The Role of AI in Cyber Threats

AI

February 19, 2025

An MS-ISAC White Paper – The Evolving Role of Generative Artificial Intelligence in the Cyber Threat Landscape – TLP CLEAR

 

The adoption of Generative Artificial Intelligence (GenAI) for malicious cyber activity is in a transitional period. Cyber threat actors (CTAs) are exploring incorporating GenAI into their campaigns while relying on more traditional tactics, techniques, and procedures (TTPs). The use of these platforms is growing, but widespread adoption is limited by technical barriers, defenses, and the proven effectiveness and reliability of more conventional attack methods.

  • Obstacles in attributing GenAI attacks make assessing the scope of their use difficult.
  • CTAs are leveraging GenAI to improve existing campaigns, though the use appears limited to specific areas, including phishing and malign influence campaigns.
  • CTAs continue to rely on traditional TTPs and known tools rather than switching to GenAI-created or enhanced TTPs.
  • Despite a lower barrier for entry, limitations on what GenAI platforms can produce limit their utility for CTAs.