AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt Injection

AI-Powered Cyber Attacks (TL-2026-2668), also tracked as EchoLeak, is a medium-severity tracked intrusion set, first published 2026-09-26. It is linked to a Russia, China, Iran, North Korea-nexus actor with medium confidence, affects Microsoft 365 Copilot (Word, Excel, PowerPoint, Outlook, Teams, references 1 CVE (CVE-2025-32711), maps to 19 MITRE ATT&CK / ATLAS techniques (AML.T0040, AML.T0051, AML.T0054), and is covered by 9 detection rules and 27 indicators of compromise.

Key facts for TL-2026-2668

Threat ID
TL-2026-2668
Also known as
EchoLeak, Vibe Hacking (AI-directed autonomous exploitation)
Severity
MEDIUM
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-09-26
Last reviewed
2026-09-26
Attribution confidence
MEDIUM
Nation-state nexus
Russia, China, Iran, North Korea
Motivation
ESPIONAGE
Target sectors
government administration, defense, finance, technology, health, energy, retail, education, manufacturing
Target regions
North America, Europe, Asia-Pacific, Global
Detection rules
9
Indicators of compromise
27

Malware and tooling in AI-Powered Cyber Attacks

Malware and tooling: BlackMamba, DarkSword, GiftDrop, LAMEHUG, LAMEHUG - S9035, MalTerminal, MiniPlasma, PowerChrome, PromptLock, shadow, BeEF, PentAGI

Multiple corroborating 2023-2026 vendor and government reports document AI/LLM tooling now embedded across the full attack lifecycle: LLM-personalized phishing built from scraped LinkedIn/breach data, deepfake voice/video used to defraud Arup of $25.6M in a single Hong Kong incident, self-rewriting AI-generated malware (BlackMamba, MalTerminal, PromptLock, LAMEHUG/PROMPTSTEAL) that evades signature and even EDR detection, state-nexus actors (Midnight Blizzard-linked, Chinese exploit-foundry operators, APT31/APT42/UNC2970) abusing Claude and Gemini for reconnaissance and autonomous exploitation, and zero-click prompt injection (EchoLeak, CVE-2025-32711) that exfiltrated data from Microsoft 365 Copilot without any user interaction.

How AI-Powered Cyber Attacks works

This threat aggregates six distinct, independently evidenced AI-enabled attack techniques that a September 25, 2026 SOC Prime overview ties together as a single detection-engineering trend, and which this research substantiates against primary vendor/government reporting rather than treating as a single incident.

1) AI-generated phishing and social engineering: threat actors now scrape LinkedIn profiles, breach dumps, and public code/cloud-metadata footprints with LLMs to auto-generate individualized lures at volume, collapsing what Trend Micro documented as a 'LinkedIn to tailored attack in 30 minutes' pipeline. Google's Threat Intelligence Group (GTIG) confirmed North Korea's UNC2970 used Gemini to research cybersecurity/defense-firm job roles and salary data to refine fake-recruiter phishing personas, while Iran's APT42 used Gemini for translation, persona development, and phishing-content drafting across multiple operation stages.

2) Deepfake voice/video BEC: in February 2024, engineering firm Arup's Hong Kong office was defrauded of HK$200 million (~US$25.6 million) across 15 wire transfers after a finance employee joined a video conference in which every other 'participant' -- impersonating the CFO and colleagues -- was a real-time deepfake, following an initial CFO-impersonation spear-phishing email. The fraud was only discovered when the employee separately contacted head office about the 'secret transaction.'

3) Polymorphic, AI-written malware: HYAS Labs' March 2023 BlackMamba proof-of-concept queries OpenAI's API at every execution to re-synthesize its keylogging payload via Python's exec(), producing a functionally identical but binarily unique sample each run and recording zero detections against a leading EDR in testing. SentinelLABS' LABScon25 research (September 2025) documented MalTerminal, the earliest known malware with an embedded LLM (GPT-4) call used to generate ransomware or reverse-shell code on demand, plus PromptLock ransomware (uses a locally hosted gpt-oss:20b model via the Ollama API to write malicious Lua on the fly) and APT28-linked LAMEHUG/PROMPTSTEAL (invokes Qwen2.5-Coder-32B-Instruct via the Hugging Face API to generate attacker commands from static prompts). A year-long SentinelLABS VirusTotal retrohunt found 7,000+ samples containing 6,000+ unique hardcoded LLM-provider API keys, which the researchers note is itself a detection opportunity.

