Three unrelated threat actors, and the roles AI systems now play during offensive operations. Full technical report available.

Gambit Security Threat Intelligence team investigated three unrelated threat actors that show how attackers are incorporating AI into real-world intrusions, and the roles AI systems now play during offensive operations.
Across these cases, the attackers used AI to:
We also document a couple of AI failure modes. Some came from the weaker models the attackers selected. Others were the unintended side effects of the cover story used to convince the model it was running an authorized penetration test.
We don't have to imagine whether an AI operating inside a compromised environment can cause a disruption. In one of these intrusions, it already did, when the model caused an outage on a compromised firewall while trying to modify its configuration.
The same case also demonstrates how close AI-assisted intrusion activity can get to the recovery layer. The model identified the victim's backup product, schedule, storage location, logs, and available recovery points. The model had already mapped much of the recovery path, while elsewhere in the intrusion it was trusted to make production changes and delete staged data after exfiltration. If the attacker's objective had shifted from theft to disruption, much of the discovery work had already been done. But as this incident shows, damage does not necessarily have to be intentional.
The first case examines a suspected 'The Gentlemen' ransomware-as-a-service affiliate that used Claude Code during intrusions into at least six organizations. The second examines Zerofot, a threat actor that built a scanner with Codex and Claude Code to harvest thousands of keys from thousands of hosts across the internet. The third examines RAGE, an AI-generated Python framework that exploits exposed services to deploy cryptocurrency miners, and that showed interest in cloud compromise when the opportunity arose.
In all three cases, operational security failures by the attackers gave us visibility into their infrastructure, tools, and AI conversations.
One finding is worth separating out. In the first case the operator did not know the victim's environment. He asked the model which of the databases mattered most, and it ranked them and pointed at the two the business could least afford to lose. The access was the operator's. The understanding of the business was the model's.
Reporters and researchers who need additional technical detail or indicators can reach our threat intelligence team.
The latest from Gambit: research, insights, and live sessions
