THREAT OPS › Threat News › “Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI
“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI
<ul><li>Actor usage of AI is exploding. By analyzing artifacts left behind, Talos has created a detailed analysis of how we are seeing adversaries leverage the technology to include development, force multiplication, and vulnerability research.</li><li>Based on the evidence Talos gathered, guardrails did not provide much protection, with most actors able to convince the models to comply despite th
Attributed threat actors
- PlayG1040
MITRE ATT&CK techniques
- Artificial IntelligenceT1588.007
- IP AddressesT1590.005
- VulnerabilitiesT1588.006
- Cloud AccountsT1586.003
- Social EngineeringT1684
- Email AccountT1087.003
- DefacementT1491
- Web ServicesT1583.006
- Cloud AccountsT1585.003
- Web ServicesT1584.006
- Browser FingerprintT1036.012
- CredentialsT1589.001
- Cloud AccountsT1078.004
- Reverse ShellAML.T0072
- AI ArtifactsAML.T0112.001
Indicators of compromise
- https://huggingface.co/blog/security-incident-july-2026url
- https://openai.com/index/hugging-face-model-evaluation-security-incident/url
- https://forums.moneysavingexpert.com/discussion/2162641/is-tubely-com-safe-or-is-it-a-scam-siteurl
- https://www.theerrolflynnblog.com/2011/03/26/tubely-site-is-spam-site-and-the-chat-has-viruses-and-trojans/url
- https://www.trendmicro.com/en_us/research/26/e/inside-the-influence-and-fraud-patriot-bait-campaign.html?ct=1783532687994url
- https://oasis-security.io/blog/hephaestus-automated-attack-framework-targeting-government-and-educational-institutions-in-indonesiaurl
- storage.ghost.iodomain
- tubely.comdomain
- web.archive.orgdomain
- ixmax.cndomain