The Use of Artificial Intelligence in Cyberattacks, Part 3
Phases 5– 7 (+1) of the Cyber Kill Chain Model, Challenges, Trends, Outlook
Copyright (c) 2026 Kovács Zoltán

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
Absztrakt
The first part of the series of articles provided a basic understanding of the fundamental concepts of artificial intelligence and its relevant subfields, and demonstrated that the Cyber Kill Chain (CKC) model is suitable for achieving the main objective of the article, despite all its limitations, i.e. it can be used to review what AI-supported tools attackers
can already use in the various phases of a cyberattack and how these tools help them. The
second part of the series examined the latter in phases 1–4 of the CKC, while this article, the third part of the series, shows how attackers can use AI in the last three plus one phases of the CKC and how it helps them achieve their goals. In addition, this article highlights the challenges attackers face when using AI and presents the trends that can be observed in cyberattacks. Finally, this article makes recommendations for the direction of further research, namely, to examine the possibilities of using AI-supported defence solutions in the individual phases of CKC and to compare the possibilities of the attacking and defending sides in order to develop effective response capabilities.
Kulcsszavak:
Hogyan kell idézni
Hivatkozások
ABBADI, Driss – LACHKAR, Abdelkader (2024): Cyber Threats in the Age of Artificial Intelligence: Exploiting Advanced Technologies and Strengthening Cybersecurity. International Journal of Science and Research Archive, 13(1), 2576–2588. Online: https://doi.org/10.30574/ijsra.2024.13.1.1961
ABOZE, John B. (2025): A Comprehensive Guide to Data Exfiltration. Lakera, 21 May 2025. Online: https://www.lakera.ai/blog/data-exfiltration
AL-AZZAWI, Mays – DOAN, Dung – SIPOLA, Tuomo – HAUTAMÄKI, Jari – KOKKONEN, Teri (2025): Red Teaming with Artificial Intelligence-Driven Cyberattacks: A Scoping Review. ArXiv. Online: https://doi.org/10.48550/arXiv.2503.19626
ANDERSON, Hyrum S. – WOODBRIDGE, Jonathan – FILAR, Bobby (2016): DeepDGA: Adversarially-Tuned Domain Generation and Detection. Proceedings of the 2016 ACM Workshop on Artificial Intelligence and Security, 13–21. Online: https://doi.org/10.1145/2996758.2996767
Anthropic (2025): Disrupting the First Reported AI-orchestrated Cyber Espionage Campaign. Online: https://www.anthropic.com/news/disrupting-AI-espionage
BABAEI, Reza – CHENG, Samuel – DUAN, Rui – ZHAO, Shangqing (2025): Generative Artificial Intelligence and the Evolving Challenge of Deepfake Detection: A Systematic Analysis. Journal of Sensor and Actuator Networks, 14(1). Online: https://doi.org/10.3390/jsan14010017
BOUTIN, Jean-Ian (2025): ESET APT Activity Report Q2 2025 – Q3 2025. Online: https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q2-2025-q3-2025/
CHEREPANOV, Anton – STRÝČEK, Peter (2025): First Known AI-powered Ransomware Uncovered by ESET Research. Online: https://www.welivesecurity.com/en/ransomware/first-known-ai-powered-ransomware-uncovered-eset-research/
CRICHTON, Kyle et al. (2024): Securing Critical Infrastructure in the Age of AI. Center for Security and Emerging Technology. Online: https://doi.org/10.51593/20240032
CrowdStrike (2025): CrowdStrike 2025 Global Threat Report. Online: https://www.crowdstrike.com/en-us/resources/infographics/global-threat-report-2025/
Darktrace (2024): Navigating a New Threat Landscape: Breaking Down the AI Kill Chain. Online: https://www.darktrace.com/resources/navigating-a-new-threat-landscape
DE PASQUALE, Giulio – GRISHCHENKO, Ilya – IESARI, Riccardo – PIZZARO, Gabriel – CAVALLARO, Lorenzo – KRUEGEL, Christopher – VIGNA, Giovanni (2024): ChainReactor: Automated Privilege Escalation Chain Discovery via AI Planning. Online: https://www.usenix.org/system/files/usenixsecurity24-de-pasquale.pdf
DILMEGANI, Cem (2026): AI Data Quality in 2026: Challenges & Best Practices. AIMultiple, 27 March 2026. Online: https://research.aimultiple.com/data-quality-ai/
ERDÉSZ, Viktor (2023): A mesterséges intelligencia alkalmazása a katonai nemzetbiztonsági hírszerzésben [The Use of Artificial Intelligence in Military and National Security Intelligence]. Budapest: Katonai Nemzetbiztonsági Szolgálat.
