AI Is Changing How Cyberattacks Are Carried Out
In the past, hackers needed multiple specialists to carry out an attack, handling tasks such as:
- Analyzing the target’s systems
- Writing attack scripts
- Finding vulnerabilities
- Refining code
- Preparing documentation or instructions for the team
While AI can’t “hack a system” on its own, it can effectively help generate, analyze, and refine the information used in an attack.
How Are Claude Code and DeepSeek Being Used?
According to security researchers, attacker groups assign each AI model a role suited to its strengths, for example:
Claude Code
Used as an assistant for writing and refining code, including generating automation scripts and handling tasks related to developing attack tools.
DeepSeek
Used for data analysis, attack planning, summarizing gathered information, and helping map out next steps.
Using both AI models together makes the attack process more systematic and considerably faster than traditional methods.
AI Itself Isn’t the Threat — How It’s Used Is
The key point of this story isn’t that Claude or DeepSeek are dangerous software — it’s a reminder that
“AI tools designed to boost productivity can be misused when they end up in the wrong hands.”
This is no different from developer tools or other IT software that can be used both to build innovative products and to commit cybercrime.
The Impact on Organizations
For organizations, the rise of AI doesn’t just mean higher productivity — it also means threats are evolving faster.
Examples of risks organizations should pay attention to include:
- More convincing phishing emails
- Malware that can be modified quickly
- Automated analysis of system vulnerabilities
- AI-generated attack scripts
- Gathering data from multiple sources to plan an attack
How Should Organizations Prepare?
As AI becomes part of the toolkit for both defenders and attackers, organizations should strengthen their cybersecurity approach alongside adopting AI, for example:
- Set clear internal policies for AI use
- Keep systems and security patches consistently up to date
- Monitor systems and users for unusual behavior
- Train staff to recognize new forms of cyber threats
- Use AI to support security event detection and response
AI is changing how every organization works — and at the same time, it’s changing how cybercriminals attack.
This story is another reminder that cybersecurity isn’t just an IT department issue — it’s a critical part of organizational strategy in the digital era.
At Dragons Move, we believe adopting AI should go hand in hand with secure system design, sound data management, and building security awareness among staff — so organizations can make full use of AI’s potential while staying ready for constantly evolving risks.
Key Takeaways
- Attackers have begun incorporating AI into their cyberattack process
- Claude Code and DeepSeek are being used to help analyze, plan, and generate code for attacks
- AI itself isn’t inherently a threat, but it can be misused
- Organizations should strengthen cybersecurity measures alongside adopting AI
- Using AI safely requires technology, process, and staff knowledge working together
Source
This article was written and analyzed based on a Threat Intelligence report citing security researchers’ investigation into the use of AI in cyberattack operations. Details on attribution and the full scope of the incident are based on the researchers’ analysis and have not yet been confirmed by all parties involved.