AI is reshaping cybercrime through automated network intrusions, adaptive Android malware, deepfake executive impersonation and payment skimming. Trellix says attackers are increasingly using AI to reduce human involvement, exploit trusted digital behaviour and make fraudulent activity harder to detect.

Trellix Flags Rising Threat From AI-Driven Cyberattacks and Deepfakes

The420 Correspondent
6 Min Read

New Delhi. Artificial intelligence (AI) has pushed cybercrime into a new phase, with attackers increasingly exploiting digital activities that appear normal and trustworthy. Criminals are no longer relying only on phishing links, stolen passwords or conventional malware. Routine actions such as logging in, approving payments, using familiar mobile applications or following instructions from senior executives are increasingly being targeted through AI-driven attacks. A report by cybersecurity company Trellix has examined several such techniques involving cyber espionage, mobile malware, financial fraud and extortion.

According to the report, AI is helping attackers automate multiple routine tasks during network intrusions. In the China-linked GTG-1002 espionage campaign, AI agents reportedly handled between 80 and 90 per cent of operational tasks. Human operators made around four to six key decisions, including selecting targets and approving data theft, while software carried out many of the activities in between. These reportedly included reconnaissance, credential harvesting and exploiting vulnerabilities.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

Reducing human intervention can allow attackers to complete multiple stages of an intrusion more rapidly. The report suggests that this creates an additional challenge for security teams because individual activities may appear normal when viewed separately. Instead of examining only an isolated login or request, organisations increasingly need to analyse the broader pattern of behaviour surrounding the activity.

AI-enabled techniques are also being used against mobile devices. PromptSpy, an Android malware, can read what is displayed on a device screen and use that information to determine subsequent actions. Rather than depending entirely on fixed screen layouts or predetermined button positions, it can adapt its actions according to the interface it encounters.

According to the report, PromptSpy uses accessibility permissions to maintain its presence on a device and place invisible layers over certain controls that could otherwise be used to remove it. This can make it difficult for users to uninstall the suspicious application. The malware can also capture screen activity and lock-screen information, potentially exposing sensitive personal data.

The financial sector is facing another form of risk through deepfake technology. Trellix cited a case in which fake video and audio of senior company executives were allegedly used to persuade a finance employee to approve a $25 million transfer. The face shown during the video call and the voice heard by the employee appeared to belong to genuine executives, making the payment request appear legitimate.

Such attacks exploit not only technology but also the trust and pressure built into corporate decision-making. An urgent payment request apparently coming from a senior executive can encourage an employee to bypass normal verification procedures. As a result, relying solely on a familiar face or voice during a video call may not be sufficient before approving a high-value financial transaction.

Online shopping systems are also being targeted through attacks that exploit familiarity. In double-tap skimming, a fake payment form is presented to the customer and captures card information. The form may then appear to fail and redirect the customer to the legitimate payment page. The purchase can subsequently be completed normally, while the card details have already been stolen.

The report also discusses the cybercrime group LunaLock. According to Trellix, the group compromised more than 95,000 accounts associated with an online marketplace for artists. The company said AI was also being used to identify sensitive material in stolen data and refine extortion demands based on the information obtained.

For high-value payments, cybersecurity guidance increasingly emphasises independent verification. A payment request can be checked through an established official phone number or a pre-agreed verification code rather than relying solely on the same video call, email or message through which the request was received.

Organisations are also being advised to adopt phishing-resistant authentication, conduct regular security and exposure assessments, and encrypt sensitive documents. On mobile devices, unnecessary accessibility permissions should be avoided, while unusual application behaviour should be investigated promptly.

The growing use of AI in cyberattacks means security can no longer depend only on verifying who appears to be making a request. Organisations also need to examine the device involved, the timing of the request and whether the behaviour matches established patterns. In a digital environment where faces, voices and interfaces can be convincingly imitated, independent verification before critical actions is becoming an increasingly important defence against fraud.

About the author — Suvedita Nath is a science student with a growing interest in cybercrime and digital safety. She writes on online activity, cyber threats, and technology-driven risks. Her work focuses on clarity, accuracy, and public awareness.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected