Hackers Deploy Claude and DeepSeek in Live Cyberattacks
A new report from Gambit Security reveals that cybercriminals are actively integrating AI models like Claude and DeepSeek into live attack workflows to automate and accelerate intrusions.

A new report from Gambit Security, "AI Across the Intrusion Lifecycle," documents how threat actors are integrating artificial intelligence directly into active cyberattacks. Researchers Eyal Sela and Nir Varon analyzed three campaigns where attackers used AI to write scripts, analyze stolen data, and troubleshoot infrastructure. In one case, a suspected affiliate of The Gentlemen ransomware group used Anthropic's Claude Code in June 2026 to compromise six organizations across the U.S., Australia, Mauritius, South Africa, Thailand, and Malaysia. The operator bypassed Claude's safety guardrails by claiming the work was an authorized test, using the AI to map networks and identify targets before a model error left a utility's firewall unreachable.
A second campaign, Zerofot, used OpenAI Codex and Claude Code to build a credential-harvesting scanner called auto_scan. The operators bypassed safety filters by claiming the tool was for a capture-the-flag challenge. Between April 5 and May 23, 2026, the operation harvested 2,975 validated credentials from 1,742 hosts, including 661 SSH private keys, 635 AWS access keys across 214 accounts, 448 Google Gemini keys, 254 OpenAI keys, and 176 Anthropic keys. Claude Code also managed the campaign's backend infrastructure, handling proxy management and debugging.
A third actor deployed RAGE, an AI-generated Python framework featuring a DeepSeek-backed AI Orchestrator to manage cryptocurrency mining. The tool targeted services like Redis and Tomcat, compromising an AWS account to gain access to eight Identity and Access Management users—four with administrator privileges—and 196 Amazon S3 buckets. These findings match broader trends; Anthropic analyzed 832 malicious accounts active between March 2025 and March 2026, finding AI usage across all 14 MITRE ATT&CK tactics. Anthropic reported that medium-to-high-risk actors rose from 33% to 56% between the first and second halves of that period.
For defenders, this shift means countering adversaries operating at machine speed. While AI models made errors that exposed attackers—such as leaving self-correcting reasoning comments in the RAGE code—they significantly compressed the time required for reconnaissance. Security teams must now focus on detecting rapid, adaptive behavioral signals rather than just looking for AI-generated malware.
This is our own summary of reporting by Unite.AI



