Trending Topics

Cybercriminals using GenAI to make their lives easier but aren’t targeting AI platforms – for now
Like everyone else working in the tech industry, cybercriminals are testing out how to use generative artificial intelligence (GenAI) tools to make their jobs easier.
According to IBM’s X-Force 2025 Threat Intelligence Index report, cybercriminals are increasingly using generative AI to automate their work. Researchers found that threat actors are now using GenAI to write their code, create phishing emails and build malicious websites.
However, while AI uptake continues to mushroom across the world, cybercriminals have yet to exploit its growing presence as an attack vector.
The reports notes that the sheer diversity of the AI landscape is acting as protective factor against such attacks. However, it predicts that when two or three AI technologies become dominant in the market, threat actors will step up their efforts to build attack toolkits targeting those technologies.
Likewise if one platform represents over half the market.
A handful of AI-related attacks have been seen in the wild, including a campaign targeting the Ray open-source AI framework, and could be a sign of things to come.
“We expect vulnerabilities in AI frameworks to become more common over time,” the report stated. “As adoption grows, attacks on AI infrastructure and tools will gain traction. Organizations should prepare now for threats by securing the AI pipeline from the start, including underlying training data, models, and the broader infrastructure surrounding the models.”
Away from GenAI, cybercriminals still love old avenues of attack
While cybercriminals are turning their attention to buzzworthy new technologies, they’ve not lost interest in older attack vectors.
Ransomware activity on the dark web was up 25% last year compared to 2023, the report said, with criminals now adopting “a cross-platform approach to ransomware, supporting both Windows and Linux” as standard.
At the same time, ransomware now represents a decreasing percentage of successful malware attacks that IBM X-Force responded to last year. In 2024, ransomware was 28% of malware incident responses, a drop for three years in a row.
Backdoors accounted for 20%, followed by webshells at 13% and RATs (remote access trojans) at 10%.
Sharper phishing tactics
Phishing too remains a staple of cybercriminals’ arsenals. However, tactics are evolving, with the emails now increasingly used to deliver infostealer malware that can be exploited to gather credentials and compromise accounts.
IBM said that the number of infostealers delivered by phishing emails was up 84% in 2024 compared to 2023. “Because adversaries hide and deliver malware payloads more cleverly, it can take longer to detect than ransomware and data breaches,” the report added.
Thanks to the rise in infostealers being sent out through phishing emails, identity-based attacks now make up a greater proportion of all successful breaches. In 2024, identity-based attacks were 30% of all intrusions, an increase compared to both 2023 and 2022.
Manufacturing remained cybercriminals’ top target in 2024, according to the report, with 26% of attacks targeting the industry. Finance and insurance was a close second, at 23%, followed by business services at 18%.
