Cyber SecurityAI & Technology

AI is turbocharging the cyber-attacks that already work, Huntress data shows

Huntress's inaugural Tragic Quadrant finds AI is accelerating proven attacker tactics, from phishing kits to fake verification prompts, while trusted AI platforms themselves are becoming a delivery channel.

Much of the conversation about AI and cybercrime has focused on dramatic new threats. New data from Huntress suggests a more practical reality: attackers are mostly using AI to make tactics that already work faster, cheaper and harder to spot.  

The company has published the Huntress Tragic Quadrant, which ranks attacker tactics by how often Huntress sees them and how close they bring an organisation to serious damage. Drawing on telemetry from more than 5 million endpoints and 15 million identities across nearly 300,000 organisations, the quadrant marks every tactic where Huntress has observed AI acceleration. More than half of the tactics on the chart carry that marker.  

AI-built lures for familiar attacks 

The most common threat in the report, abuse of remote monitoring and management (RMM) tools, featured in 45% of endpoint-related incidents Huntress investigated in Q1 2026. Huntress says attackers are already using AI to generate convincing fake document-share and service-agreement lures that trick users into installing these tools for them. 

Identity attacks show the same pattern. The FBI has flagged AI-enabled phishing kits such as Kali365, which help attackers run adversary-in-the-middle (AiTM) account takeovers that bypass multi-factor authentication at scale. AiTM attacks made up 18.9% of identity-based threats Huntress tracked in 2025. 

The clearest example is device code phishing, which rose 1,380% year over year. In early 2026, a single phishing-as-a-service kit called EvilTokens hit 344 organisations across five countries in 16 days. Attackers used AI to “vibe code” the platform itself and used AI tools to analyse compromised inboxes and suggest follow-up targets. 

AI is also speeding up how quickly ClickFix attacks, fake CAPTCHA and “verification failed” prompts that trick users into pasting malicious commands, can be customised. ClickFix made up 2.2% of suspicious EDR detection signals, but nearly 99% of those were high severity. 

When the AI platform is the lure 

The report also identifies a newer trend: abuse of AI platforms themselves. Over the past nine months, attackers have weaponised shareable AI content, public mini-apps and sponsored search placement across Claude, ChatGPT and Grok. In one campaign Huntress tracked, dubbed FakeAgent, a malicious artifact hosted on the real claude.ai domain sent people searching for Claude Desktop to SectopRAT malware, hitting 29 organisations in two days. 

“AI security isn’t limited to the models themselves. Attackers use legitimate AI platforms, shared conversations, public artifacts, and search results to make malware and malicious instructions look trustworthy.” 

— Lindsey O’Donnell-Welch, Principal Technical Community Engagement Writer, Huntress 

Despite this, Huntress places AI platform abuse in its “Overhyped, for now” corner, alongside deepfakes and voice cloning. Both are real and growing but are not yet causing widespread damage at the rate of more established tactics. Huntress advises downloading AI tools only from official vendor sites or app stores and treating any install prompt that appears inside an AI platform as a moment to stop and verify. 

The company’s wider message is that defenders should not let AI hype pull attention from the fundamentals. The biggest risks in the report, RMM abuse, mailbox manipulation and account takeover, rely on trusted tools and stolen sessions, and AI is simply helping attackers reach them faster. 

Related Articles

Back to top button