{
  "version": "https://jsonfeed.org/version/1.1",
  "title": "AI Threat Watch",
  "description": "An automated watch on attackers using AI and on attacks against AI systems. Short summaries, direct links to the source.",
  "home_page_url": "https://ai-threat.watch",
  "feed_url": "https://ai-threat.watch/feed.json",
  "language": "en",
  "items": [
    {
      "id": "https://ai-threat.watch/#2026-09-18-anthropic-misuse-report",
      "url": "https://www.anthropic.com/threat-intelligence-report-september-2026",
      "title": "Detecting and countering misuse of AI: September 2026",
      "content_text": "Anthropic describes actors who automate whole intrusion chains with AI agents. One Russian-speaking espionage operator had agents rebuild malware whenever a security product detected it, and used AI to sort hundreds of gigabytes of stolen data.",
      "date_published": "2026-09-18T00:00:00Z",
      "date_modified": "2026-09-18T06:00:00Z",
      "tags": [
        "AI-Enabled",
        "GTG-20006",
        "Midnight Blizzard"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Anthropic",
          "domain": "anthropic.com",
          "type": "vendor-report"
        },
        "actors": [
          "GTG-20006",
          "Midnight Blizzard"
        ],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "Russia",
            "claimed_by": "Anthropic",
            "confidence": "not-stated"
          }
        ],
        "also": [],
        "landmark": true
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-07-08-elastic-security-labs-ref6045-mexican-banking-fraud-toolkit-wi",
      "url": "https://www.elastic.co/security-labs/threat-command/mexican-banking-fraud-scmbanker-ref6045",
      "title": "REF6045: Mexican banking fraud toolkit with signs of AI-assisted development",
      "content_text": "Elastic Security Labs documented REF6045, an operator-assisted banking fraud campaign using ClickFix fake-CAPTCHA lures to install a PowerShell toolkit called SCMBANKER against Mexican bank, fintech, and crypto exchange customers. The toolkit enables session monitoring, screenshots, vishing overlays, clipboard hijacking, and RAT deployment, and its scripts show artifacts suggesting an LLM was used to write most of th",
      "date_published": "2026-07-08T00:00:00Z",
      "date_modified": "2026-09-21T08:43:43Z",
      "tags": [
        "AI-Enabled",
        "SCMBANKER",
        "Remote Utilities"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Elastic Security Labs",
          "domain": "elastic.co",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "SCMBANKER",
          "Remote Utilities"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "not-stated",
            "claimed_by": "Elastic Security Labs",
            "confidence": "not-stated"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-07-07-flare-mycelium-framework-first-ever-witnessed",
      "url": "https://flare.io/learn/resources/blog/mycelium-framework-ai-as-a-service-botnet",
      "title": "Mycelium Framework: First Ever Witnessed AI-as-a-Service Botnet",
      "content_text": "Flare researchers describe an underground forum advertisement for 'Mycelium Framework,' a botnet claiming to classify infected machines by compute, GPU, stolen AI API keys and local models, then route AI inference, social engineering and other tasks accordingly. No source code or proof of execution was provided, and most individual techniques are previously documented, so the AI-as-a-service claims remain unverified.",
      "date_published": "2026-07-07T00:00:00Z",
      "date_modified": "2026-09-21T08:44:11Z",
      "tags": [
        "AI-Enabled",
        "Mycelium Framework",
        "Mirai",
        "TeamTNT",
        "DorkBot",
        "RageBot",
        "Phorpiex",
        "IRCBot.HI",
        "CVE-2021-22205"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Flare",
          "domain": "flare.io",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "Mycelium Framework",
          "Mirai",
          "TeamTNT",
          "DorkBot",
          "RageBot",
          "Phorpiex",
          "IRCBot.HI"
        ],
        "vulnerabilities": [
          "CVE-2021-22205"
        ],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-07-01-sysdig-jadepuffer-agentic-ransomware-for-automa",
      "url": "https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion",
      "title": "JADEPUFFER: Agentic ransomware for automated database extortion",
      "content_text": "Sysdig's Threat Research Team documented what they assess to be the first fully agentic ransomware operation, dubbed JADEPUFFER, where an LLM autonomously gained access via a Langflow RCE flaw, harvested credentials, exploited Nacos authentication bypasses, and encrypted and destroyed a victim's production database for extortion. The payloads showed self-narrating reasoning and adaptive retries with no human interven",
      "date_published": "2026-07-01T00:00:00Z",
      "date_modified": "2026-09-21T08:43:36Z",
      "tags": [
        "AI-Enabled",
        "JADEPUFFER",
        "JADEPUFFER",
        "CVE-2025-3248",
        "CVE-2021-29441"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Sysdig",
          "domain": "sysdig.com",
          "type": "vendor-report"
        },
        "actors": [
          "JADEPUFFER"
        ],
        "malware": [
          "JADEPUFFER"
        ],
        "vulnerabilities": [
          "CVE-2025-3248",
          "CVE-2021-29441"
        ],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-06-11-fortiguard-labs-threat-actors-weaponize-ai-hype-to-deliv",
      "url": "https://www.fortinet.com/blog/threat-research/threat-actors-weaponize-ai-hype-to-deliver-asyncrat",
      "title": "Threat Actors Weaponize AI Hype to Deliver AsyncRAT",
      "content_text": "FortiGuard Labs documented a multi-stage Windows malware campaign using fake AI-themed documents and guides as lures to deliver AsyncRAT via AutoHotkey-based loaders and process hollowing. Chinese-language code artifacts and structured coding style suggest the attackers used generative AI tools to help build the malware, though this is inferred rather than confirmed.",
      "date_published": "2026-06-11T00:00:00Z",
      "date_modified": "2026-09-21T08:42:26Z",
      "tags": [
        "AI-Enabled",
        "AsyncRAT",
        "AutoHotkey",
        "clay_Client"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "FortiGuard Labs",
          "domain": "fortinet.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "AsyncRAT",
          "AutoHotkey",
