AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt Injection
AI-Powered Cyber Attacks (TL-2026-2668), also tracked as EchoLeak, is a medium-severity tracked intrusion set, first published 2026-09-26. It is linked to a Russia, China, Iran, North Korea-nexus actor with medium confidence, affects Microsoft 365 Copilot (Word, Excel, PowerPoint, Outlook, Teams, references 1 CVE (CVE-2025-32711), maps to 19 MITRE ATT&CK / ATLAS techniques (AML.T0040, AML.T0051, AML.T0054), and is covered by 9 detection rules and 27 indicators of compromise.
Key facts for TL-2026-2668
- Threat ID
- TL-2026-2668
- Also known as
- EchoLeak, Vibe Hacking (AI-directed autonomous exploitation)
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-09-26
- Last reviewed
- 2026-09-26
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia, China, Iran, North Korea
- Motivation
- ESPIONAGE
- Target sectors
- government administration, defense, finance, technology, health, energy, retail, education, manufacturing
- Target regions
- North America, Europe, Asia-Pacific, Global
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in AI-Powered Cyber Attacks
Malware and tooling: BlackMamba, DarkSword, GiftDrop, LAMEHUG, LAMEHUG - S9035, MalTerminal, MiniPlasma, PowerChrome, PromptLock, shadow, BeEF, PentAGI
Multiple corroborating 2023-2026 vendor and government reports document AI/LLM tooling now embedded across the full attack lifecycle: LLM-personalized phishing built from scraped LinkedIn/breach data, deepfake voice/video used to defraud Arup of $25.6M in a single Hong Kong incident, self-rewriting AI-generated malware (BlackMamba, MalTerminal, PromptLock, LAMEHUG/PROMPTSTEAL) that evades signature and even EDR detection, state-nexus actors (Midnight Blizzard-linked, Chinese exploit-foundry operators, APT31/APT42/UNC2970) abusing Claude and Gemini for reconnaissance and autonomous exploitation, and zero-click prompt injection (EchoLeak, CVE-2025-32711) that exfiltrated data from Microsoft 365 Copilot without any user interaction.
How AI-Powered Cyber Attacks works
This threat aggregates six distinct, independently evidenced AI-enabled attack techniques that a September 25, 2026 SOC Prime overview ties together as a single detection-engineering trend, and which this research substantiates against primary vendor/government reporting rather than treating as a single incident.
1) AI-generated phishing and social engineering: threat actors now scrape LinkedIn profiles, breach dumps, and public code/cloud-metadata footprints with LLMs to auto-generate individualized lures at volume, collapsing what Trend Micro documented as a 'LinkedIn to tailored attack in 30 minutes' pipeline. Google's Threat Intelligence Group (GTIG) confirmed North Korea's UNC2970 used Gemini to research cybersecurity/defense-firm job roles and salary data to refine fake-recruiter phishing personas, while Iran's APT42 used Gemini for translation, persona development, and phishing-content drafting across multiple operation stages.
2) Deepfake voice/video BEC: in February 2024, engineering firm Arup's Hong Kong office was defrauded of HK$200 million (~US$25.6 million) across 15 wire transfers after a finance employee joined a video conference in which every other 'participant' -- impersonating the CFO and colleagues -- was a real-time deepfake, following an initial CFO-impersonation spear-phishing email. The fraud was only discovered when the employee separately contacted head office about the 'secret transaction.'
3) Polymorphic, AI-written malware: HYAS Labs' March 2023 BlackMamba proof-of-concept queries OpenAI's API at every execution to re-synthesize its keylogging payload via Python's exec(), producing a functionally identical but binarily unique sample each run and recording zero detections against a leading EDR in testing. SentinelLABS' LABScon25 research (September 2025) documented MalTerminal, the earliest known malware with an embedded LLM (GPT-4) call used to generate ransomware or reverse-shell code on demand, plus PromptLock ransomware (uses a locally hosted gpt-oss:20b model via the Ollama API to write malicious Lua on the fly) and APT28-linked LAMEHUG/PROMPTSTEAL (invokes Qwen2.5-Coder-32B-Instruct via the Hugging Face API to generate attacker commands from static prompts). A year-long SentinelLABS VirusTotal retrohunt found 7,000+ samples containing 6,000+ unique hardcoded LLM-provider API keys, which the researchers note is itself a detection opportunity.
4) AI-accelerated reconnaissance and employee profiling: beyond the Gemini cases above, Anthropic's September 2026 threat intelligence report documents a Chinese-speaking operation (GTG-10007, tracked to Changsha, Hunan) that used Claude as an 'agent swarm' orchestration layer to decompose reconnaissance across roughly 50 organizations into parallel subagents, and a Russian state-nexus operation (GTG-20006, linked to Midnight Blizzard) that used Claude for reconnaissance, phishing-infrastructure automation, and command execution against 20+ Ukrainian/European government, defense, and embassy targets -- notably having Claude autonomously rebuild its own malware components the moment security products flagged them.
