Microsoft Report Warns of AI-Powered Automation in Cyberattacks and Malware Creation
According to Microsoft's latest Digital Defense Report, covering trends from July 2024 through June 2025, cybercriminals are increasingly utilizing artificial intelligence (AI) to enhance malware development, identify vulnerabilities more swiftly, and…
According to Microsoft's latest Digital Defense Report, covering trends from July 2024 through June 2025, cybercriminals are increasingly utilizing artificial intelligence (AI) to enhance malware development, identify vulnerabilities more swiftly, and execute sophisticated phishing campaigns.
The report reveals that in 80% of the cyber incidents investigated by Microsoft, attackers were primarily motivated by financial gain rather than intelligence gathering. The advent of AI-powered attacks has lowered the entry barrier for cybercriminals, allowing individuals with limited technical expertise to conduct impactful campaigns.
Financial motives now dominate cyberattacks, with over 52% of incidents driven by extortion or ransomware. Microsoft processes over 100 trillion signals daily, blocking approximately 4.5 million new malware attempts, analyzing 38 million identity risk detections, and screening 5 billion emails for malware and phishing.
Despite extensive defensive measures, threat actors continue to leverage AI to automate attack processes, expand social engineering operations, and generate synthetic media to enhance the realism of their campaigns.
AI Transforms Both Attack and Defense Strategies
The report highlights that 2025 saw a marked increase in AI adoption by both attackers and defenders. Threat actors use generative AI to automate phishing campaigns, discover software vulnerabilities at unprecedented speeds, and develop adaptive malware that can modify its behavior to evade detection.
Nation-state actors have incorporated AI into cyber influence operations, making these efforts more advanced, scalable, and targeted. While AI enhances attacker capabilities, defenders also leverage the technology's power to detect threats, close detection gaps, and protect vulnerable users.
Financial motives now dominate cyberattacks, with over 52% of incidents driven by extortion or ransomware.
Ransomware actors specifically target sectors where victims have limited options when systems are encrypted. Geopolitical objectives continue to drive state-sponsored cyber activity, with an expansion in targeting communications, research, and academia.
Organizations are urged to prioritize securing their AI tools and training teams to stay ahead of increasingly sophisticated adversaries. Critical public services, such as hospitals and local governments, face heightened risk due to limited cybersecurity budgets and outdated software.
The past year witnessed cyberattacks causing delayed emergency medical care and disruption in other essential services. Institutions storing sensitive data are particularly vulnerable, as attackers can monetize this data through illicit marketplaces.
The report indicates a concerning rise in identity-based attacks, with more than 97% targeting passwords through large-scale guessing attempts using leaked credentials. Identity attacks increased by 32% in the first half of 2025.
Cybercriminals deploy infostealer malware to harvest credentials and browser session tokens, which are then sold on cybercrime forums. However, Microsoft emphasizes that phishing-resistant multifactor authentication (MFA) can block over 99% of these attacks, even when attackers have correct username and password combinations.
In May, Microsoft's Digital Crimes Unit disrupted Lumma Stealer, a popular infostealer malware, in collaboration with the US Department of Justice and Europol.
Nation-state actors continue targeting key industries and regions for espionage and financial gain. China accelerates espionage across industries, while Iran and Russia expand their targeting to include North America and NATO countries, respectively. North Korea focuses on revenue generation through remote IT worker schemes and extortion.
The report concludes that traditional security measures are insufficient against evolving threats. Organizations must treat cybersecurity as a strategic priority, implementing modern defenses that utilize AI and fostering strong collaboration across industries and governments to build collective deterrence against sophisticated adversaries.
Based on reporting by GBHackers.