European Union Agency for Law Enforcement Cooperation (2025): IOCTA. Internet Organised Crime Threat Assessment 2025. Luxembourg: Publications Office of the European Union. Online: https://doi.org/10.2813/4926508
FRISONI, Daniele (2020): Potential Impact of Artificial Intelligence to C2 Systems. Joint Air Power Competence Centre. Online: https://www.japcc.org/essays/potential-impact-of-artificial-intelligence-to-c2-systems/
GIL, Luis – WILLIAMS, Beth (2025): AI vs. AI: The Race Between Adversarial and Defensive Intelligence. CrowdStrike, 4 August 2025. Online: https://www.crowdstrike.com/en-us/blog/ai-vs-ai-cybersecurity-arms-race/
HOLDEN, Alex (2023): Contending with Artificially Intelligent Ransomware. ISACA, 1 September 2023. Online: https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2023/contending-with-artificially-intelligent-ransomware
HUMPHRIES, Russ (2026): The Dark Side: How Threat Actors Are Using AI. Connect Wise, 3 March 2026. Online: https://www.connectwise.com/blog/the-dark-side-how-threat-actors-are-using-ai
IProov (2023): Understanding the Different Types of Generative AI Deepfake Attacks. iProov, 30 November 2023. Online: https://www.iproov.com/blog/generative-ai-attack-types-explained
ITszótár.hu (2025): Metamorf és polimorf kártevők: Ezen kártékony szoftverek működésének magyarázata [Metamorphic and Polymorphic Malware: An Explanation of How this Malicious Software Works]. ITszótár.hu, 15 May 2025. Online: https://itszotar.hu/metamorf-es-polimorf-kartevok-ezen-kartekony-szoftverek-mukodesenek-magyarazata/
JAIN, Anu – CHHABRA, Gurpal S. (2014). Anti-Forensics Techniques: An Analytical Review. 2014 Seventh International Conference on Contemporary Computing (IC3), 412–418. Online: https://doi.org/10.1109/IC3.2014.6897209
KEWAT, Rajnish (2025): What Are AI-Generated Rootkits and How Do They Threaten Enterprise Systems? Cyber Security Training Institute, 8 August 2025. Online: https://www.cybersecurityinstitute.in/blog/what-are-ai-generated-rootkits-and-how-do-they-threaten-enterprise-systems
LEE, Junho – KWON, Jihoon – SEO, HyunA – LEE, Myeongyeol – SEO, Hyungyu – JUNG, Jinho – KOO, Hyungjoon (2025): BootKitty: A Stealthy Bootkit-Rootkit Against Modern Operating Systems. Online: https://www.usenix.org/conference/woot25/presentation/lee
Lockheed Martin (s. a.): Cyber Kill Chain. Online: https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html
Mailchimp (s. a.): AI as a Service: The Latest Business Model. Online: https://mailchimp.com/resources/ai-as-a-service/
MATEJIC, Nicole – WILSON, Chris (2024): Crimes of Influence: Generative Artificial Intelligence-led Crime as a Service. The Commonwealth Cyber Journal, 2, 75–95.
Microsoft Security (2025): What Is the Cyber Kill Chain? Online: https://www.microsoft.com/en-us/security/business/security-101/what-is-cyber-kill-chain
MORAES, Marco Túlio (2025): AI Agents: The New Frontier of Cybercrime Business Must Confront. World Economic Forum, 18 June 2025. Online: https://www.weforum.org/stories/2025/06/ai-agent-cybercrime-business/
PAPPACHAN, Princy – ADI, Novi S. – FIRMANSYAH, Gerry – RAHAMAN, Mosiur (2024): Deep Learning-Based Forensics and Anti-Forensics. In ABD EL-LATIF, Ahmed A. – TAWALBEH, Lo’ai – MOHANTY, Manoranjan – GUPTA, Brij B. – PSANNIS, Konstantinos E. (eds.): Digital Forensics and Cyber Crime Investigation. Boca Raton: CRC Press.