4) AI-accelerated reconnaissance and employee profiling: beyond the Gemini cases above, Anthropic's September 2026 threat intelligence report documents a Chinese-speaking operation (GTG-10007, tracked to Changsha, Hunan) that used Claude as an 'agent swarm' orchestration layer to decompose reconnaissance across roughly 50 organizations into parallel subagents, and a Russian state-nexus operation (GTG-20006, linked to Midnight Blizzard) that used Claude for reconnaissance, phishing-infrastructure automation, and command execution against 20+ Ukrainian/European government, defense, and embassy targets -- notably having Claude autonomously rebuild its own malware components the moment security products flagged them.

5) AI-assisted, multi-turn BEC conversation: industry reporting (Proofpoint, Abnormal Security) describes BEC evolving from single impersonation emails into coordinated, multi-persona campaigns that build trust over several exchanges, with the AI adjusting tone and content based on victim replies -- consistent with Anthropic's report of Claude being used for real-time exploitation-pipeline decision-making rather than one-shot content generation.

6) Prompt injection against enterprise AI assistants: CVE-2025-32711 ('EchoLeak', CWE-74, disclosed by Aim Security and patched server-side by Microsoft in June 2025, CVSS 9.3 per Microsoft / 7.5 per NVD) is the first documented real-world zero-click prompt-injection exploit against a production LLM system: a single crafted email caused Microsoft 365 Copilot to access and exfiltrate internal file contents to an attacker-controlled endpoint with no user interaction, by chaining bypasses of the XPIA cross-prompt-injection classifier, Markdown link redaction, auto-fetched images, and an allow-listed Teams proxy. Anthropic's September 2026 report separately documents the inverse pattern -- an AI-supply-chain actor (GTG-50020) injecting malicious instructions into an AI vendor's own automated evaluation sandbox to steal production API keys, and a fraudulent-reseller operation (GTG-50021) harvesting Anthropic account credentials through look-alike discounted-access sites.

Taken together, these six vectors show AI is not a single new technique but a force multiplier applied across the existing ATT&CK kill chain -- reconnaissance, resource development, initial access, execution, defense evasion, credential access, collection, exfiltration, and C2 -- which is why this threat is scoped and published as a cross-cutting TTP-trend advisory rather than a single-actor incident.

MITRE ATT&CK / ATLAS techniques used in TL-2026-2668

ML Model Access

AML.T0040 AI Model Inference API Access

execution

AML.T0051 LLM Prompt Injection

Defense Evasion

AML.T0054 LLM Jailbreak; T1027 Obfuscated Files or Information; T1684.001 Impersonation

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol

Collection

T1114 Email Collection

Initial Access

T1195 Supply Chain Compromise; T1566 Phishing

Credential Access

T1552 Unsecured Credentials

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1585 Establish Accounts; T1588 Obtain Capabilities

Reconnaissance

T1589 Gather Victim Identity Information; T1591 Gather Victim Org Information; T1593 Search Open Websites/Domains; T1598 Phishing for Information

Affected products and versions in AI-Powered Cyber Attacks

  • Microsoft — 365 Copilot (Word, Excel, PowerPoint, Outlook, Teams integrations)
    Vulnerable versions: all tenants prior to the June 2025 server-side fix for CVE-2025-32711 (EchoLeak)
    Fixed in: server-side patched by Microsoft, June 2025 -- no client update required
  • Multiple — Enterprise LLM assistants/agents that ingest untrusted email or documents
    Vulnerable versions: any deployment lacking indirect-prompt-injection input sanitization or output-scope controls
    Fixed in: N/A -- requires architectural mitigation, not a vendor patch

Remediation for AI-Powered Cyber Attacks

Patches

  • Microsoft 365 Copilot server-side patch for CVE-2025-32711 (EchoLeak) -- applied automatically by Microsoft as of June 2025; no client-side action required, but tenants should confirm Purview/XPIA classifier logging is enabled.

Immediate actions

  • Enforce out-of-band callback verification using pre-established phone numbers (never numbers supplied within the suspect call/email) for any wire-transfer, payroll, or credential-reset request, even when 'approved' over a video or voice call.
  • Apply Microsoft's server-side fix for CVE-2025-32711 (EchoLeak) and audit any enterprise AI assistant that ingests untrusted email/documents for indirect prompt-injection exposure (auto-fetched remote images, markdown link rendering, proxy allow-lists).
  • Rotate and scope down AI-provider (Anthropic/OpenAI/Google) API keys and session tokens, especially any obtained through third-party resellers or unmanaged proxy services, per Anthropic's documented fraudulent-reseller credential-harvesting cases.

Workarounds

  • Restrict Copilot/enterprise-AI-assistant ability to auto-fetch remote images or render reference-style Markdown links from untrusted email/document content until XPIA-equivalent hardening is independently verified.
  • Require secondary human approval for any AI-agent-initiated financial transaction, credential change, or bulk data/mailbox export.

Longer-term hardening

  • Tune EDR/behavioral detection to flag LLM-generated code patterns (hardcoded provider API keys, embedded prompt strings, runtime code synthesis via exec()/eval()) rather than relying on static signatures, given confirmed AI-rewritten polymorphic payloads (BlackMamba, MalTerminal, PromptLock, LAMEHUG).
  • Adopt liveness-detection and multi-channel (not single video/voice channel) identity verification for executive-authorized financial or credential actions to counter deepfake BEC.
  • Establish AI/agentic-tool usage governance: scope what actions an AI agent may take autonomously, require human approval for financial/credential/bulk-export actions, and log all agent tool calls for audit.

CVEs associated with AI-Powered Cyber Attacks

CVE-2025-32711

Weaknesses (CWE) in AI-Powered Cyber Attacks

CWE-74

Timeline of AI-Powered Cyber Attacks

  • HYAS Labs discloses BlackMamba, a proof-of-concept polymorphic keylogger that calls OpenAI's API at every execution to re-synthesize its payload, recording zero detections in EDR testing.
  • WormGPT, a GPT-J-based uncensored LLM fine-tuned for BEC/phishing content generation, appears on underground forums marketed as 'the blackhat alternative to GPT.'
  • FraudGPT is identified circulating on dark web forums and Telegram channels for phishing pages, scam content, and vulnerability discovery.
  • Engineering firm Arup's Hong Kong office is defrauded of roughly HK$200 million (~US$25.6 million) across 15 wire transfers after a finance employee is deceived on a video call where every other participant, impersonating the CFO and colleagues, is a real-time deepfake.
  • Arup is publicly confirmed as the victim of the Hong Kong deepfake video-conference BEC scam.
  • CVE-2025-32711 ('EchoLeak') is disclosed by Aim Security and patched server-side by Microsoft: a zero-click prompt-injection flaw letting a single crafted email cause Microsoft 365 Copilot to exfiltrate internal data with no user interaction.
  • Academic paper formalizes EchoLeak as the first real-world zero-click prompt-injection exploit against a production LLM system.
  • SentinelLABS presents LABScon25 research documenting MalTerminal (earliest known LLM-embedded malware using GPT-4), PromptLock, and APT28-linked LAMEHUG/PROMPTSTEAL, plus a year-long VirusTotal retrohunt finding 7,000+ samples with 6,000+ hardcoded LLM API keys.
  • Google's Threat Intelligence Group discloses state-backed actors (China's APT31/Temp.HEX, Iran's APT42, North Korea's UNC2970, and Russian groups) abusing Gemini for reconnaissance, phishing-lure creation, exploit research, and C2 development across the full attack lifecycle.
  • A data leak reportedly exposes close to 19,000 WormGPT buyer accounts, including emails and payment metadata.
  • Anthropic publishes its September 2026 threat intelligence report detailing seven categories of AI misuse, including a Russian state-nexus operation (GTG-20006, Midnight Blizzard-linked) that had Claude autonomously rebuild detected malware, a Chinese exploit-foundry operation (GTG-10007) running agent-swarm reconnaissance across ~50 organizations, ShinyHunters-affiliated 'vibe hacking' (GTG-50014), and AI-supply-chain credential-theft campaigns (GTG-50020, GTG-50021).
  • SOC Prime publishes 'What Is an AI-Powered Cyber Attack?', synthesizing AI-personalized phishing, deepfake BEC, polymorphic malware, AI-accelerated recon, AI-assisted BEC dialogue, and prompt injection into a single detection-engineering trend brief.

Sources cited for AI-Powered Cyber Attacks

More in threat intel

Detection coverage for TL-2026-2668

As of 2026-09-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2668 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats