← Back to blog Threat Intelligence

How Cybercriminals Are Weaponizing AI in 2026

For most of the last decade, the limiting factor in cybercrime was effort. Writing convincing phishing emails, researching targets, and developing malware all took time, skill, and language fluency. Generative AI has quietly removed those constraints. In 2026, a lone attacker with a laptop can operate with the speed and polish of a well-funded crew.

This isn't science fiction — it's showing up in the incidents our team investigates every week. Here's how the threat landscape has shifted.

Phishing at machine speed

The classic advice — "watch for spelling mistakes and awkward grammar" — is now dangerously outdated. Large language models produce flawless, fluent messages in any language, tuned to the tone of a real colleague or vendor. Worse, they do it at scale.

Attackers feed a model scraped data from LinkedIn, breach dumps, and company websites, then generate thousands of personalized lures — each referencing a real project, manager, or invoice. The result is spear-phishing quality delivered with spam-level volume.

Malware that writes itself

Underground "dark LLMs" — jailbroken or purpose-built models marketed under names like WormGPT and FraudGPT — strip away the safety guardrails of mainstream tools. They help criminals:

  • Generate polymorphic malware that rewrites its own code to evade signature-based antivirus.
  • Translate working exploits between languages and platforms in minutes.
  • Debug and obfuscate payloads without any deep programming knowledge.

The skill barrier that once kept low-level criminals out of serious intrusions is collapsing.

+1,265% Reported rise in malicious phishing emails between Q4 2022 and Q3 2023 — coinciding with the public release of generative AI tools. Source: SlashNext, The State of Phishing 2023.

Automated reconnaissance and social engineering

AI agents can now perform the tedious groundwork of an attack autonomously: mapping a company's org chart, identifying who approves payments, and drafting a pretext tailored to each person. Combined with voice cloning and deepfake video, the same intelligence powers convincing impersonation — a topic we cover in depth in our piece on deepfake fraud.

What this means for your business

The uncomfortable truth is that awareness training built around "spotting the obvious tell" no longer works, because the tells are gone. Defending against AI-accelerated attacks requires layered, proactive controls — not a single trained eye.

Key takeaways

  • Assume phishing is now grammatically perfect and personally relevant — train staff on process and verification, not spelling.
  • Move to phishing-resistant MFA (passkeys / hardware keys) so a stolen password isn't enough.
  • Layer behavioural detection on top of signature antivirus to catch polymorphic malware.
  • Run realistic, AI-grade phishing simulations so your team practises against today's threats.

Sources

  1. SlashNext — The State of Phishing 2023 (1,265% increase in malicious phishing emails, Q4 2022–Q3 2023).
  2. SlashNext research — first reporting on the WormGPT and FraudGPT "dark LLM" tools (2023).

Is your team ready for AI-driven attacks?

ProVaSec runs proactive assessments and realistic phishing simulations built around the modern threat landscape.

Get a free onboarding audit →