POWELL, Evan (2025): Invisible C2 – Thanks to AI-powered Techniques. Deep Tempo, 14 March 2025. Online: https://medium.com/deeptempo/invisible-c2-thanks-to-ai-powered-techniques-462ef2624c8a
PRASAD, Nilantha – DIRO, Abebe – WARREN, Matthew – FERNANDO, Mahesh (2025): A Survey of Cyber Threat Attribution: Challenges, Techniques, and Future Directions. Computers & Security, 157. Online: https://doi.org/10.1016/j.cose.2025.104606
RAGHO, Soni R. – CHAUDHARI, Narendra (2025): Artificial Intelligence in Digital Forensics: A Review of Cyber-Attack Detection Models and Frameworks. Journal of Information Systems Engineering and Management, 10(57s). Online: https://jisem-journal.com/index.php/journal/article/view/12402
RAZ, Md – UDESHI, Meet – CHARAN, Sai P. V. – KRISHNAMURTHY, Prashanth – KHORRAMI, Farshad – KARRI, Ramesh (2025): Ransomware 3.0: Self-Composing and LLM-Orchestrated. Arxiv. Online: https://doi.org/10.48550/arXiv.2508.20444
Sangfor Technologies (2025): AI DDoS: How Artificial Intelligence Is Changing the Face of Cyber Attacks. Sangfor, 9 September 2025. Online: https://www.sangfor.com/blog/cybersecurity/ai-ddos-attacks
SCHIPPERS, Raymond (2025): AI 2030: The Coming Era of Autonomous Cyber Crime. Check Point, 24 October 2025. Online: https://blog.checkpoint.com/executive-insights/ai-2030-the-coming-era-of-autonomous-cyber-crime/
SCHRÖER, Saskia L. – PAJOLA, Luca – CASTAGNARO, Alberto – APRUZZESE, Giovanni – CONTI, Mauro (2025): Exploiting AI for Attacks: On the Interplay between Adversarial AI and Offensive AI. ArXiv. Online: https://arxiv.org/html/2506.12519
TEJEDOR, Jesús (2025): A Dangerous Alliance: The new Dark Web + AI Marketplace. Telefónica, 5 June 2025. Online: https://telefonicatech.com/en/blog/a-dangerous-alliance-how-ai-is-reshaping-the-dark-web-economy
TIMILEHIN, Oladoja (2023): Defending the Digital Horizon: Artificial Intelligence in Cybersecurity Warfare.
TOULAS, Bill (2025): LameHug Malware Uses AI LLM to Craft Windows Data-theft Commands in Real-time. Bleeping Computer, 17 July 2025. Online: https://www.bleepingcomputer.com/news/security/lamehug-malware-uses-ai-llm-to-craft-windows-data-theft-commands-in-real-time/
TRINCKES, Jay (s. a.): AI Data Breach: Understanding their Impact and Protecting Your Data. Thoropass. Online: https://www.thoropass.com/blog/ai-data-breach
UTTER, Jamison (2024): The Machine War Has Begun: Cybercriminals Leveraging AI in DDoS Attacks. A10 Networks, 24 September 2024. Online: https://www.a10networks.com/blog/the-machine-war-has-begun-cybercriminals-leveraging-ai-in-ddos-attacks/
WANG, Yulong – SUN, Tong – LI, Shenghong – YUAN, Xin – NI, Wei – HOSSAIN, Ekram – POOR, Vincent H. (2023): Adversarial Attacks and Defenses in Machine Learning-Empowered Communication Systems and Networks: A Contemporary Survey. IEEE Communications Surveys & Tutorials, 25(4), 2245–2298. Online: https://doi.org/10.1109/COMST.2023.3319492
WANG, Zhi – LIU, Chaoge – CUI, Xiang – YIN, Jie – LIU, Jiaxi – WU, DI – LIU, Qixu (2022): DeepC2: AI-Powered Covert Command and Control on OSNs. In ALCARAZ, Cristina – CHEN, Liqun – LI, Shujun – SAMARATI, Pierangela (eds.): Information and Communications Security. Cham: Springer, 394–414. Online: https://doi.org/10.1007/978-3-031-15777-6_22