Cisco Talos analyzed AI/LLM prompt logs and artifacts recovered from endpoints to document how threat actors across skill levels are weaponizing AI for malicious software development, criminal force multiplication, and vulnerability research. Guardrails across all major AI platforms are failing — actors bypass them with simple ownership claims, CTF labeling, task decomposition, and persistent memory conditioning. The report details multiple active operations including a 2000-device Android TV DDoS botnet, a 50M-record bulk-mail validation platform (Tubely), a React2Shell credential harvesting pipeline targeting 9,180+ hosts, a Deluge/qBittorrent cryptojacking fleet, Telegram Mini App wallet-draining operations, and the autonomous Hephaestus red team framework. Actor skill level is the primary determinant of operational impact, with advanced actors achieving sophisticated capabilities while novice actors produce functional but limited tooling.
DDoS botnet
1 post
“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI