Artificial intelligence (AI) is no longer simply improving attacker productivity.
According to a new ThreatDown report, AI is fundamentally reshaping the cybercrime ecosystem by lowering the barriers to sophisticated attacks and enabling autonomous exploitation.
- Key takeaways of the ThreatDown AI cybercrime report
- How AI Is Lowering the Barrier to Cyberattacks
- Criminal AI tools are becoming easier to access
- How AI Is changing malware and cyberattack techniques
- How AI agents are creating new insider security risks
- How shadow AI increases enterprise cybersecurity risk
- AI could accelerate zero-day vulnerability discovery
- How organizations can prepare for AI-powered cyber threats
Key takeaways of the ThreatDown AI cybercrime report
- AI is lowering the barrier to sophisticated cyberattacks by enabling autonomous reconnaissance, exploitation, and attack planning.
- Criminals are increasingly using guardrail-free AI models and legitimate AI infrastructure to scale cyber operations.
- Shadow AI, malicious AI agent skills, and AI-powered malware are creating new enterprise security and identity risks.
- Researchers warn AI could dramatically accelerate zero-day discovery, shrinking the time defenders have to patch vulnerabilities.
- Organizations should prioritize vulnerability management, continuous monitoring, and shadow AI governance to prepare for AI-powered threats.
How AI Is Lowering the Barrier to Cyberattacks
The report also warns that unmanaged AI adoption is expanding organizations’ attack surfaces and creating new opportunities for attackers.
Researchers suggest that organizations have a narrowing window — roughly six months — to prepare before the next generation of AI-powered cyber threats becomes mainstream.
The findings highlight how modern AI agents have evolved beyond answering questions or generating code.
Today’s models can complete complex tasks independently, operate software for extended periods, and collaborate with other AI agents.
While these capabilities increase productivity for legitimate users, they also provide cybercriminals with powerful new offensive tools.
One example cited in the report involved an attacker using mainstream AI models to compromise multiple Mexican government organizations.
During reconnaissance, the AI identified a supervisory control and data acquisition (SCADA) interface inside a municipal water utility, classified it as critical infrastructure, and recommended an attack path despite the attacker having no prior operational technology expertise.
Although the intrusion ultimately failed, the incident demonstrated how AI can dramatically reduce the expertise required to target critical infrastructure.
Criminal AI tools are becoming easier to access
Researchers also found that malicious AI tools are becoming increasingly accessible.
Rather than relying on custom-built criminal models, many underground services simply wrap legitimate frontier AI models with jailbreaks that remove safety guardrails or resell access through legitimate cloud infrastructure.
The report also found more than 6,600 openly published guardrail-free AI models on Hugging Face.
Together, these models accumulated approximately 22 million downloads in a single 30-day period.
Because many can run locally, they eliminate opportunities for cloud providers to monitor prompts or restrict misuse.
How AI Is changing malware and cyberattack techniques
Threat actors are increasingly incorporating AI directly into their operations.
The report references documented cases where AI agents automated reconnaissance, credential harvesting, and network penetration across multiple industries.
Researchers also observed malware capable of generating malicious logic dynamically during execution rather than embedding it inside binaries, reducing the effectiveness of traditional signature-based detection.
More recent malware variants go even further by running AI models locally on compromised systems instead of relying on cloud APIs.
This removes visibility for AI providers while making defensive monitoring more difficult.
How AI agents are creating new insider security risks
The rapid adoption of autonomous AI agents also creates new enterprise risks.
According to the report, public marketplaces for AI agent skills have quickly become targets for attackers.
Researchers documented malicious skills capable of stealing credentials, exfiltrating sensitive data, installing malware, and even modifying an AI agent’s long-term memory to maintain persistence.
Attackers also shifted toward social engineering techniques by disguising malware as legitimate AI-related resources.
In one example, a fake guide promising to help users profit from AI-driven prediction markets instructed victims to download a malicious executable that ultimately installed credential-stealing malware.
At the time of discovery, the payload reportedly achieved near-zero detection across many endpoint security products.
How shadow AI increases enterprise cybersecurity risk
The report warns that employee adoption of unsanctioned AI tools is creating a rapidly expanding attack surface.
Nearly half of employees using generative AI reportedly access these services through unmanaged personal accounts.
Researchers cite data indicating that one in five organizations experienced a breach linked to shadow AI in 2025, with incidents costing an average of $670,000 more than standard breaches.
In addition to exposing sensitive conversations and business data, unmanaged AI platforms often contain valuable credentials, OAuth tokens, API keys, and session tokens that can be leveraged during identity-based attacks.
AI could accelerate zero-day vulnerability discovery
Perhaps the report’s most concerning prediction involves software vulnerabilities.
Researchers point to what they describe as the first known criminal use of AI to develop a zero-day exploit and argue that future AI models could dramatically accelerate vulnerability discovery.
The report highlights Anthropic’s Mythos research model, which reportedly identified zero-day vulnerabilities across major operating systems and browsers while demonstrating the ability to construct complex multi-stage attack chains.
Researchers believe AI models with similar capabilities could appear on criminal marketplaces within six to twelve months, increasing both exploit development and patching demands for defenders.
How organizations can prepare for AI-powered cyber threats
ThreatDown suggests that organizations should focus on three key priorities as AI-powered attacks continue to mature:
- Accelerate vulnerability management and patch deployment to reduce exploit windows.
- Maintain continuous monitoring through security operations or managed detection and response to identify AI-assisted attacks early.
- Discover and govern shadow AI by identifying unauthorized AI tools, agent skills, and AI integrations operating throughout the environment.
Rather than viewing AI as simply another technology trend, the report suggests organizations should prepare for a cybersecurity landscape where attackers can automate reconnaissance, accelerate exploit development, and weaponize AI adoption itself.
While many of these capabilities are already emerging, researchers believe the next several months could determine whether defenders stay ahead of AI-enabled threats or struggle to keep pace.
Whether the initial compromise comes from AI-assisted phishing, credential theft, or a zero-day exploit, Zero Trust helps limit attacker access and reduce the blast radius.





