AI Threats in the Wild: How Malicious Actors Combine AI with Traditional Tools Across Platforms
Over the past two years, our publication of threat reports has provided valuable insights into how malicious actors are exploiting AI technologies. The case studies featured in this report, consistent with earlier findings, reveal that threat actors typically combine AI tools with conventional methods such as websites, social media accounts, and phishing campaigns. Their operations are rarely confined to a single platform or AI model. Instead, they often leverage multiple AI systems at different stages of their workflows—using one model for content generation, another for voice synthesis, and yet another for image manipulation. This multi-tool, multi-platform approach increases the sophistication and reach of their attacks. For example, our analysis of a Chinese influence operation demonstrated how diverse AI models were deployed across various phases of a coordinated disinformation campaign. By sharing these findings, we aim to equip the tech industry and the broader public with the knowledge needed to detect, understand, and mitigate emerging AI-driven threats. The full report is available for review.