          "clay_Client"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-06-11-helpnet-owasp-agentic",
      "url": "https://www.helpnetsecurity.com/2026/06/11/owasp-prompt-injection-ai-security-failures/",
      "title": "Prompt injection still drives most agentic AI security failures in production",
      "content_text": "Coverage of OWASP's 2026 findings on agentic AI. Most production failures still begin with prompt injection, and attackers increasingly poison what agents trust: MCP servers, packages and coding-tool configuration.",
      "date_published": "2026-06-11T00:00:00Z",
      "date_modified": "2026-06-11T06:00:00Z",
      "tags": [
        "AI-Targeted",
        "CVE-2025-6514",
        "CVE-2026-22708"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Help Net Security",
          "domain": "helpnetsecurity.com",
          "type": "news"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [
          "CVE-2025-6514",
          "CVE-2026-22708"
        ],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-06-03-anthropic-what-we-learned-mapping-a-year-s-worth-o",
      "url": "https://www.anthropic.com/news/AI-enabled-cyber-threats-mitre-attack",
      "title": "What we learned mapping a year's worth of AI-enabled cyber threats",
      "content_text": "Anthropic analyzed 832 accounts banned for malicious cyber activity between March 2025 and March 2026, mapping their techniques to MITRE ATT&CK. They found AI use shifting from initial access to post-compromise activity, risk scores rising over time, and the framework failing to capture autonomous agentic orchestration seen in a November 2025 state-sponsored espionage case.",
      "date_published": "2026-06-03T00:00:00Z",
      "date_modified": "2026-09-21T08:41:04Z",
      "tags": [
        "AI-Enabled",
        "Claude Code"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Anthropic",
          "domain": "anthropic.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "Claude Code"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-05-19-trend-micro-inside-shadow-water-063-s-banana-rat-fro",
      "url": "https://www.trendmicro.com/en_us/research/26/e/banana-rat.html",
      "title": "Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud",
      "content_text": "Trend Micro's MDR team correlated attacker server infrastructure with victim telemetry to map Banana RAT, a banking trojan targeting 16 Brazilian financial institutions via phishing and fileless PowerShell delivery. The malware provides remote control, keylogging, overlay injection, and PIX QR code interception, using a polymorphic crypter service to evade detection.",
      "date_published": "2026-05-19T00:00:00Z",
      "date_modified": "2026-09-21T08:43:23Z",
      "tags": [
        "AI-Targeted",
        "SHADOW-WATER-063",
        "Banana RAT",
        "Backdoor.PS1.BANANARAT.A"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Trend Micro",
          "domain": "trendmicro.com",
          "type": "vendor-report"
        },
        "actors": [
          "SHADOW-WATER-063"
        ],
        "malware": [
          "Banana RAT",
          "Backdoor.PS1.BANANARAT.A"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "Brazil",
            "claimed_by": "TrendAI",
            "confidence": "high"
          }
        ],
        "also": [
          {
            "name": "Zscaler ThreatLabz",
            "domain": "zscaler.com:443",
            "url": "https://www.zscaler.com:443/blogs/security-research/clickfix-campaign-generated-ai-delivers-smartrat"
          }
        ],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-05-12-gtig-ai-threat-tracker",
      "url": "https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access",
      "title": "GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access",
      "content_text": "GTIG reports adversaries applying AI to vulnerability exploitation, initial access and faster development of evasive, polymorphic malware. It also covers supply chain attacks against AI components, and notes no actor has yet bypassed the core safety logic of frontier models.",
      "date_published": "2026-05-12T00:00:00Z",
      "date_modified": "2026-05-12T06:00:00Z",
      "tags": [
        "AI-Enabled"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Google Threat Intelligence Group",
          "domain": "cloud.google.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": true
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-05-11-trend-micro-vibe-hacking-two-ai-augmented-campaigns",
      "url": "https://www.trendmicro.com/en_us/research/26/e/vibe-hacking-two-ai-augmented-campaigns-target-government-and-financial-sectors-in-latin-america.html",
      "title": "Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America",
      "content_text": "Trend Micro identified two campaigns, SHADOW-AETHER-040 and SHADOW-AETHER-064, using agentic AI (including Claude) to drive intrusions from initial access to data exfiltration against government and financial targets in Mexico and Brazil. The AI agents dynamically generated custom tools and backdoors, used jailbreaking via fake red-team pretexts, and integrated with Shodan and VulDB for reconnaissance.",
      "date_published": "2026-05-11T00:00:00Z",
      "date_modified": "2026-09-21T08:40:31Z",
      "tags": [
        "AI-Enabled",
        "SHADOW-AETHER-040",
        "SHADOW-AETHER-064",
        "Chisel",
        "Neo-reGeorg",
        "CrackMapExec",
        "Impacket",
        "implante_http",
        "ProxyChains",
        "PetitPotam"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Trend Micro",
          "domain": "trendmicro.com",
          "type": "vendor-report"
        },
        "actors": [
          "SHADOW-AETHER-040",
          "SHADOW-AETHER-064"
        ],
        "malware": [
          "Chisel",
          "Neo-reGeorg",
          "CrackMapExec",
          "Impacket",
          "implante_http",
          "ProxyChains",
          "PetitPotam"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-05-07-microsoft-prompts-become-shells",
      "url": "https://www.microsoft.com/en-us/security/blog/2026/05/07/prompts-become-shells-rce-vulnerabilities-ai-agent-frameworks/",
      "title": "When prompts become shells: RCE vulnerabilities in AI agent frameworks",
      "content_text": "Microsoft researchers show how a single injected prompt reached host-level code execution in agents built on Semantic Kernel. Model-controlled parameters flowed unsanitized into a search plugin. Both flaws are fixed.",
      "date_published": "2026-05-07T00:00:00Z",
