platform for a few hundred dollars a month. It comes with automated reconnaissance, AI-generated lures, MFA bypass, and post-compromise automation that executes in minutes. Meanwhile, a typical organization’s security operations run on human analysts reviewing alerts, making triage decisions manually, and working through an investigation process designed for a slower threat environment of the past. Offense is operating at machine speed. Defense, in many organizations, is still operating at human speed.

The Answer

The answer isn't to panic or to replace every human analyst with a bot. It's to recognize that AI-augmented threats require AI-assisted defense and to make targeted investments that close the specific gaps these tools exploit.

  • Authentication anomalies such as logins from new devices, new geographies, single-factor authentications that bypass MFA and impossible travel are some of the earliest indicators of a PhaaS-driven compromise. Detection rules for these behaviors need to run in minutes, not hours.

  • Modern PhaaS kits bypass traditional MFA by stealing session tokens in real time so phishing-resistant authentication methods such as hardware keys or passkeys are the controls that hold up best against these techniques. Prioritize your highest-risk users and applications first.

  • Executive voice calls authorizing urgent financial transactions should have out-of-band verification steps that don't rely on the authenticity of the call itself. The $243,000 deepfake CEO attack worked because the receiving organization had no such process. That was 2019 and the technology is significantly better now.

  • User behavior analytics, anomaly detection, and automated correlation of weak signals across large alert volumes are areas where AI-assisted tooling genuinely improves detection outcomes. If attackers are using AI to find and exploit gaps faster than humans can close them, defenders need AI to close that response gap.

AI hasn't fundamentally changed what attackers want. They still want access, credentials, money, and data. What AI has changed is how fast they can get it, how convincingly they can deceive your employees, and how low the barrier is to running a sophisticated operation.

The organizations that will navigate this era successfully aren't necessarily the ones with the biggest security budgets. They're the ones that have assessed the gap between how fast attacks happen and how fast they detect and respond, and begin making the changes to close it. The threat actors already made the transition to AI-augmented operations, the question is whether your defenses have.

 

 

For more information about SecureSky, or assistance with combatting  AI-based attacks, please contact us at:

https://securesky.com/contact-us/

info@securesky.com

+1 833.473.2759  (+1 833.4SecSky)