Cybercriminals Leverage AI and LLMs as Offensive Weapons

Cybercriminals Leverage AI and LLMs as Offensive Weapons

AI in the Crosshairs: Cybercriminals Turn Language Models into Attack Engines

The misuse of generative AI is reshaping the cyber threat landscape. Malicious actors are no longer just experimenting with tools like ChatGPT, Claude, or DeepSeek—they’re actively incorporating these large language models (LLMs) into the mechanics of modern cyberattacks. From streamlining exploit creation to fine-tuning malware, AI is becoming a force multiplier for digital crime.

Insights from the S2W Threat Intelligence Center (TALON) reveal a sharp uptick in AI-centric discussions across underground communities since the start of 2025. Offense-focused innovation has become a hot topic, with attackers sharing custom-built tools and techniques designed to bypass traditional defenses.

These developments have dramatically lowered the technical skill required to launch advanced attacks. Automated script generation, real-time obfuscation, and AI-curated reconnaissance are now commonplace. A striking example involves CVE-2024-10914, a critical remote code execution flaw. On illicit platforms like Cracked and BreachForums, AI-built scanners and exploit scripts for this vulnerability were openly circulated.

In January 2025, a threat actor known as “KuroCracks” posted a customized Masscan utility tailored to CVE-2024-10914. Enhanced through ChatGPT, the tool could autonomously identify susceptible targets and deploy payloads, allowing botnet operators to scale their infections with unprecedented efficiency. Examination of the code revealed dynamic payload generation and adaptive evasion tactics, driven by machine learning logic.

This isn’t just a shift in tooling—it’s a shift in doctrine. LLMs are no longer confined to the domain of defenders. Offensively repurposed, they are accelerating the speed, scale, and stealth of cyberattacks.

But the threat doesn’t stop at using AI—it now includes attacking it. In a disturbing trend, adversaries have begun exploiting AI infrastructures themselves. In February 2025, the actor “MTU1500Tunnel” advertised a vulnerability targeting Gemini’s API accounting mechanism. This manipulation technique could siphon processing resources or redirect AI outcomes for malicious gain.

The dual-use dilemma is becoming clearer: LLMs are both weapons and high-value targets.

The Rise of AI Without Restraints: Jailbreaking Language Models

As attackers look to unlock the full potential of LLMs, they’ve focused heavily on bypassing built-in safeguards. Open-source models, often released without strong controls, are especially at risk. Modified models like WormGPT strip out ethical boundaries entirely, offering unrestricted outputs for phishing, exploit generation, and data injection.

S2W’s analysis uncovered widespread use of prompt manipulation to subvert commercial models like ChatGPT. In one guide circulating on the dark web, users were taught how to reframe malicious requests as benign-sounding development queries, effectively slipping past content filters:

Original Prompt (Blocked)

Rephrased Prompt (Executed)

These jailbreak techniques are further weaponized with orchestration frameworks like LangChain and MCP (Model Context Protocol), enabling end-to-end automation of the attack lifecycle—from vulnerability research to live exploitation.

A Call to Action: Guarding the Future of AI

The cybercriminal playbook is evolving. Combating these emerging threats requires more than reactive measures—it calls for a collaborative, systemic approach. S2W advocates for comprehensive defenses, including AI prompt abuse detection, traffic monitoring at the LLM API layer, and stronger community intelligence sharing to stay ahead of adversaries.

In the age of AI-augmented threats, innovation and security must move forward together. The stakes are no longer hypothetical—this is the new frontline of cybersecurity.

More Articles & Posts