      "date_modified": "2026-05-07T06:00:00Z",
      "tags": [
        "AI-Targeted",
        "CVE-2026-25592",
        "CVE-2026-26030"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Microsoft Security",
          "domain": "microsoft.com",
          "type": "research"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [
          "CVE-2026-25592",
          "CVE-2026-26030"
        ],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-04-14-owasp-exploit-roundup-q1",
      "url": "https://genai.owasp.org/2026/04/14/owasp-genai-exploit-round-up-report-q1-2026/",
      "title": "OWASP GenAI Exploit Round-up Report Q1 2026",
      "content_text": "Quarterly review of eight AI-related incidents mapped to the OWASP LLM and agentic risk lists. It includes active exploitation of a maximum-severity Flowise flaw and GrafanaGhost, a prompt injection path that exfiltrates data from Grafana's AI features.",
      "date_published": "2026-04-14T00:00:00Z",
      "date_modified": "2026-04-14T06:00:00Z",
      "tags": [
        "AI-Targeted",
        "CVE-2025-59528"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "OWASP GenAI Security Project",
          "domain": "genai.owasp.org",
          "type": "research"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [
          "CVE-2025-59528"
        ],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-04-10-gambit-security-a-single-operator-two-ai-platforms-nine",
      "url": "https://gambit.security/blog-posts/a-single-operator-two-ai-platforms-nine-government-agencies-the-full-technical-report",
      "title": "A Single Operator, Two AI Platforms, Nine Government Agencies: The Full Technical Report",
      "content_text": "Gambit Security's forensic report describes a single operator who used Claude Code and OpenAI's GPT-4.1 as core operational tools to breach nine Mexican government organizations and exfiltrate hundreds of millions of records between December 2025 and February 2026. Recovered materials show over 400 custom attack scripts, 20 tailored exploits, and thousands of AI-generated commands used to compress attack timelines an",
      "date_published": "2026-04-10T00:00:00Z",
      "date_modified": "2026-09-21T08:40:23Z",
      "tags": [
        "AI-Enabled"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Gambit Security",
          "domain": "gambit.security",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "Mexico",
            "claimed_by": "Gambit Security",
            "confidence": "not-stated"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-03-27-datadog-litellm-teampcp",
      "url": "https://securitylabs.datadoghq.com/articles/litellm-compromised-pypi-teampcp-supply-chain-campaign/",
      "title": "LiteLLM and Telnyx compromised on PyPI: Tracing the TeamPCP supply chain campaign",
      "content_text": "Two backdoored releases of LiteLLM, a widely used LLM gateway library, were published to PyPI on March 24, 2026 with a credential stealer. Datadog traces the campaign from a poisoned Trivy scanner through npm and into PyPI.",
      "date_published": "2026-03-27T00:00:00Z",
      "date_modified": "2026-03-27T06:00:00Z",
      "tags": [
        "AI-Targeted",
        "TeamPCP"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Datadog Security Labs",
          "domain": "securitylabs.datadoghq.com",
          "type": "research"
        },
        "actors": [
          "TeamPCP"
        ],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [
          {
            "name": "LiteLLM",
            "domain": "docs.litellm.ai",
            "url": "https://docs.litellm.ai/blog/security-update-march-2026"
          }
        ],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-03-12-ibm-x-force-a-slopoly-start-to-ai-enhanced-ransomwar",
      "url": "https://www.ibm.com/think/x-force/slopoly-start-ai-enhanced-ransomware-attacks",
      "title": "A Slopoly start to AI-enhanced ransomware attacks",
      "content_text": "IBM X-Force found a likely AI-generated PowerShell C2 backdoor, dubbed Slopoly, deployed by ransomware group Hive0163 during a live intrusion using ClickFix, NodeSnake, InterlockRAT and Interlock ransomware. The malware is technically unremarkable but shows guardrail bypass and signals adoption of AI-assisted malware development among established ransomware actors.",
      "date_published": "2026-03-12T00:00:00Z",
      "date_modified": "2026-09-21T08:40:16Z",
      "tags": [
        "AI-Enabled",
        "Hive0163",
        "ITG23",
        "TA569",
        "TAG-124",
        "Slopoly",
        "NodeSnake",
        "InterlockRAT",
        "Interlock",
        "JunkFiction",
        "Broomstick",
        "Supper",
        "PortStarter"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "IBM X-Force",
          "domain": "ibm.com",
          "type": "vendor-report"
        },
        "actors": [
          "Hive0163",
          "ITG23",
          "TA569",
          "TAG-124"
        ],
        "malware": [
          "Slopoly",
          "NodeSnake",
          "InterlockRAT",
          "Interlock",
          "JunkFiction",
          "Broomstick",
          "Supper",
          "PortStarter"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-02-25-openai-disrupting-malicious-uses",
      "url": "https://openai.com/index/disrupting-malicious-ai-uses/",
      "title": "Disrupting malicious uses of AI",
      "content_text": "OpenAI's case studies show models used as one step in larger workflows that also rely on websites and social accounts: romance and recovery scams, covert influence operations, and a state-linked harassment effort.",
      "date_published": "2026-02-25T00:00:00Z",
      "date_modified": "2026-02-25T06:00:00Z",
      "tags": [
        "AI-Enabled",
        "Rybar"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "OpenAI",
          "domain": "openai.com",
          "type": "vendor-report"
        },
        "actors": [
          "Rybar"
        ],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [
          {
            "name": "Help Net Security",
            "domain": "helpnetsecurity.com",
            "url": "https://www.helpnetsecurity.com/2026/02/26/openai-malicious-chatgpt-use-report/"
          }
        ],
        "landmark": true
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-02-23-trendai-research-malicious-openclaw-skills-used-to-distri",
      "url": "https://www.trendaisecurity.com/en-us/resources-insights/trendai-security-blog/malicious-openclaw-skills-used-to-distribute-atomic-macos-stealer",