5) AI-assisted, multi-turn BEC conversation: industry reporting (Proofpoint, Abnormal Security) describes BEC evolving from single impersonation emails into coordinated, multi-persona campaigns that build trust over several exchanges, with the AI adjusting tone and content based on victim replies -- consistent with Anthropic's report of Claude being used for real-time exploitation-pipeline decision-making rather than one-shot content generation.
6) Prompt injection against enterprise AI assistants: CVE-2025-32711 ('EchoLeak', CWE-74, disclosed by Aim Security and patched server-side by Microsoft in June 2025, CVSS 9.3 per Microsoft / 7.5 per NVD) is the first documented real-world zero-click prompt-injection exploit against a production LLM system: a single crafted email caused Microsoft 365 Copilot to access and exfiltrate internal file contents to an attacker-controlled endpoint with no user interaction, by chaining bypasses of the XPIA cross-prompt-injection classifier, Markdown link redaction, auto-fetched images, and an allow-listed Teams proxy. Anthropic's September 2026 report separately documents the inverse pattern -- an AI-supply-chain actor (GTG-50020) injecting malicious instructions into an AI vendor's own automated evaluation sandbox to steal production API keys, and a fraudulent-reseller operation (GTG-50021) harvesting Anthropic account credentials through look-alike discounted-access sites.
Taken together, these six vectors show AI is not a single new technique but a force multiplier applied across the existing ATT&CK kill chain -- reconnaissance, resource development, initial access, execution, defense evasion, credential access, collection, exfiltration, and C2 -- which is why this threat is scoped and published as a cross-cutting TTP-trend advisory rather than a single-actor incident.
MITRE ATT&CK / ATLAS techniques used in TL-2026-2668
ML Model Access
AML.T0040 AI Model Inference API Access
execution
AML.T0051 LLM Prompt Injection
Defense Evasion
AML.T0054 LLM Jailbreak; T1027 Obfuscated Files or Information; T1684.001 Impersonation
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol
Collection
Initial Access
T1195 Supply Chain Compromise; T1566 Phishing
Credential Access
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1585 Establish Accounts; T1588 Obtain Capabilities
Reconnaissance
T1589 Gather Victim Identity Information; T1591 Gather Victim Org Information; T1593 Search Open Websites/Domains; T1598 Phishing for Information
Affected products and versions in AI-Powered Cyber Attacks
- Microsoft — 365 Copilot (Word, Excel, PowerPoint, Outlook, Teams integrations)
Vulnerable versions: all tenants prior to the June 2025 server-side fix for CVE-2025-32711 (EchoLeak)
Fixed in: server-side patched by Microsoft, June 2025 -- no client update required - Multiple — Enterprise LLM assistants/agents that ingest untrusted email or documents
Vulnerable versions: any deployment lacking indirect-prompt-injection input sanitization or output-scope controls
Fixed in: N/A -- requires architectural mitigation, not a vendor patch
Remediation for AI-Powered Cyber Attacks
Patches
- Microsoft 365 Copilot server-side patch for CVE-2025-32711 (EchoLeak) -- applied automatically by Microsoft as of June 2025; no client-side action required, but tenants should confirm Purview/XPIA classifier logging is enabled.
Immediate actions
- Enforce out-of-band callback verification using pre-established phone numbers (never numbers supplied within the suspect call/email) for any wire-transfer, payroll, or credential-reset request, even when 'approved' over a video or voice call.
- Apply Microsoft's server-side fix for CVE-2025-32711 (EchoLeak) and audit any enterprise AI assistant that ingests untrusted email/documents for indirect prompt-injection exposure (auto-fetched remote images, markdown link rendering, proxy allow-lists).
- Rotate and scope down AI-provider (Anthropic/OpenAI/Google) API keys and session tokens, especially any obtained through third-party resellers or unmanaged proxy services, per Anthropic's documented fraudulent-reseller credential-harvesting cases.
Workarounds
- Restrict Copilot/enterprise-AI-assistant ability to auto-fetch remote images or render reference-style Markdown links from untrusted email/document content until XPIA-equivalent hardening is independently verified.
- Require secondary human approval for any AI-agent-initiated financial transaction, credential change, or bulk data/mailbox export.
Longer-term hardening
- Tune EDR/behavioral detection to flag LLM-generated code patterns (hardcoded provider API keys, embedded prompt strings, runtime code synthesis via exec()/eval()) rather than relying on static signatures, given confirmed AI-rewritten polymorphic payloads (BlackMamba, MalTerminal, PromptLock, LAMEHUG).
