VYPR
trendPublished Sep 23, 2026· 1 source

AI-Driven Cyberattacks Escalate with Autonomous Fraud and Digital Trust Abuse

Trellix reports on a new phase of AI-driven cyberattacks that exploit digital trust through automation, impacting fraud, espionage, and extortion.

Cyberattacks are increasingly leveraging familiar actions like signing in, approving payments, or using trusted applications. Artificial intelligence is enabling attackers to automate these actions at unprecedented speed, making financial fraud and network intrusions harder to detect before significant damage occurs. These sophisticated threats manifest in various forms, from automating parts of network intrusions to impersonating executives on video calls, hiding within mobile applications, or overlaying fake payment forms onto legitimate checkouts. The common vulnerability exploited is misplaced trust in seemingly normal interactions, underscoring the need for continuous identity and behavior checks beyond simple login credentials.

The report from Trellix highlights a convergence of espionage, mobile malware, fraud, and extortion, rather than focusing on a single new malware family. The consequences are far-reaching, including the theft of sensitive phone data, payment details, large fraudulent financial transfers, and severe reputational damage. According to Trellix, attackers are using AI-driven automation to dynamically adjust their methods, meaning that even convincing visual or auditory cues may no longer be sufficient to verify the authenticity of a request.

In the China-linked GTG-1002 espionage campaign, AI agents reportedly handled an astonishing 80% to 90% of operational tasks. Human operators were involved in only a few critical decisions, such as target selection and data exfiltration approval, while the AI software managed the bulk of the intrusion process. This level of automation allows intrusions to progress at a significantly accelerated pace, as demonstrated by previous reports on AI-orchestrated espionage campaigns that utilized automated reconnaissance, credential harvesting, and exploit development.

On mobile devices, the PromptSpy malware exemplifies a more focused yet practical application of AI. This Android malware analyzes the device's screen content and uses this information to interact with the interface. Unlike malware relying on fixed screen coordinates, PromptSpy can adapt its actions to different UI layouts. It leverages accessibility permissions to maintain its presence and can place invisible layers over legitimate controls, preventing users from uninstalling it or stopping its malicious activities. Trellix advises users to restrict accessibility permissions and utilize Safe Mode for removal, while organizations should monitor for unusual device behavior.

Deepfake technology is also being weaponized to facilitate fraud. Trellix details a case where fake video and audio of company executives were used to trick a finance employee into authorizing a $25 million transfer. These scams exploit the pressure to respond quickly to requests from senior leadership. Previous instances of deepfake business fraud have highlighted the danger of relying solely on visual or auditory cues, emphasizing the need for robust verification processes.

Online checkout fraud is another area where AI is being employed. In a technique known as double-tap skimming, attackers present a fake payment form that first captures card details. This fake form then appears to fail, redirecting the user to the legitimate payment page. The transaction may still succeed, making the initial data theft difficult to detect. Trellix recommends simulated checkout tests and regular audits to identify and prevent such fraudulent overlays before they impact customers.

Furthermore, the LunaLock ransomware reportedly uses AI to identify sensitive data within compromised systems and to craft more effective extortion demands. Trellix noted that this group compromised over 95,000 accounts associated with an artists' marketplace, illustrating the persistent risks posed by exposed files even after systems are supposedly restored. For high-value transactions, Trellix recommends verifying requests through a separate, pre-established communication channel, such as a callback or a prearranged code, alongside phishing-resistant authentication and encryption of sensitive data.

The overarching lesson from these evolving threats is the critical need to move beyond traditional trust models. Security strategies must incorporate continuous verification of actions and behaviors, rather than relying solely on the apparent identity of the requester. As AI capabilities advance, the line between legitimate and malicious activity will continue to blur, demanding more sophisticated and adaptive defense mechanisms.

Synthesized by Vypr AI