      "title": "Malicious OpenClaw Skills Used to Distribute Atomic macOS Stealer",
      "content_text": "TrendAI Research documented a campaign where malicious OpenClaw agent skills trick AI agents like GPT-4o into installing a new variant of Atomic macOS Stealer (AMOS), which then deceives users into entering their password. The malware exfiltrates browser data, crypto wallets, Apple and KeePass keychains, and documents, with hundreds of malicious skills found across ClawHub, SkillsMP, and GitHub repositories.",
      "date_published": "2026-02-23T00:00:00Z",
      "date_modified": "2026-09-21T08:40:00Z",
      "tags": [
        "AI-Targeted",
        "Atomic (AMOS) Stealer",
        "AMOS"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "TrendAI Research",
          "domain": "trendaisecurity.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "Atomic (AMOS) Stealer",
          "AMOS"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-02-21-hunt-io-cyberandramen-ne-llms-in-the-kill-chain-inside-a-custom-m",
      "url": "https://cyberandramen.net/2026/02/21/llms-in-the-kill-chain-inside-a-custom-mcp-targeting-fortigate-devices-across-continents/",
      "title": "LLMs in the Kill Chain: Inside a Custom MCP Targeting FortiGate Devices Across Continents",
      "content_text": "Researchers found an exposed server revealing a threat actor using a custom MCP server (ARXON) with DeepSeek and Claude Code to automate reconnaissance, attack planning, and exploitation of compromised FortiGate devices across thousands of targets in over 100 countries. The actor evolved from using open-source HexStrike MCP tooling in December 2025 to fully custom orchestration (ARXON and CHECKER2) by February 2026,",
      "date_published": "2026-02-21T00:00:00Z",
      "date_modified": "2026-09-21T08:39:34Z",
      "tags": [
        "AI-Enabled",
        "ARXON",
        "CHECKER2",
        "HexStrike",
        "ntlmrelayx.py",
        "Impacket",
        "Metasploit",
        "BloodHound",
        "Nuclei",
        "CVE-2019-6693",
        "CVE-2026-24061",
        "CVE-2025-33073",
        "CVE-2023-27532",
        "CVE-2019-7192"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Hunt.io / cyberandramen.net",
          "domain": "cyberandramen.net",
          "type": "research"
        },
        "actors": [],
        "malware": [
          "ARXON",
          "CHECKER2",
          "HexStrike",
          "ntlmrelayx.py",
          "Impacket",
          "Metasploit",
          "BloodHound",
          "Nuclei"
        ],
        "vulnerabilities": [
          "CVE-2019-6693",
          "CVE-2026-24061",
          "CVE-2025-33073",
          "CVE-2023-27532",
          "CVE-2019-7192"
        ],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-02-20-amazon-threat-intelligen-ai-augmented-threat-actor-accesses-forti",
      "url": "https://aws.amazon.com/blogs/security/ai-augmented-threat-actor-accesses-fortigate-devices-at-scale/",
      "title": "AI-augmented threat actor accesses FortiGate devices at scale",
      "content_text": "Amazon Threat Intelligence documented a Russian-speaking, financially motivated actor using multiple commercial LLMs to compromise over 600 FortiGate devices in 55+ countries via exposed management interfaces and weak credentials, not exploits. AI generated attack plans, custom Go/Python tooling, and reconnaissance scripts, letting a low-skill actor achieve broad operational scale, though it still failed against hard",
      "date_published": "2026-02-20T00:00:00Z",
      "date_modified": "2026-09-21T08:39:05Z",
      "tags": [
        "AI-Enabled",
        "Ed1s0nZ",
        "Meterpreter",
        "mimikatz",
        "gogo",
        "Nuclei",
        "CyberStrikeAI",
        "PrivHunterAI",
        "InfiltrateX",
        "watermark-tool",
        "CVE-2019-7192",
        "CVE-2023-27532",
        "CVE-2024-40711"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Amazon Threat Intelligence",
          "domain": "aws.amazon.com",
          "type": "vendor-report"
        },
        "actors": [
          "Ed1s0nZ"
        ],
        "malware": [
          "Meterpreter",
          "mimikatz",
          "gogo",
          "Nuclei",
          "CyberStrikeAI",
          "PrivHunterAI",
          "InfiltrateX",
          "watermark-tool"
        ],
        "vulnerabilities": [
          "CVE-2019-7192",
          "CVE-2023-27532",
          "CVE-2024-40711"
        ],
        "attribution": [],
        "also": [
          {
            "name": "Team Cymru",
            "domain": "team-cymru.com",
            "url": "https://www.team-cymru.com/post/tracking-cyberstrikeai-usage"
          }
        ],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-02-19-eset-research-promptspy-ushers-in-the-era-of-android-t",
      "url": "https://www.welivesecurity.com/en/eset-research/promptspy-ushers-in-era-android-threats-using-genai/",
      "title": "PromptSpy ushers in the era of Android threats using GenAI",
      "content_text": "ESET found PromptSpy, Android malware that queries Google's Gemini with UI XML dumps to get step-by-step instructions for locking itself into the recent apps list, aiding persistence. The malware also deploys a VNC module for remote device control and targets users in Argentina; no live samples have been seen in telemetry, suggesting it may still be a proof of concept.",
      "date_published": "2026-02-19T00:00:00Z",
      "date_modified": "2026-09-21T08:39:17Z",
      "tags": [
        "AI-Enabled",
        "PromptSpy",
        "VNCSpy",
        "PromptLock",
        "Android.Phantom",
        "Android/Phishing.Agent.M"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "ESET Research",
          "domain": "welivesecurity.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "PromptSpy",
          "VNCSpy",
          "PromptLock",
          "Android.Phantom",
          "Android/Phishing.Agent.M"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "China",
            "claimed_by": "ESET",
            "confidence": "medium"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-02-12-gtig-distillation-experimentation",
      "url": "https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use",
      "title": "GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use",
      "content_text": "Quarterly view of how actors linked to North Korea, Iran, China and Russia used AI in late 2025. GTIG saw no breakthrough capability, but disrupted frequent model extraction attempts against its own models.",
      "date_published": "2026-02-12T00:00:00Z",