- Adopt liveness-detection and multi-channel (not single video/voice channel) identity verification for executive-authorized financial or credential actions to counter deepfake BEC.
- Establish AI/agentic-tool usage governance: scope what actions an AI agent may take autonomously, require human approval for financial/credential/bulk-export actions, and log all agent tool calls for audit.
CVEs associated with AI-Powered Cyber Attacks
Weaknesses (CWE) in AI-Powered Cyber Attacks
CWE-74
Timeline of AI-Powered Cyber Attacks
- HYAS Labs discloses BlackMamba, a proof-of-concept polymorphic keylogger that calls OpenAI's API at every execution to re-synthesize its payload, recording zero detections in EDR testing.
- WormGPT, a GPT-J-based uncensored LLM fine-tuned for BEC/phishing content generation, appears on underground forums marketed as 'the blackhat alternative to GPT.'
- FraudGPT is identified circulating on dark web forums and Telegram channels for phishing pages, scam content, and vulnerability discovery.
- Engineering firm Arup's Hong Kong office is defrauded of roughly HK$200 million (~US$25.6 million) across 15 wire transfers after a finance employee is deceived on a video call where every other participant, impersonating the CFO and colleagues, is a real-time deepfake.
- Arup is publicly confirmed as the victim of the Hong Kong deepfake video-conference BEC scam.
- CVE-2025-32711 ('EchoLeak') is disclosed by Aim Security and patched server-side by Microsoft: a zero-click prompt-injection flaw letting a single crafted email cause Microsoft 365 Copilot to exfiltrate internal data with no user interaction.
- Academic paper formalizes EchoLeak as the first real-world zero-click prompt-injection exploit against a production LLM system.
- SentinelLABS presents LABScon25 research documenting MalTerminal (earliest known LLM-embedded malware using GPT-4), PromptLock, and APT28-linked LAMEHUG/PROMPTSTEAL, plus a year-long VirusTotal retrohunt finding 7,000+ samples with 6,000+ hardcoded LLM API keys.
- Google's Threat Intelligence Group discloses state-backed actors (China's APT31/Temp.HEX, Iran's APT42, North Korea's UNC2970, and Russian groups) abusing Gemini for reconnaissance, phishing-lure creation, exploit research, and C2 development across the full attack lifecycle.
- A data leak reportedly exposes close to 19,000 WormGPT buyer accounts, including emails and payment metadata.
- Anthropic publishes its September 2026 threat intelligence report detailing seven categories of AI misuse, including a Russian state-nexus operation (GTG-20006, Midnight Blizzard-linked) that had Claude autonomously rebuild detected malware, a Chinese exploit-foundry operation (GTG-10007) running agent-swarm reconnaissance across ~50 organizations, ShinyHunters-affiliated 'vibe hacking' (GTG-50014), and AI-supply-chain credential-theft campaigns (GTG-50020, GTG-50021).
- SOC Prime publishes 'What Is an AI-Powered Cyber Attack?', synthesizing AI-personalized phishing, deepfake BEC, polymorphic malware, AI-accelerated recon, AI-assisted BEC dialogue, and prompt injection into a single detection-engineering trend brief.
Sources cited for AI-Powered Cyber Attacks
- What Is an AI-Powered Cyber Attack?
- Countering misuse of AI: September 2026
- GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools
- Google Reports State-Backed Hackers Using Gemini AI for Recon and Attack Support
- Deepfake CFO Video Calls Result in $25MM in Damages
- Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee
- LABScon25 Replay | LLM-Enabled Malware In the Wild
- Researchers Uncover GPT-4-Powered MalTerminal Malware Creating Ransomware, Reverse Shell
- Malicious AI Exposed: WormGPT, MalTerminal, and LameHug
- Dark Web Markets Offer New FraudGPT AI Tool
- BlackMamba: Using AI to Generate Polymorphic Malware
- EchoLeak (CVE-2025-32711): What the Microsoft Copilot Prompt Injection Vulnerability Means for Your Data
- EchoLeak: The First Real-World Zero-Click Prompt Injection Exploit in a Production LLM System
- CVE-2025-32711 Detail
- From LinkedIn to Tailored Attack in 30 Minutes: How AI Accelerates Target Profiling for Cybercrime
More in threat intel
- Insiders for Hire: Underground Market for Employee Access Expands Beyond Privileged IT Roles
- Agentic AI used for post-exploitation in breach of the Dutch Institute for Vulnerability Disclosure (DIVD)
- Hacker-for-Hire Economy: Cyber Mercenaries Offer Account Compromise, Surveillance, Doxxing and DDoS as a Service
- ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and Multiple Unverified Data-Breach Claims
- Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem
Detection coverage for TL-2026-2668
As of 2026-09-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2668 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.