AI arms script kiddies with state-sponsored capabilities, Unit 42 warns
Unit 42 warns that AI is giving low-skill hackers state-sponsored-level tooling and sophistication, reshaping cyber threat classifications.
The warning came as Unit 42 discussed early findings from its new service, Frontier AI Defense, which launched in April. The service combines threat intelligence, threat telemetry, and frontier AI models to help enterprise clients address security issues that have become urgent due to AI.
According to Unit 42, in three weeks of internal tests, the team completed the equivalent of about one or two years of penetration testing, uncovering dozens of vulnerabilities across customer environments using AI pen-testing models. If the speed and scale of AI-based vulnerability discovery can be applied this effectively for defenders, the same tools could give cybercriminals a significant advantage.
Sherrod DeGrippo, Vice President of Threat Intelligence at Unit 42, said that traditional categories of cyberattacks have shifted. Socially motivated groups, she said, are "enabled with the same tooling and sophistication as a state-sponsored group" due to artificial intelligence. "This part of the landscape will continue to increase and bring in low-skilled actors that now have exponentially bigger and better capabilities than we've seen before," DeGrippo commented. "These are people who know how to use a tool -- and we've given them incredible tools."
In the past, most script kiddies and hacktivists lacked an adequate understanding of the underlying technology or programming languages to modify digital weapons for their specific goals. They relied on others' tools, scripts, and programs. Now, with the backing of AI to run analyses, reverse-engineer, or even develop tools for them if the right guardrails are not in place, these lower-skilled groups have far more at their disposal without the need to upskill.
Unit 42 calls AI a "force multiplier" that is changing how cybersecurity operates. While threat actors have previously experimented with AI and large language models piece by piece in the attack chain -- improving phishing campaigns, translating language, or assisting with ransomware negotiations -- AI is now being used across the entire process. One example is JadePuffer, which is believed to be a fully agentic ransomware attack, with every stage handled by AI from beginning to end.
Sam Rubin, Senior Vice President of Consulting and Threat Intelligence at Unit 42, said there has been a "relative balance between the security and compromise of our information," but now, "AI is breaking that balance." The elements of a cyberattack, from discovering vulnerabilities to developing malware or conducting social engineering, used to require manual execution. But now, AI can take over many of these tasks, which gives cybercriminals "the time and energy back to be more effective," according to Rubin.
The speed advantage is stark. During the cybersecurity firm's work on its new service, the team found that AI could be used to identify and exploit vulnerabilities, escalate privileges, and steal data all within 10 hours in an operation that would normally take a penetration testing team around two weeks.
DeGrippo was also asked whether old-school hacktivism, like Anonymous, could make an AI-powered resurgence. According to the executive, "it's absolutely possible" as "AI is enabling individuals in ways that they have never been enabled before." She also noted that attribution will become far more difficult in the future, as AI and open access tools complicate the process of identifying attackers.