AI-powered cyberattacks: how hackers are using ChatGPT to strike faster
Reading time: 5 minutes

AI-Powered Cyberattacks: How Hackers Are Using ChatGPT to Strike Faster
Artificial intelligence was supposed to be one of cybersecurity's greatest allies. It still is, but malicious actors have also adopted it. In 2025, AI-assisted cyberattacks moved from a theoretical concern to a proven reality, with major incidents linked to the use of Large Language Models (LLMs) for offensive operations.
The New Attack Toolkit
In early 2025, security researchers from OpenAI and Microsoft Threat Intelligence jointly confirmed that state-sponsored actors from Russia, China, North Korea, and Iran had used GPT-class models to accelerate several stages of their operations, including:
Spear-phishing content generation — writing hyper-personalized emails that bypass traditional anti-spam filters
Malicious code improvement — optimizing existing malicious code to evade signature-based detection
Vulnerability research — automating the analysis of open-source CVE databases to identify exploitable targets
Social engineering scripts — generating credible scenarios for vishing (voice phishing) attacks
Real-World Cases
Forest Blizzard (Russia)
This group, affiliated with Russian military intelligence (GRU), used AI tools to conduct research on satellite and radar technologies, likely in support of operations targeting NATO's military logistics infrastructure.
Crimson Sandstorm (Iran)
Iran-linked actors used Large Language Models (LLMs) to create phishing email templates targeting defense sector companies and research universities in Europe and the United States.
Emerald Sleet (North Korea)
North Korean operators leveraged AI to create convincing fake LinkedIn profiles and recruitment materials, used to conduct social engineering attacks targeting aerospace and defense companies.
What Defenders Are Doing
The security community's response has been equally swift. Companies such as CrowdStrike, Palo Alto Networks, and SentinelOne have launched natively AI-powered detection modules, specifically designed to identify AI-generated phishing content and malware variants crafted with the help of AI.
The UK's National Cyber Security Centre (NCSC) also published a major report in January 2025, warning that AI will almost certainly increase the volume and impact of cyberattacks over the next two years, particularly in the areas of ransomware and espionage.
What This Means for Your Organization
Update your phishing training: Employees must know that AI-generated emails are almost indistinguishable from legitimate communications.
Deploy behavioral email analysis tools that go beyond simple signature matching.
Audit your attack surface: AI-assisted attackers move faster, leaving less time to apply patches.
Invest in AI-native security platforms capable of matching the speed of AI-driven threats.
The AI arms race in cybersecurity is no longer a matter of the future: it is a current reality. Organizations that fail to adapt their defenses risk being left behind by adversaries who have already made the leap.
Don't wait for a security breach.
The average cost of a data breach is $4.88 million.