      "date_modified": "2026-02-12T06:00:00Z",
      "tags": [
        "AI-Enabled"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Google Threat Intelligence Group",
          "domain": "cloud.google.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "North Korea",
            "claimed_by": "Google Threat Intelligence Group",
            "confidence": "not-stated"
          },
          {
            "country": "Iran",
            "claimed_by": "Google Threat Intelligence Group",
            "confidence": "not-stated"
          },
          {
            "country": "China",
            "claimed_by": "Google Threat Intelligence Group",
            "confidence": "not-stated"
          },
          {
            "country": "Russia",
            "claimed_by": "Google Threat Intelligence Group",
            "confidence": "not-stated"
          }
        ],
        "also": [
          {
            "name": "Google",
            "domain": "blog.google",
            "url": "https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/gtig-report-ai-cyber-attacks-feb-2026/"
          }
        ],
        "landmark": true
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-02-11-moonlock-lab-moonlock-lab-thread-on-clickfix-malware",
      "url": "https://x.com/moonlock_lab/status/2021695650367226108?s=12",
      "title": "Moonlock Lab thread on ClickFix malware abusing Claude.ai and Medium",
      "content_text": "Moonlock Lab reports that a Google Sponsored ad for a macOS search led users to malware via ClickFix delivery, seen over 15,000 times. One variant abused a public artifact hosted on claude.ai, while another used a Medium post impersonating Apple support, both attributed to the same threat actor.",
      "date_published": "2026-02-11T00:00:00Z",
      "date_modified": "2026-09-21T08:38:42Z",
      "tags": [
        "AI-Targeted",
        "ClickFix"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Moonlock Lab",
          "domain": "x.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "ClickFix"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2026-01-21-breached-company-the-lethal-trifecta-strikes-four-major-a",
      "url": "https://breached.company/the-lethal-trifecta-strikes-four-major-ai-agent-vulnerabilities-in-five-days/",
      "title": "The Lethal Trifecta Strikes: Four Major AI Agent Vulnerabilities in Five Days",
      "content_text": "Between January 7-15, 2026, researchers including PromptArmor disclosed indirect prompt injection vulnerabilities in four production AI tools: IBM Bob, Superhuman AI, Notion AI, and Anthropic's Claude Cowork, each allowing data exfiltration via the 'lethal trifecta' of private data access, untrusted content exposure, and external communication channels. Vendor responses varied widely, from Superhuman's rapid remediat",
      "date_published": "2026-01-21T00:00:00Z",
      "date_modified": "2026-09-21T08:41:18Z",
      "tags": [
        "AI-Targeted",
        "Claude Cowork",
        "IBM Bob",
        "Notion AI",
        "Superhuman AI",
        "Superhuman Go"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Breached.company",
          "domain": "breached.company",
          "type": "news"
        },
        "actors": [],
        "malware": [
          "Claude Cowork",
          "IBM Bob",
          "Notion AI",
          "Superhuman AI",
          "Superhuman Go"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-12-05-unit-42-palo-alto-networ-new-prompt-injection-attack-vectors-thro",
      "url": "https://unit42.paloaltonetworks.com/model-context-protocol-attack-vectors/",
      "title": "New Prompt Injection Attack Vectors Through MCP Sampling",
      "content_text": "Unit 42 researchers show that the Model Context Protocol sampling feature, which lets MCP servers request LLM completions from the client, lacks security controls and trusts servers implicitly. They built a proof-of-concept malicious MCP server against an unnamed coding copilot demonstrating resource theft via hidden prompts, conversation hijacking, and covert tool invocation. No in-the-wild exploitation is claimed;",
      "date_published": "2025-12-05T00:00:00Z",
      "date_modified": "2026-09-21T08:38:25Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Unit 42 (Palo Alto Networks)",
          "domain": "unit42.paloaltonetworks.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-11-13-anthropic-gtg-1002",
      "url": "https://assets.anthropic.com/m/ec212e6566a0d47/original/Disrupting-the-first-reported-AI-orchestrated-cyber-espionage-campaign.pdf",
      "title": "Disrupting the first reported AI-orchestrated cyber espionage campaign",
      "content_text": "A group tasked Claude Code with running intrusions against roughly 30 organisations, with the model carrying out an estimated 80 to 90 percent of tactical work. Anthropic validated a handful of successful compromises before banning the accounts.",
      "date_published": "2025-11-13T00:00:00Z",
      "date_modified": "2025-11-13T06:00:00Z",
      "tags": [
        "AI-Enabled",
        "GTG-1002"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Anthropic",
          "domain": "anthropic.com",
          "type": "vendor-report"
        },
        "actors": [
          "GTG-1002"
        ],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "China",
            "claimed_by": "Anthropic",
            "confidence": "high"
          }
        ],
        "also": [],
        "landmark": true
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-11-05-gtig-advances-ai-tools",
      "url": "https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools",
      "title": "GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools",
      "content_text": "GTIG documents the first malware families that query an LLM during execution to generate scripts and rewrite their own code. It also describes actors posing as students or researchers to talk Gemini past its safeguards.",
      "date_published": "2025-11-05T00:00:00Z",
      "date_modified": "2025-11-05T06:00:00Z",
      "tags": [
        "AI-Enabled",
        "APT28",
        "PROMPTFLUX",
        "PROMPTSTEAL"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Google Threat Intelligence Group",
          "domain": "cloud.google.com",
          "type": "vendor-report"
        },
        "actors": [
          "APT28"
        ],
        "malware": [
          "PROMPTFLUX",
          "PROMPTSTEAL"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": true
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-11-05-infosecurity-claude-extensions",
