Have cyber attacks changed this year? What about last year. Then read the mainstream press and autonomous attacks are always six months away.
Since roughly 2023, the forecast keeps being restated and never date stamped against the earlier predictions. So, is it just a sales slogan for detection and response or is there more to it.
Speed was never the constraint
The common argument runs that a defence operating at human speed against an attack operating at machine speed loses on arithmetic alone.
Attacks have outrun human response speed for years. Breakout times under an hour have been measured since well before any of AI stuff, with the fastest observed cases inside a minute, and ransomware time to encryption has been counted in hours for a decade. If that were decisive, defence would have lost in 2019.
What determines outcomes is dwell time and detection, not raw attacker speed. Attackers may deliberately go slow to stay under thresholds, and request volume is a large part of what got GTG-1002 caught. This was the report published by Anthropic on 13th of November 2025, titled "Disrupting the first reported AI-orchestrated cyber espionage campaign." Speed is a detection surface as much as an advantage.
The payload is the worst place to put a model
Is there an incentive to embed a LLM model in an implant, even if this was possible? Malware needs determinism. A model is not by design. An implant that resolves an API by hash and works every time beats anything that asks a model what to do next and works ninety four times in a hundred. Attackers optimise for reliability under adversarial conditions.
The work a model would do in 1st or 2nd stage implant is also already solved. Enumeration, credential dumping, lateral movement and persistence are handled by deterministic tooling refined over a decade. You wouldn't pay per token for a worse version of a tool you already have.
The 2026 Verizon DBIR report figure says across 793 threat actors actioned for AI policy violations, the average AI assisted technique already had 55 known malware tools performing the same function, only under 2.5% of techniques were classified as rare or novel.
A hosted model is a telemetry feed pointed at the operator
Calling a hosted model from an implant means an API key is sitting in the binary. Not a great idea. It also means outbound traffic to a well known provider address, nice find! We got ourselves a full server side log of every prompt the operator sends.
Those 793 actors in the DBIR dataset were identifiable precisely because they used a hosted model. Every AI integrated implant is a telemetry source pointed at its own author.
Local inference would remove that exposure but the weights are gigabytes and capable inference needs a GPU, which is an implausible implant at this time. Unit 42 states it has observed no locally executed agentic loops at all, only remote calls, and that limit is physical rather than a matter of attacker sophistication.
Unit 42 report found in August, out of 405 AI enabled samples collected from WildFire, VirusTotal Intelligence and published research, only 12 had ever appeared on a customer endpoint. Approximately 97 percent of the collection has no real production presence.
Malware analyst cannot see where the AI actually sits
However, that 97 percent only measures AI in the payload, and that is not where adoption is happening. Think about where an LLM model genuinely helps an intrusion. Writing the loader and development time! Vishing and help desk social engineering, which produces no file at all. Lure text and translation. Target selection. And the almighty Vulnerability Research, which Google Threat Intelligence has now documented and timed in detail.
Every one of those is invisible from a malware defence seat. Not because the detection is weak, but because there is no artifact to detect. This is where we should be looking! So the early takeaway is: expect even more variation in samples, less reused functions, more bespoke 2nd and 3rd stage loaders and more novel phishing campaigns with greater personalisation of message per recipient.
Putting a model inside malware is a bad idea that few serious actors bother with. But that does not mean attackers are not using AI. In November 2025 Anthropic disclosed campaign GTG-1002, attributed to a Chinese state-linked group, in which Claude Code executed 80 to 90 percent of tactical operations against roughly 30 organisations. Reconnaissance, vulnerability discovery, credential harvesting, lateral movement and exfiltration, with human involvement reported at only 4 to 6 decision points per intrusion.
That is the architecture the forecasters may be pointing at, and it is worth taking seriously. It also used NO custom malware. The operation ran open source penetration testing tools under model control, which means it would surface in defensive telemetry as ordinary tooling and stolen credentials.
The caveats are substantial, and several come from the disclosure itself. Anthropic reported that only a small number of the targets were actually compromised, and that Claude frequently overstated findings and fabricated data during the operation. The initial claim of thousands of requests per second was later corrected.
The first documented autonomous campaign was a system that ran fast, hallucinated throughout, needed a human to correct it, and mostly failed.
What to automate
Automating enrichment, triage and detection engineering always helps. Any mechanical work which takes unnecessary time. The next priority follows where the uplift actually is - Patching any internet facing systems matters most because vulnerability research is the one area where models demonstrably help attackers. There is no question about speed and gains in vulnerability discovery.
Behavioural detection and sandboxing keep their priority also, since they caught every AI enabled sample that reached a defended endpoint in the largest study published this year.
Takeaway
The AI is not in the malware because the payload is the worst place to put it. It is in development, social engineering and vulnerability research. It is also not evidence that attackers have ignored these tools for malware.
Source notes
- Unit 42, The State of AI-Enabled Malware August 2026: https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/
- Unit 42, Analyzing the Current State of AI Use in Malware: https://unit42.paloaltonetworks.com/ai-use-in-malware/
- Anthropic, Disrupting the first reported AI-orchestrated cyber espionage campaign: https://www-cdn.anthropic.com/d7dd50dd1185f59be051b307150d877f2b82bd2c.pdf
- BleepingComputer, Anthropic claims of Claude AI-automated cyberattacks met with doubt: https://www.bleepingcomputer.com/news/security/anthropic-claims-of-claude-ai-automated-cyberattacks-met-with-doubt/
- Google Threat Intelligence Group, AI Threat Tracker, May 2026: https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access
- Verizon 2026 Data Breach Investigations Report: https://www.verizon.com/business/resources/reports/dbir/