The Use of Artificial Intelligence in Cyberattacks, Part 3

Phases 5– 7 (+1) of the Cyber Kill Chain Model, Challenges, Trends, Outlook

  • Kovács Zoltán
doi: 10.32567/hm.2026.1.2

Absztrakt

The first part of the series of articles provided a basic understanding of the fundamental concepts of artificial intelligence and its relevant subfields, and demonstrated that the Cyber Kill Chain (CKC) model is suitable for achieving the main objective of the article, despite all its limitations, i.e. it can be used to review what AI-supported tools attackers
can already use in the various phases of a cyberattack and how these tools help them. The
second part of the series examined the latter in phases 1–4 of the CKC, while this article, the third part of the series, shows how attackers can use AI in the last three plus one phases of the CKC and how it helps them achieve their goals. In addition, this article highlights the challenges attackers face when using AI and presents the trends that can be observed in cyberattacks. Finally, this article makes recommendations for the direction of further research, namely, to examine the possibilities of using AI-supported defence solutions in the individual phases of CKC and to compare the possibilities of the attacking and defending sides in order to develop effective response capabilities.

Kulcsszavak:

artificial intelligence cybersecurity cyberattack Cyber Kill Chain C2 maintaining a persistent presence exfiltration system disruption

Hogyan kell idézni

Kovács, Z. (2026). The Use of Artificial Intelligence in Cyberattacks, Part 3: Phases 5– 7 (+1) of the Cyber Kill Chain Model, Challenges, Trends, Outlook. Hadmérnök, 21(1), 25–39. https://doi.org/10.32567/hm.2026.1.2

Hivatkozások

ABBADI, Driss – LACHKAR, Abdelkader (2024): Cyber Threats in the Age of Artificial Intelligence: Exploiting Advanced Technologies and Strengthening Cybersecurity. International Journal of Science and Research Archive, 13(1), 2576–2588. Online: https://doi.org/10.30574/ijsra.2024.13.1.1961

ABOZE, John B. (2025): A Comprehensive Guide to Data Exfiltration. Lakera, 21 May 2025. Online: https://www.lakera.ai/blog/data-exfiltration

AL-AZZAWI, Mays – DOAN, Dung – SIPOLA, Tuomo – HAUTAMÄKI, Jari – KOKKONEN, Teri (2025): Red Teaming with Artificial Intelligence-Driven Cyberattacks: A Scoping Review. ArXiv. Online: https://doi.org/10.48550/arXiv.2503.19626

ANDERSON, Hyrum S. – WOODBRIDGE, Jonathan – FILAR, Bobby (2016): DeepDGA: Adversarially-Tuned Domain Generation and Detection. Proceedings of the 2016 ACM Workshop on Artificial Intelligence and Security, 13–21. Online: https://doi.org/10.1145/2996758.2996767

Anthropic (2025): Disrupting the First Reported AI-orchestrated Cyber Espionage Campaign. Online: https://www.anthropic.com/news/disrupting-AI-espionage

BABAEI, Reza – CHENG, Samuel – DUAN, Rui – ZHAO, Shangqing (2025): Generative Artificial Intelligence and the Evolving Challenge of Deepfake Detection: A Systematic Analysis. Journal of Sensor and Actuator Networks, 14(1). Online: https://doi.org/10.3390/jsan14010017

BOUTIN, Jean-Ian (2025): ESET APT Activity Report Q2 2025 – Q3 2025. Online: https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q2-2025-q3-2025/

CHEREPANOV, Anton – STRÝČEK, Peter (2025): First Known AI-powered Ransomware Uncovered by ESET Research. Online: https://www.welivesecurity.com/en/ransomware/first-known-ai-powered-ransomware-uncovered-eset-research/

CRICHTON, Kyle et al. (2024): Securing Critical Infrastructure in the Age of AI. Center for Security and Emerging Technology. Online: https://doi.org/10.51593/20240032

CrowdStrike (2025): CrowdStrike 2025 Global Threat Report. Online: https://www.crowdstrike.com/en-us/resources/infographics/global-threat-report-2025/

Darktrace (2024): Navigating a New Threat Landscape: Breaking Down the AI Kill Chain. Online: https://www.darktrace.com/resources/navigating-a-new-threat-landscape