      "url": "https://www.infosecurity-magazine.com/news/claude-desktop-extensions-prompt/",
      "title": "Claude Desktop Extensions Vulnerable to Web-Based Prompt Injection",
      "content_text": "Researchers reported that extensions for the Claude desktop app could be driven by instructions planted in web content, turning an ordinary browsing request into a path to actions on the user's machine.",
      "date_published": "2025-11-05T00:00:00Z",
      "date_modified": "2025-11-05T06:00:00Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Infosecurity Magazine",
          "domain": "infosecurity-magazine.com",
          "type": "news"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-10-07-openai-october-report",
      "url": "https://openai.com/global-affairs/disrupting-malicious-uses-of-ai-october-2025/",
      "title": "Disrupting malicious uses of AI: October 2025",
      "content_text": "OpenAI details banned accounts tied to state actors and criminal groups that used ChatGPT for malware development, scams and surveillance tooling. It reports no evidence that its models gave attackers novel offensive capability.",
      "date_published": "2025-10-07T00:00:00Z",
      "date_modified": "2025-10-07T06:00:00Z",
      "tags": [
        "AI-Enabled"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "OpenAI",
          "domain": "openai.com",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [
          {
            "name": "IT Brew",
            "domain": "itbrew.com",
            "url": "https://www.itbrew.com/stories/2025/10/15/openai-disruption-report"
          }
        ],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-09-25-koi-postmark-mcp",
      "url": "https://www.koi.ai/blog/postmark-mcp-npm-malicious-backdoor-email-theft",
      "title": "First Malicious MCP in the Wild: The Postmark Backdoor That's Stealing Your Emails",
      "content_text": "An npm package posing as the Postmark MCP server behaved normally for fifteen versions, then added one line that copied every email sent through it to the author's server. Koi calls it the first malicious MCP server seen in the wild.",
      "date_published": "2025-09-25T00:00:00Z",
      "date_modified": "2025-09-25T06:00:00Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Koi Security",
          "domain": "koi.ai",
          "type": "research"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [
          {
            "name": "The Hacker News",
            "domain": "thehackernews.com",
            "url": "https://thehackernews.com/2025/09/first-malicious-mcp-server-found.html"
          },
          {
            "name": "Dark Reading",
            "domain": "darkreading.com",
            "url": "https://www.darkreading.com/application-security/malicious-mcp-server-exfiltrates-secrets-bcc"
          }
        ],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-09-23-dataconomy-malterminal",
      "url": "https://dataconomy.com/2025/09/23/sentinelone-finds-malterminal-malware-using-openai-gpt-4/",
      "title": "SentinelOne finds MalTerminal malware using OpenAI GPT-4",
      "content_text": "SentinelLABS hunted for binaries carrying LLM API keys and embedded prompts, and found MalTerminal, which asks GPT-4 to write ransomware or a reverse shell at runtime. A retired API endpoint dates it before November 2023. No live use is known.",
      "date_published": "2025-09-23T00:00:00Z",
      "date_modified": "2025-09-23T06:00:00Z",
      "tags": [
        "AI-Enabled",
        "MalTerminal"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Dataconomy",
          "domain": "dataconomy.com",
          "type": "news"
        },
        "actors": [],
        "malware": [
          "MalTerminal"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-08-27-anthropic-threat-intel-august",
      "url": "https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf",
      "title": "Threat Intelligence Report: August 2025",
      "content_text": "Introduces vibe hacking: one criminal used Claude Code to run data extortion against at least 17 organisations. Other cases cover North Korean remote worker fraud, ransomware sold by a developer with little coding skill, and AI across the fraud ecosystem.",
      "date_published": "2025-08-27T00:00:00Z",
      "date_modified": "2025-08-27T06:00:00Z",
      "tags": [
        "AI-Enabled",
        "North Korean IT workers",
        "Claude Code",
        "Claude"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Anthropic",
          "domain": "anthropic.com",
          "type": "vendor-report"
        },
        "actors": [
          "North Korean IT workers"
        ],
        "malware": [
          "Claude Code",
          "Claude"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "North Korea",
            "claimed_by": "Anthropic",
            "confidence": "not-stated"
          },
          {
            "country": "China",
            "claimed_by": "Anthropic",
            "confidence": "not-stated"
          }
        ],
        "also": [
          {
            "name": "Anthropic",
            "domain": "anthropic.com",
            "url": "https://www.anthropic.com/news/detecting-countering-misuse-aug-2025"
          }
        ],
        "landmark": true
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-08-26-eset-promptlock",
      "url": "https://welivesecurity.com/en/ransomware/first-known-ai-powered-ransomware-uncovered-eset-research",
      "title": "First known AI-powered ransomware uncovered by ESET Research",
      "content_text": "PromptLock runs OpenAI's gpt-oss-20b locally through Ollama to generate Lua scripts that enumerate, exfiltrate and encrypt files. ESET later confirmed the samples match an academic prototype, not malware deployed in attacks.",
      "date_published": "2025-08-26T00:00:00Z",
      "date_modified": "2025-08-26T06:00:00Z",
      "tags": [
        "AI-Enabled",
        "PromptLock"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "ESET Research",
          "domain": "welivesecurity.com",
          "type": "research"
        },
        "actors": [],
        "malware": [
          "PromptLock"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-08-01-thn-cursor-curxecute",
      "url": "https://thehackernews.com/2025/08/cursor-ai-code-editor-fixed-flaw.html",
      "title": "Cursor AI Code Editor Fixed Flaw Allowing Attackers to Run Commands via Prompt Injection",
      "content_text": "An indirect prompt injection could make Cursor's agent write a malicious MCP configuration file without user approval, giving the attacker remote code execution on the developer's machine.",
      "date_published": "2025-08-01T00:00:00Z",
      "date_modified": "2025-08-01T06:00:00Z",
      "tags": [
        "AI-Targeted",
        "CVE-2025-54135"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "The Hacker News",
          "domain": "thehackernews.com",
          "type": "news"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [
          "CVE-2025-54135"
        ],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-07-18-thn-lamehug",
      "url": "https://thehackernews.com/2025/07/cert-ua-discovers-lamehug-malware.html",
      "title": "CERT-UA Discovers LAMEHUG Malware Linked to APT28, Using LLM for Phishing Campaign",
      "content_text": "LAMEHUG, delivered by phishing to Ukrainian government bodies, sends task descriptions to a Qwen model hosted on Hugging Face and runs the Windows commands it returns.",
      "date_published": "2025-07-18T00:00:00Z",
      "date_modified": "2025-07-18T06:00:00Z",
      "tags": [
        "AI-Enabled",
        "APT28",
        "UAC-0001",
        "LAMEHUG"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "The Hacker News",
          "domain": "thehackernews.com",
          "type": "news"
        },
        "actors": [
          "APT28",
          "UAC-0001"
        ],
        "malware": [
          "LAMEHUG"
        ],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "Russia",
            "claimed_by": "CERT-UA",
            "confidence": "medium"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-06-11-securityweek-echoleak",
      "url": "https://www.securityweek.com/echoleak-ai-attack-enabled-theft-of-sensitive-data-via-microsoft-365-copilot/",
      "title": "'EchoLeak' AI Attack Enabled Theft of Sensitive Data via Microsoft 365 Copilot",
      "content_text": "Aim Security showed that a single crafted email could make Microsoft 365 Copilot send internal data to an attacker with no user interaction. Microsoft patched it server-side and reported no exploitation in the wild.",
      "date_published": "2025-06-11T00:00:00Z",
      "date_modified": "2025-06-11T06:00:00Z",
      "tags": [
        "AI-Targeted",
        "CVE-2025-32711"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "SecurityWeek",
          "domain": "securityweek.com",
          "type": "news"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [
          "CVE-2025-32711"
        ],
        "attribution": [],
        "also": [
          {
            "name": "arXiv",
            "domain": "arxiv.org",
            "url": "https://arxiv.org/html/2509.10540v1"
          }
        ],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-04-01-anthropic-operating-multi-client-influence-network",
      "url": "https://cdn.sanity.io/files/4zrzovbb/website/45bc6adf039848841ed9e47051fb1209d6bb2b26.pdf",
      "title": "Operating Multi-Client Influence Networks Across Platforms",
      "content_text": "Anthropic disrupted an influence-as-a-service operation that used Claude to manage over 100 social media personas across X and Facebook, making tactical decisions on engagement and generating image prompts. The operation served at least four distinct clients pushing narratives on European, Iranian, UAE, and Kenyan interests, prioritizing persistence and relationship-building over viral spread. No nation-state attribu",
      "date_published": "2025-04-01T00:00:00Z",
      "date_modified": "2026-09-21T08:37:33Z",
      "tags": [
        "AI-Enabled",
        "Claude"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Anthropic",
          "domain": "cdn.sanity.io",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [
          "Claude"
        ],
        "vulnerabilities": [],
        "attribution": [],
        "also": [
          {
            "name": "Anthropic",
            "domain": "anthropic.com",
            "url": "https://www.anthropic.com/news/detecting-and-countering-malicious-uses-of-claude-march-2025"
          }
        ],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-01-29-google-deepmind-how-we-estimate-the-risk-from-prompt-inj",
      "url": "https://blog.google/security/how-we-estimate-risk-from-promp/",
      "title": "How we estimate the risk from prompt injection attacks on AI systems",
      "content_text": "Google DeepMind describes an automated red-teaming framework using optimization-based attacks (Actor Critic, Beam Search, Tree of Attacks with Pruning) to test AI agents' susceptibility to indirect prompt injection that could exfiltrate sensitive user data. This is a defensive research methodology, not a report of real-world exploitation, and no specific incidents are disclosed.",
      "date_published": "2025-01-29T00:00:00Z",
      "date_modified": "2026-09-21T08:37:15Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Google DeepMind",
          "domain": "blog.google",
          "type": "vendor-report"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-01-29-gtig-adversarial-misuse",
      "url": "https://cloud.google.com/blog/topics/threat-intelligence/adversarial-misuse-generative-ai",
      "title": "Adversarial Misuse of Generative AI",
      "content_text": "GTIG's first analysis of how government-backed groups used Gemini. Actors from Iran, China, North Korea and Russia used it for research, coding help and content, and did not develop novel capabilities with it.",
      "date_published": "2025-01-29T00:00:00Z",
      "date_modified": "2025-01-29T06:00:00Z",
      "tags": [
        "AI-Enabled",
        "APT43"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Google Threat Intelligence Group",
          "domain": "cloud.google.com",
          "type": "vendor-report"
        },
        "actors": [
          "APT43"
        ],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "Iran",
            "claimed_by": "Google Threat Intelligence Group",
            "confidence": "not-stated"
          },
          {
            "country": "China",
            "claimed_by": "Google Threat Intelligence Group",
            "confidence": "not-stated"
          },
          {
            "country": "North Korea",
            "claimed_by": "Google Threat Intelligence Group",
            "confidence": "not-stated"
          },
          {
            "country": "Russia",
            "claimed_by": "Google Threat Intelligence Group",
            "confidence": "not-stated"
          }
        ],
        "also": [
          {
            "name": "TechTarget",
