Attackers are no longer just experimenting with AI — they are building entire attack workflows around it. Three patterns are highlighted: fake AI tool downloads via SEO poisoning and malvertising (e.g., a spoofed Claude Code installer delivering credential-stealing malware), spoofed AI-generated answers that trick users into running malicious terminal commands (AMOS stealer campaign), and productized phishing infrastructure like EvilTokens that uses AI to generate tailored lures, bypass email filters, and steal session tokens at machine speed. The core insight is that AI is not the weapon itself — attackers are exploiting the trust users place in AI-adjacent workflows, making attacks blend seamlessly into normal activity. Defenders are urged to build resilient teams capable of catching what automated tools miss.

7m read timeFrom huntress.com
Post cover image
Table of contents
Old tricks, new targets: Fake AI tools in searchWhen “helpful” AI answers become the attackPhishing as a product: Infrastructure at machine speedThe throughlineJoin us for a special session with Microsoft
1 Impression