Generative AI is reshaping the cyberthreat scene, with financially motivated and nation-state actors alike using the rapidly evolving technology for deploying malware, gaining unauthorized access into corporate networks, spreading credible phishing messages, and disguising identities in scams - like North Korea’s growing use of deepfakes in
widening IT worker fraud.
Gen AI is being used to automate threats, scale operations, bypass protections, and even
target the AI deployments of organizations, cybersecurity firm
CrowdStrike noted in its
CrowdStrike 2025 Threat Hunting Report released this week.
“AI has dominated headlines recently,” Adam Meyers, senior vice president of counter adversary operations for the Austin, Texas-based company, said during a briefing with journalists. “Everybody's using AI.”
The report, which covers incidents between July 2024 and June 2025, hits on a number of other areas of concern, such rapidly growing North Korea’s state-sponsored IT worker scams, the ongoing challenge of ransomware, and the cross-domain exploits that are successfully enabling bad actors in their operations. More than 320 organizations were infiltrated by North Korean IT worker scammers that used generative AI to accelerate the attacks.
A Common Thread
That said, the thread that appears to tie much of this together is the growing use of generative AI by cybercriminals in their operations. It also highlights the need for corporate security teams and MSSPs to
incorporate the technology into their own efforts to counter the enhanced speed and sophistication of adversaries.
CrowdStrike researchers revealed that throughout 2024 and into this year, bad actors have continued to integrate generative AI into much of what they do, primarily to enhance their methods rather than replacing tactics they’ve already used.
“Nation-state adversaries — such as those attributed to Iran and North Korea — are increasingly adopting GenAI technology to make their cyber operations faster, more efficient, and harder to detect,” they wrote in the report. “They are using publicly available models to aid their reconnaissance, vulnerability research, and phishing campaign content and payload development.”
They added that “threat actors with fewer resources, including eCrime and hacktivist actors, have employed GenAI to automate tasks and improve their tools, including script generation, technical problem-solving, malware development, and infrastructure enhancement.”
AI vs. AI
Threat groups are also increasingly targeting AI systems that businesses are deploying in their networks and workflows, often using them to gain initial access into IT environments. The researchers noted several hackers exploiting an unauthenticated code injection vulnerability in Langflow AI – a popular tool for building AI agents and workflows – using specially crafted HTTP requests to achieve persistence, access credentials, and deploy ransomware.
“This activity demonstrates that threat actors are viewing AI tools as integrated infrastructure rather than peripheral applications, targeting them as primary attack vectors,” the researchers wrote. “As organizations continue adopting AI tools, the attack surface will continue expanding, and trusted AI tools will emerge as the next insider threat.”
While the use of AI by threat actors continues to skyrocket, not all of them are getting benefits from it. How effective it is depends on things like system availability and operational integration. The sophisticated ones will be able to use it more to their advantage because there is still a level of expertise needed to created AI-generated code, and not all hackers have it, according to CrowdStrike.
“Less-sophisticated adversaries tend to use it to their detriment,” Meyers said, noting that with the FunkLocker ransomware, the operators didn’t use generative AI well, which made it easy for analysts to decrypt it. They also left their name on the malware. There was a barrier to entry that the more sophisticated adversaries have used to their advantage. Less sophisticated adversaries oftentimes use it to their detriment.”
MSSPs Embrace AI
Like most defenders, MSSPs are using AI to enhance their services and to guard against AI-fueled threats. Managed cloud services provider
Cloud4C wrote this year about the
changing role of MSSPs, from scanning logs and forwarding alerts to providing continuous threat visibility, analysis, and response across a customer’s entire IT environment.
“These providers bring together intelligent tools, behavioral analytics, machine learning models, and seasoned security experts to build a holistic, real-time defense strategy,” the company wrote. “Artificial intelligence is at the heart of this transformation. Traditional security tools rely on predefined rules and signatures, which makes them slow to adapt to new threat patterns. AI-driven MSSPs, however, use real-time data and machine learning to continuously learn and evolve.”
Timus Networks listed AI-powered applications that should be
incorporated into MSSP services, including predictive threat intelligence, automated threat response, and behavioral analytics.
“By incorporating AI and ML into their service offerings, MSSPs can provide their clients with more sophisticated, efficient, and effective cybersecurity solutions, staying ahead of evolving threats in an increasingly complex digital landscape,” Timus wrote.