A Huntress threat intelligence retrospective on how adversaries used AI in 2025. Rather than introducing novel attack primitives, threat actors leveraged LLMs like ChatGPT and DeepSeek as productivity tools to rapidly generate PowerShell scripts and automate traditional tradecraft. Four case studies are presented: an AI-generated credential dumper with Cyrillic artifacts, a failed Veeam credential theft attempt at a non-profit, an iterative browser credential harvesting campaign targeting Chase/QuickBooks/Coinbase via Telegram exfiltration, and a malicious AI-assisted Chrome extension functioning as a full RAT. The conclusion is that AI accelerates attack speed and lowers the skill barrier but doesn't change underlying behaviors — meaning security fundamentals (MFA, EDR, network segmentation, script block logging) remain effective defenses. IOCs and MITRE ATT&CK TTPs are included.

16m read timeFrom huntress.com
Post cover image
Table of contents
BackgroundAI tradecraftCase study 1: AI-generated credential dumperCase study 2: Veeam credential theft attempt at a non-profitCase study 3: Three AI scripts for browser cred theft and one that workedCase study 4: AI-assisted malicious Chrome extension developmentConclusion: Defensive guidance and 2026 outlookIndicators of compromise (IOCs)TTPs
1 Impression