Threat Actors Exploit Weaponized AI to Seize Full Domain Access in Under 30 Minutes
## Cybersecurity: AI in Modern Threat Landscapes
Cybersecurity: AI in Modern Threat Landscapes
Recent developments indicate that threat actors are increasingly leveraging artificial intelligence (AI) to expedite the process from initial access to full domain compromise, often achieving this within 30 minutes. This rapid advancement leaves defenders with minimal time to respond effectively.
Enterprises adopting AI in development, identity, and cloud workflows are facing adversaries who exploit similar tools for automating lateral movement, reconnaissance, and scaling post-exploitation activities.
AI-enabled intruders can escalate privileges, identify domain controllers, and gain full domain access swiftly, often before traditional security teams can respond to alerts.
Adversaries are utilizing AI models during live intrusions to generate concise commands for reconnaissance, credential harvesting, and data staging on compromised systems. CrowdStrike's findings indicate a significant reduction in eCrime "breakout time," which is the interval between initial access and lateral movement towards key assets, dropping to just 29 minutes in 2025.
The LAMEHUG malware has been observed using AI models to generate commands that assess hardware, processes, services, network configurations, and Active Directory domain information. This illustrates the increasing reliance on AI for reconnaissance tasks.
This rapid advancement leaves defenders with minimal time to respond effectively.
The technology sector remains a frequent target due to its integral role in critical business systems and supply chains.
Threat actors are integrating AI across various stages of the intrusion process. In 2025, there was a 563% increase in incidents involving fake CAPTCHA lures compared to the previous year. Moderately resourced eCrime groups have employed AI tools like Gemini and DeepSeek to generate scripts for credential dumping and forensic evidence destruction.
Attackers have also exploited victims' local AI command-line tools through malicious packages, demonstrating a growing trend of delegating post-exploitation tasks to AI systems within victim networks.
State-aligned actors, such as Russia-nexus FANCY BEAR, have utilized AI in targeted campaigns, embedding prompts for data exfiltration activities.
AI-generated scripts can expedite the classic path to domain dominance by identifying high-value accounts and servers, exploiting misconfigurations, and facilitating privilege escalation. A notable incident in February 2025 involved PRESSURE CHOLLIMA executing a large-scale cryptocurrency theft by compromising a digital asset management platform.
In 2025, 35% of cloud incidents involved abuse of valid accounts, emphasizing the shift towards credential-driven intrusions. The year also saw an 89% increase in attacks by AI-enabled adversaries, with 82% of detections being malware-free, indicating a focus on tool-based intrusions that mimic normal operations.
This trend underscores the necessity for defenders to adopt AI-driven detection, investigation, and response capabilities. Without these, organizations may find themselves compromised before they can meaningfully respond.
Based on reporting by GBHackers.
