VYPR
researchPublished Aug 4, 2026· 1 source

Sophisticated Attackers Leverage AI for Productivity, While Novices Struggle

Highly skilled threat actors are effectively using AI tools to boost their cyberattack capabilities, but less-skilled attackers find it difficult to translate AI-generated ideas into practical exploits.

Sophisticated cyberattackers are increasingly leveraging Artificial Intelligence (AI) tools, particularly large language models (LLMs), to significantly enhance their productivity and operational effectiveness. Research from Cisco Talos, analyzing recovered prompt logs, indicates that advanced users are pushing the boundaries of what's possible, generating complex and potent outputs for malicious purposes. These findings suggest that AI is acting as a powerful force multiplier for those already possessing deep technical expertise.

However, the same research highlights a stark contrast for less-skilled attackers. While novice users can coax LLMs into generating malicious ideas, they struggle to translate these concepts into functional attacks. This disparity stems from a lack of fundamental expertise, particularly in technical language and coding, which prevents them from effectively guiding the AI or implementing its suggestions. A study from Harvard Business School corroborates this, noting that while LLMs excel at idea generation, they hit a "wall" when users lack sufficient execution skills.

Examples of this struggle are evident in the logs. One distributed-denial-of-service (DDoS) operator, despite controlling a botnet of approximately 2,000 infected devices, failed to develop effective command-and-control software due to an inability to articulate precise technical requirements to the LLM. Similarly, an individual attempting to create a penetration testing tool for e-commerce and healthcare sites in Brazil, using an LLM and the outdated RockYou password list, achieved no successful logins, indicating a significant gap between intent and execution.

In contrast, advanced actors are demonstrating remarkable proficiency. Cisco Talos researchers observed users employing AI for legitimate-sounding vulnerability research, even specifying in-scope and out-of-scope parameters for private bug bounty programs. More concerning are the sophisticated applications, such as the creation of cloned cryptocurrency wallet and Telegram Mini App interfaces designed to trick users into divulging credentials. These actors are not only generating novel attack vectors but also integrating AI into complex attack pipelines.

One particularly advanced use case involved a group of threat actors who reportedly used LLMs to repeatedly compromise multiple organizations, primarily in Southeast Asia. They leveraged Hephaestus, an automated attack framework powered by Claude, and employed multiple AI models and playbooks to obfuscate their activities, compartmentalizing attack stages. This approach minimized the risk of any single AI agent revealing the full scope of the operation, with researchers noting a distinct lack of model pushback or guardrail activation.

Interestingly, the research suggests that AI guardrails, designed to prevent malicious use, are often easily bypassed. Simple social engineering tactics, such as claiming ownership of systems, stating a need for bug fixing, or asserting participation in capture-the-flag competitions, appear sufficient to circumvent these safety measures in many instances. This ease of bypass further empowers skilled attackers who can manipulate AI models to their advantage.

The implications of AI in cybersecurity are thus twofold: it is an accelerant for sophisticated, well-resourced adversaries, enabling them to develop and deploy more effective attacks with greater efficiency. For less experienced actors, however, AI remains a tool with a steep learning curve, offering idea generation but not the expertise required for successful exploitation. The trend indicates a widening gap between the capabilities of elite threat actors and those with more limited skills, driven by the differential adoption and mastery of AI technologies.

Synthesized by Vypr AI