DE PASQUALE, Giulio – GRISHCHENKO, Ilya – IESARI, Riccardo – PIZZARO, Gabriel – CAVALLARO, Lorenzo – KRUEGEL, Christopher – VIGNA, Giovanni (2024): ChainReactor: Automated Privilege Escalation Chain Discovery via AI Planning. Online: https://www.usenix.org/system/files/usenixsecurity24-de-pasquale.pdf

DILMEGANI, Cem (2026): AI Data Quality in 2026: Challenges & Best Practices. AIMultiple, 27 March 2026. Online: https://research.aimultiple.com/data-quality-ai/

ERDÉSZ, Viktor (2023): A mesterséges intelligencia alkalmazása a katonai nemzetbiztonsági hírszerzésben [The Use of Artificial Intelligence in Military and National Security Intelligence]. Budapest: Katonai Nemzetbiztonsági Szolgálat.

European Union Agency for Law Enforcement Cooperation (2025): IOCTA. Internet Organised Crime Threat Assessment 2025. Luxembourg: Publications Office of the European Union. Online: https://doi.org/10.2813/4926508

FRISONI, Daniele (2020): Potential Impact of Artificial Intelligence to C2 Systems. Joint Air Power Competence Centre. Online: https://www.japcc.org/essays/potential-impact-of-artificial-intelligence-to-c2-systems/

GIL, Luis – WILLIAMS, Beth (2025): AI vs. AI: The Race Between Adversarial and Defensive Intelligence. CrowdStrike, 4 August 2025. Online: https://www.crowdstrike.com/en-us/blog/ai-vs-ai-cybersecurity-arms-race/

HOLDEN, Alex (2023): Contending with Artificially Intelligent Ransomware. ISACA, 1 September 2023. Online: https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2023/contending-with-artificially-intelligent-ransomware

HUMPHRIES, Russ (2026): The Dark Side: How Threat Actors Are Using AI. Connect Wise, 3 March 2026. Online: https://www.connectwise.com/blog/the-dark-side-how-threat-actors-are-using-ai

IProov (2023): Understanding the Different Types of Generative AI Deepfake Attacks. iProov, 30 November 2023. Online: https://www.iproov.com/blog/generative-ai-attack-types-explained

ITszótár.hu (2025): Metamorf és polimorf kártevők: Ezen kártékony szoftverek működésének magyarázata [Metamorphic and Polymorphic Malware: An Explanation of How this Malicious Software Works]. ITszótár.hu, 15 May 2025. Online: https://itszotar.hu/metamorf-es-polimorf-kartevok-ezen-kartekony-szoftverek-mukodesenek-magyarazata/

JAIN, Anu – CHHABRA, Gurpal S. (2014). Anti-Forensics Techniques: An Analytical Review. 2014 Seventh International Conference on Contemporary Computing (IC3), 412–418. Online: https://doi.org/10.1109/IC3.2014.6897209

KEWAT, Rajnish (2025): What Are AI-Generated Rootkits and How Do They Threaten Enterprise Systems? Cyber Security Training Institute, 8 August 2025. Online: https://www.cybersecurityinstitute.in/blog/what-are-ai-generated-rootkits-and-how-do-they-threaten-enterprise-systems

LEE, Junho – KWON, Jihoon – SEO, HyunA – LEE, Myeongyeol – SEO, Hyungyu – JUNG, Jinho – KOO, Hyungjoon (2025): BootKitty: A Stealthy Bootkit-Rootkit Against Modern Operating Systems. Online: https://www.usenix.org/conference/woot25/presentation/lee

Lockheed Martin (s. a.): Cyber Kill Chain. Online: https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html

Mailchimp (s. a.): AI as a Service: The Latest Business Model. Online: https://mailchimp.com/resources/ai-as-a-service/

MATEJIC, Nicole – WILSON, Chris (2024): Crimes of Influence: Generative Artificial Intelligence-led Crime as a Service. The Commonwealth Cyber Journal, 2, 75–95.

Microsoft Security (2025): What Is the Cyber Kill Chain? Online: https://www.microsoft.com/en-us/security/business/security-101/what-is-cyber-kill-chain

MORAES, Marco Túlio (2025): AI Agents: The New Frontier of Cybercrime Business Must Confront. World Economic Forum, 18 June 2025. Online: https://www.weforum.org/stories/2025/06/ai-agent-cybercrime-business/

PAPPACHAN, Princy – ADI, Novi S. – FIRMANSYAH, Gerry – RAHAMAN, Mosiur (2024): Deep Learning-Based Forensics and Anti-Forensics. In ABD EL-LATIF, Ahmed A. – TAWALBEH, Lo’ai – MOHANTY, Manoranjan – GUPTA, Brij B. – PSANNIS, Konstantinos E. (eds.): Digital Forensics and Cyber Crime Investigation. Boca Raton: CRC Press.

