The AI-Powered Adversary

How deception and machine speed are rewriting the rules of social engineering

Download Your Ebook
By submitting this form, you accept our Terms of Service & Privacy Policy

AI has given attackers a serious upgrade: faster tools, more convincing lures, and the ability to scale a single campaign across hundreds of targets at once.

This ebook exposes how attackers are leveraging AI to manipulate trust and scale their operations, grounding that shift in real incidents our team investigated firsthand. Inside, you'll see:

  • How a malvertising campaign hid behind a real, trusted AI platform domain to trick 29 organizations in two days
  • How a mediocre attacker with zero coding experience can now build custom malware in minutes using AI-generated tooling
  • How a single phishing-as-a-service platform used AI to run a personalized identity attack against 344 organizations in 16 days, with no two lures alike
  • Why freely available, unrestricted AI models are closing the gap between "anyone can try this" and "anyone can pull this off"

Along the way, we'll point you toward the gaps today's adversaries are counting on you to miss, and what you can do to close them.

Download the ebook to see the full picture of the new flavor of adversary we’re up against, and find out where your own stack might already be exposed.

Cover and interior spreads of the Huntress ebook

Frequently asked questions

An AI-powered adversary is a cybercriminal or threat group that uses artificial intelligence to plan, build, or scale an attack, from writing custom malware and phishing lures to scanning environments for unpatched systems. AI sits on top of familiar tactics like credential theft and impersonation, making them faster, more personalized, and harder to detect than the manual versions security teams are used to.

It's real, and it's already happening. This ebook walks through three named incidents Huntress investigated directly: a malvertising campaign that used a real AI platform domain to distribute malware, a piece of malware an attacker built using AI-generated ("vibe coded") code, and a phishing-as-a-service platform that used AI to personalize attacks against 344 organizations in 16 days.

AI-enabled attacks are dangerous because they've erased the skill and time it used to take to build something harmful. Someone with no coding background can now generate custom, one-off malware in minutes just by describing what they want, and that malware has never existed before, so signature-based detection has nothing to recognize. At the same time, a new class of unrestricted, open-weight AI models has spread fast, models with none of the safety guardrails built into mainstream chatbots, freely available, and capable of profiling a target or finding a way in without ever being pushed to. AI-assisted attacks also systematically expose critical gaps that a single standalone antivirus, EDR, or localized AI capability can't close alone, since attackers move across identity, email, and endpoints in the same campaign. The result is attacks that are faster, more numerous, and harder to catch with the tools most teams already have.

AI-powered adversaries typically exploit the same gaps that have always existed: exposed credentials, excessive permissions, unpatched systems, and convincing phishing. Defense comes down to coordinated visibility across identity, users, endpoints, and email rather than a single new tool.