Hackers Turn Claude, Qwen and DeepSeek Into AI Agents for Real-World Cyberattacks

By Published On: September 5, 2026

The landscape of cyber warfare has taken a disturbing turn, as hackers are now leveraging commercial AI models not just for analysis, but as active participants in real-world cyberattack operations. This shift marks a critical escalation, transforming AI from a mere tool into an agent capable of directing and executing components of sophisticated attacks. Organizations must recognize the profound implications of this development for their security posture.

AI-Driven Cyberattacks: A New Paradigm

Recent campaigns have revealed that threat actors are integrating leading commercial AI models, specifically Claude, Qwen, and DeepSeek, into their attack frameworks. This isn’t about AI generating phishing emails; it’s about AI directing the overall attack flow, automating reconnaissance, exploit selection, and even post-exploitation activities. This integration enables a more adaptive, efficient, and potentially stealthier adversary.

The operational framework observed combines AI-directed tasking with established cyberattack methodologies. This includes exploiting vulnerable public-facing servers, utilizing stolen credentials for unauthorized access, deploying webshells for persistent control, and introducing custom remote-access malware. This hybrid approach significantly amplifies the scale and sophistication of attacks.

Notable Targets and Campaign Reach

The impact of these AI-augmented operations is already evident across various high-value targets. Investigations have traced successful intrusions to sensitive institutions, including:

  • Taiwan’s Kuomintang Party History Archives: A critical repository of historical and political data, demonstrating an interest in geopolitical intelligence.
  • Indonesia’s Ministry of Foreign Affairs: Indicating a focus on diplomatic and international relations intelligence gathering.
  • Government and Education Networks in Mainland China: Highlighting an internal or state-sponsored interest in sensitive governmental data and research.

These incidents underscore the global reach and diverse motivations behind threat actors employing these advanced AI-driven tactics.

Mechanisms of AI Integration in Attacks

The primary function of these AI models within the attack chain appears to be task automation and decision support. Instead of a human manually sifting through reconnaissance data or selecting exploits, the AI agents are fed information and instructed to identify optimal paths for exploitation or lateral movement. This can involve:

  • Vulnerability Identification: Analyzing target systems for known weaknesses, potentially including vulnerabilities such as CVE-2023-22515 (critical Confluence vulnerability) or CVE-2023-46805 (Ivanti Connect Secure authentication bypass).
  • Payload Generation: Customizing malware or webshells based on target environment specifics.
  • Automated Lateral Movement: Identifying pathways within compromised networks and executing steps for further infiltration.
  • Stealth and Evasion: Potentially optimizing attack patterns to bypass traditional security controls, though this area requires further research.

The use of custom remote-access malware further suggests a bespoke approach to maintaining persistence and control over compromised systems, making detection and eradication significantly more challenging.

Remediation Actions and Defensive Strategies

Defending against AI-augmented cyberattacks requires a multi-layered and adaptive security strategy. Organizations must strengthen their foundational security practices and integrate advanced detection capabilities.

  • Patch Management and Vulnerability Prioritization: Implement a robust patch management program. Prioritize patching critical vulnerabilities, especially those impacting public-facing services (e.g., as detailed in CVE-2024-21887 and CVE-2024-21888 for Ivanti). Regularly scan for and remediate misconfigurations.
  • Strong Authentication and Credential Management: Enforce multi-factor authentication (MFA) across all services, especially for administrative accounts. Implement strict password policies and regularly audit for compromised credentials.
  • Network Segmentation: Segment networks to limit lateral movement. Isolate critical assets and implement zero-trust principles, ensuring that even if one segment is breached, the impact is contained.
  • Endpoint Detection and Response (EDR) / Extended Detection and Response (XDR): Deploy advanced EDR/XDR solutions capable of detecting anomalous behavior, custom malware, and webshell activity. Ensure these tools are regularly updated and their alerts are actively monitored.
  • Intrusion Detection/Prevention Systems (IDS/IPS): Maintain up-to-date IDS/IPS signatures and monitor for suspicious network traffic patterns indicative of reconnaissance, exploitation attempts, or command-and-control communication.
  • Security Information and Event Management (SIEM): Centralize and correlate security logs from all systems. Utilize SIEM for anomaly detection, threat hunting, and rapid incident response.
  • Web Application Firewalls (WAF): Deploy WAFs to protect public-facing web applications from common attack vectors, including those that might be automated by AI agents.
  • Incident Response Plan: Develop and regularly test a comprehensive incident response plan. Ensure clear roles, responsibilities, and communication protocols are established to minimize breach impact.
  • Threat Intelligence Integration: Subscribe to and integrate up-to-date threat intelligence feeds to understand emerging TTPs, including those leveraged by AI-driven adversaries.

Relevant Tools for Detection and Mitigation

Tool Name Purpose Link
Nmap Network discovery and security auditing https://nmap.org/
Metasploit Framework Penetration testing, exploit development, and post-exploitation https://www.metasploit.com/
Snort Network intrusion detection system https://www.snort.org/
Wazuh XDR platform for security monitoring, intrusion detection, and incident response https://wazuh.com/
OWASP ZAP Web application security scanner https://www.zaproxy.org/

Conclusion

The weaponization of commercial AI models like Claude, Qwen, and DeepSeek by cybercriminals represents a significant evolution in the threat landscape. These AI agents are not merely assisting; they are actively participating in the reconnaissance, exploitation, and post-exploitation phases of sophisticated cyberattacks. Organizations must pivot their defensive strategies to account for an adversary capable of increased automation, speed, and adaptability. Prioritizing fundamental security hygiene, coupled with advanced threat detection and proactive incident response, is paramount to mitigate the risks posed by these emerging AI-driven threats.

Share this article

Leave A Comment