POWELL, Evan (2025): Invisible C2 – Thanks to AI-powered Techniques. Deep Tempo, 14 March 2025. Online: https://medium.com/deeptempo/invisible-c2-thanks-to-ai-powered-techniques-462ef2624c8a

PRASAD, Nilantha – DIRO, Abebe – WARREN, Matthew – FERNANDO, Mahesh (2025): A Survey of Cyber Threat Attribution: Challenges, Techniques, and Future Directions. Computers & Security, 157. Online: https://doi.org/10.1016/j.cose.2025.104606

RAGHO, Soni R. – CHAUDHARI, Narendra (2025): Artificial Intelligence in Digital Forensics: A Review of Cyber-Attack Detection Models and Frameworks. Journal of Information Systems Engineering and Management, 10(57s). Online: https://jisem-journal.com/index.php/journal/article/view/12402

RAZ, Md – UDESHI, Meet – CHARAN, Sai P. V. – KRISHNAMURTHY, Prashanth – KHORRAMI, Farshad – KARRI, Ramesh (2025): Ransomware 3.0: Self-Composing and LLM-Orchestrated. Arxiv. Online: https://doi.org/10.48550/arXiv.2508.20444

Sangfor Technologies (2025): AI DDoS: How Artificial Intelligence Is Changing the Face of Cyber Attacks. Sangfor, 9 September 2025. Online: https://www.sangfor.com/blog/cybersecurity/ai-ddos-attacks

SCHIPPERS, Raymond (2025): AI 2030: The Coming Era of Autonomous Cyber Crime. Check Point, 24 October 2025. Online: https://blog.checkpoint.com/executive-insights/ai-2030-the-coming-era-of-autonomous-cyber-crime/

SCHRÖER, Saskia L. – PAJOLA, Luca – CASTAGNARO, Alberto – APRUZZESE, Giovanni – CONTI, Mauro (2025): Exploiting AI for Attacks: On the Interplay between Adversarial AI and Offensive AI. ArXiv. Online: https://arxiv.org/html/2506.12519

TEJEDOR, Jesús (2025): A Dangerous Alliance: The new Dark Web + AI Marketplace. Telefónica, 5 June 2025. Online: https://telefonicatech.com/en/blog/a-dangerous-alliance-how-ai-is-reshaping-the-dark-web-economy

TIMILEHIN, Oladoja (2023): Defending the Digital Horizon: Artificial Intelligence in Cybersecurity Warfare.

TOULAS, Bill (2025): LameHug Malware Uses AI LLM to Craft Windows Data-theft Commands in Real-time. Bleeping Computer, 17 July 2025. Online: https://www.bleepingcomputer.com/news/security/lamehug-malware-uses-ai-llm-to-craft-windows-data-theft-commands-in-real-time/

TRINCKES, Jay (s. a.): AI Data Breach: Understanding their Impact and Protecting Your Data. Thoropass. Online: https://www.thoropass.com/blog/ai-data-breach

UTTER, Jamison (2024): The Machine War Has Begun: Cybercriminals Leveraging AI in DDoS Attacks. A10 Networks, 24 September 2024. Online: https://www.a10networks.com/blog/the-machine-war-has-begun-cybercriminals-leveraging-ai-in-ddos-attacks/

WANG, Yulong – SUN, Tong – LI, Shenghong – YUAN, Xin – NI, Wei – HOSSAIN, Ekram – POOR, Vincent H. (2023): Adversarial Attacks and Defenses in Machine Learning-Empowered Communication Systems and Networks: A Contemporary Survey. IEEE Communications Surveys & Tutorials, 25(4), 2245–2298. Online: https://doi.org/10.1109/COMST.2023.3319492

WANG, Zhi – LIU, Chaoge – CUI, Xiang – YIN, Jie – LIU, Jiaxi – WU, DI – LIU, Qixu (2022): DeepC2: AI-Powered Covert Command and Control on OSNs. In ALCARAZ, Cristina – CHEN, Liqun – LI, Shujun – SAMARATI, Pierangela (eds.): Information and Communications Security. Cham: Springer, 394–414. Online: https://doi.org/10.1007/978-3-031-15777-6_22