AI Cyberattacks: How Threat Actors Use AI in Real Intrusions 

Threat actors are using AI to accelerate intrusions, steal credentials, and identify high-value targets.

Written By
Ken Underhill
Ken Underhill
Aug 14, 2026
5 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

AI is becoming a bigger part of real-world cyberattacks, helping threat actors conduct intrusions, steal credentials, navigate networks, and identify valuable targets.  

A Gambit Security investigation into three unrelated threat actors found attackers integrating AI throughout the intrusion lifecycle, extending its use beyond phishing and malware generation. 

“One finding is worth separating out. In the first case the operator did not know the victim’s environment,” said the researchers.

They explained, “He asked the [AI] model which of the databases mattered most, and it ranked them and pointed at the two the business could least afford to lose.”

Key takeaways of how threat actors use AI in attacks

  • AI is becoming an operational attack tool, with threat actors using it for reconnaissance, exploitation, troubleshooting, lateral movement, and identifying high-value targets.
  • AI can accelerate attacker decision-making, as Claude Code analyzed unfamiliar victim environments and recommended systems and databases for The Gentlemen affiliate to target.
  • Credential theft can be automated at scale, with Zerofot using AI-developed tooling to collect 2,975 validated credentials from 1,742 victim hosts in less than two months.
  • AI can support attack infrastructure, with Claude Code managing Zerofot’s operational tasks while RAGE incorporated an LLM directly into its exploitation framework.
  • Defenses must account for faster attacker workflows, making identity controls, credential protection, segmentation, monitoring, and tested incident response plans increasingly important.

How threat actors are using AI 

Threat actor / campaign AI tools How AI was used Key finding
The Gentlemen affiliate Claude Code Reconnaissance, exploitation, lateral movement, scripting, system analysis, and target prioritization AI helped navigate unfamiliar victim environments and identify high-value systems and data.
Zerofot Claude Code, OpenAI Codex Scanner development, credential harvesting, infrastructure management, proxy management, and troubleshooting AI-supported tooling helped collect 2,975 validated credentials from 1,742 victim hosts.
RAGE AI-generated code, DeepSeek-backed AI Orchestrator Exploit development, credential harvesting, cryptominer deployment, and botnet operations AI was used to help build attack tooling and was integrated directly into the exploitation framework.
Advertisement

How attackers use AI across the intrusion lifecycle 

The findings show that generative AI is becoming more than a tool for writing malicious code or preparing phishing attacks. 

Across the three cases, threat actors used AI to automate tasks, troubleshoot problems, analyze compromised environments, and guide their next steps.  

Rather than introducing fundamentally new attack techniques, AI primarily acted as a force multiplier, helping attackers execute established techniques faster and adapt their operations as circumstances changed.

The Gentlemen affiliate uses AI during active intrusions 

One of the clearest examples involved a suspected affiliate of The Gentlemen ransomware-as-a-service (RaaS) operation. 

Gambit observed the threat actor using Claude Code during intrusions into at least six organizations and linked the actor to two earlier compromises. 

The victims spanned several industries and countries, including an Australian energy utility, a financial services company in Mauritius, manufacturers in Thailand and the United States, and an IT services company in Malaysia.

During these intrusions, Claude Code functioned almost like an interactive assistant for the attacker. 

The operator used it to generate and execute reconnaissance and exploitation commands, create malicious scripts, modify firewall policies, and analyze business systems for information relevant to the operation. 

AI could also respond to failed commands and errors by adjusting its approach and trying alternatives, demonstrating how an attacker can use an LLM interactively rather than simply requesting a piece of code and executing it manually.

After obtaining domain credentials and VPN access, the operator used Claude to support reconnaissance and lateral movement inside victim networks. 

The AI analyzed output from network enumeration tools, identified systems where stolen credentials provided administrative access, and recommended potential targets such as domain controllers, file servers, and backup servers. 

In other instances, Claude analyzed application databases and backup infrastructure, helping the attacker identify valuable production data and understand where backups were stored.

Advertisement

Zerofot uses AI to harvest credentials at scale 

In the second case, a threat actor known as Zerofot demonstrated how AI can help attackers develop and operate malicious infrastructure at scale. 

The operator used OpenAI Codex and Claude Code to build auto_scan, a custom scanner and credential harvester that searched internet-accessible systems for exposed configuration files, directories, and other files containing sensitive information. 

This scanner extracted potential credentials and validated them against services including AWS, OpenAI, Anthropic, GitHub, GitLab, Stripe, and other providers.

Zerofot amassed a substantial volume of stolen credentials, collecting 2,975 validated keys and credentials from 1,742 victim hosts between April and May 2026. 

Those credentials included 661 SSH private keys, 635 AWS access keys associated with 214 accounts, 448 Google Gemini keys, 254 OpenAI keys, 205 GitHub tokens, and 176 Anthropic keys. 

AI’s role in the Zerofot operation went beyond just developing the scanner. 

Claude Code also handled IT and DevOps tasks needed to keep the operation running. 

These included managing scanner infrastructure and proxies, checking network routes, modifying firewall configurations, and troubleshooting the credential-harvesting environment. 

This illustrates another potential advantage for attackers: AI can support not only the intrusion itself but also the infrastructure and operational work surrounding it.

RAGE integrates AI into an exploitation framework 

In the third case, Gambit researchers examined RAGE, a custom Python framework designed to scan internet-facing services, exploit vulnerable deployments, harvest credentials, and deploy cryptocurrency miners. 

The framework included modules targeting services such as Redis, Elasticsearch, Docker, Tomcat, Jenkins, Hadoop YARN, Confluence, and Supervisord. 

Gambit researchers found indications that RAGE and many of its accompanying scripts were generated with AI, including comments and docstrings that preserved what appeared to be a model’s first-person, self-correcting reasoning.

Advertisement

RAGE took AI integration another step by incorporating an LLM directly into the attack framework. 

Its operator dashboard included a DeepSeek-backed “AI Orchestrator” designed to advise the operators running the mining botnet. 

Together, the three cases show how attackers are using AI to conduct intrusions, automate credential theft, and build AI-assisted attack frameworks. 

How to reduce risk from AI-powered attacks 

Organizations can reduce the risks posed by AI-assisted attacks by strengthening identity and infrastructure security. 

  • Enforce MFA and least-privilege access for administrative accounts, cloud identities, and other privileged systems to reduce the impact of stolen credentials.
  • Protect and regularly rotate credentials and secrets by eliminating hardcoded credentials, using centralized secrets management, and favoring short-lived credentials where possible.
  • Reduce exposure of internet-facing services by restricting administrative interfaces and hardening services such as VPNs, Redis, Docker, and other externally accessible systems.
  • Segment networks and protect critical infrastructure to restrict lateral movement and isolate domain controllers, backup servers, databases, and other high-value systems.
  • Monitor for suspicious identity and credential activity such as unusual access-key creation, role assumption, secrets retrieval, privilege escalation, and abnormal authentication attempts.
  • Test incident response plans and use attack simulation tools with scenarios around credential theft, data exfiltration and destruction, and ransomware.

Together, these measures can help limit the blast radius of a successful attack while building resilience against AI-assisted threats. 

Bottom line

The more consequential shift is the compression of attacker workflows. 

These cases show AI being used to interpret unfamiliar environments, troubleshoot failed actions, prioritize high-value assets, and maintain attack infrastructure — tasks that traditionally required more threat actor time and expertise. 

As those capabilities improve, security programs may need to reassess assumptions around attacker dwell time and operational speed.

With attacker workflows accelerating, Zero Trust can help organizations restrict access and limit lateral movement after an initial compromise.

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.