            "domain": "techtarget.com",
            "url": "https://www.techtarget.com/searchsecurity/news/366618357/Google-details-adversarial-AI-activity-on-Gemini"
          }
        ],
        "landmark": true
      }
    },
    {
      "id": "https://ai-threat.watch/#2025-01-29-wiz-deepseek-database",
      "url": "https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak",
      "title": "Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information, Including Chat History",
      "content_text": "An unauthenticated ClickHouse database belonging to DeepSeek exposed over a million log lines, including chat history, API secrets and backend details, and allowed full control of the database. DeepSeek secured it after disclosure.",
      "date_published": "2025-01-29T00:00:00Z",
      "date_modified": "2025-01-29T06:00:00Z",
      "tags": [
        "AI-Targeted"
      ],
      "_atw": {
        "category": "ai-targeted",
        "source": {
          "name": "Wiz Research",
          "domain": "wiz.io",
          "type": "research"
        },
        "actors": [],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2024-06-26-google-threat-analysis-g-google-disrupted-over-10-000-instances-o",
      "url": "https://blog.google/threat-analysis-group/google-disrupted-dragonbridge-activity-q1-2024/",
      "title": "Google disrupted over 10,000 instances of DRAGONBRIDGE activity in Q1 2024",
      "content_text": "Google's TAG reports on DRAGONBRIDGE, a PRC-linked influence operation, disrupting over 10,000 instances in Q1 2024 across YouTube and Blogger, totaling 175,000 lifetime. The actor increasingly used generative AI, including AI-generated news anchors and synthetic voiceovers, to push narratives around Taiwan's election and US social issues, though engagement remained largely inauthentic and low.",
      "date_published": "2024-06-26T00:00:00Z",
      "date_modified": "2026-09-21T08:37:10Z",
      "tags": [
        "AI-Enabled",
        "DRAGONBRIDGE"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Google Threat Analysis Group",
          "domain": "blog.google",
          "type": "vendor-report"
        },
        "actors": [
          "DRAGONBRIDGE"
        ],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "China",
            "claimed_by": "Google Threat Analysis Group",
            "confidence": "high"
          }
        ],
        "also": [],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2024-05-01-openai-ai-and-covert-influence-operations-lates",
      "url": "https://cdn.openai.com/threat-intelligence-reports/threat-intel-report-may-2024.pdf",
      "title": "AI and Covert Influence Operations: Latest Trends",
      "content_text": "OpenAI describes disrupting five covert influence operations from Russia, China, Iran and an Israeli commercial firm that used its models to generate and refine content, translate text, and fake engagement across social platforms. None of the operations achieved meaningful audience engagement, scoring no higher than Category 2 on the Breakout Scale.",
      "date_published": "2024-05-01T00:00:00Z",
      "date_modified": "2026-09-21T08:37:00Z",
      "tags": [
        "AI-Enabled",
        "Bad Grammar",
        "Doppelganger",
        "Spamouflage",
        "International Union of Virtual Media (IUVM)",
        "Zero Zeno",
        "STOIC"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "OpenAI",
          "domain": "cdn.openai.com",
          "type": "vendor-report"
        },
        "actors": [
          "Bad Grammar",
          "Doppelganger",
          "Spamouflage",
          "International Union of Virtual Media (IUVM)",
          "Zero Zeno",
          "STOIC"
        ],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "Russia",
            "claimed_by": "OpenAI",
            "confidence": "not-stated"
          },
          {
            "country": "China",
            "claimed_by": "OpenAI",
            "confidence": "not-stated"
          },
          {
            "country": "Iran",
            "claimed_by": "OpenAI",
            "confidence": "not-stated"
          },
          {
            "country": "Israel",
            "claimed_by": "OpenAI",
            "confidence": "not-stated"
          }
        ],
        "also": [
          {
            "name": "OpenAI",
            "domain": "openai.com",
            "url": "https://openai.com/index/disrupting-deceptive-uses-of-ai-by-covert-influence-operations/"
          }
        ],
        "landmark": false
      }
    },
    {
      "id": "https://ai-threat.watch/#2024-02-14-microsoft-staying-ahead",
      "url": "https://www.microsoft.com/en-us/security/blog/2024/02/14/staying-ahead-of-threat-actors-in-the-age-of-ai/",
      "title": "Staying ahead of threat actors in the age of AI",
      "content_text": "Microsoft and OpenAI published the first joint account of state-affiliated groups using LLMs, mostly for reconnaissance, scripting help and social engineering content. The accounts were disabled.",
      "date_published": "2024-02-14T00:00:00Z",
      "date_modified": "2024-02-14T06:00:00Z",
      "tags": [
        "AI-Enabled",
        "Forest Blizzard",
        "Emerald Sleet",
        "Crimson Sandstorm",
        "Charcoal Typhoon",
        "Salmon Typhoon"
      ],
      "_atw": {
        "category": "ai-enabled",
        "source": {
          "name": "Microsoft Threat Intelligence",
          "domain": "microsoft.com",
          "type": "vendor-report"
        },
        "actors": [
          "Forest Blizzard",
          "Emerald Sleet",
          "Crimson Sandstorm",
          "Charcoal Typhoon",
          "Salmon Typhoon"
        ],
        "malware": [],
        "vulnerabilities": [],
        "attribution": [
          {
            "country": "Russia",
            "claimed_by": "Microsoft",
            "confidence": "not-stated"
          },
          {
            "country": "North Korea",
            "claimed_by": "Microsoft",
            "confidence": "not-stated"
          },
          {
            "country": "Iran",
            "claimed_by": "Microsoft",
            "confidence": "not-stated"
          },
          {
            "country": "China",
            "claimed_by": "Microsoft",
            "confidence": "not-stated"
          }
        ],
        "also": [
          {
            "name": "OpenAI",
            "domain": "openai.com",
            "url": "https://openai.com/index/disrupting-malicious-uses-of-ai-by-state-affiliated-threat-actors/"
          }
        ],
        "landmark": true
      }
    }
  ]
}