KELA Unveils New Findings on AI Weaponization in 2025 AI Threat Report
KELA, a global leader in cyber threat and exposure intelligence solutions, today released its 2025 AI Threat Report: How Cybercriminals are Weaponizing AI Technology (LINK), revealing a 200% increase in mentions of malicious AI tools on cybercrime forums in 2024. The findings underscore the growing trend of cybercriminals rapidly advancing their AI tactics.
In the past 12 months, threat actors increasingly leveraged LLMs including ChatGPT, Gemini, DeepSeek, Claude and other public GenAI applications to use dark AI tools to improve business operations and to use jailbreak techniques to bypass public AI systems to conduct malicious activities. The shift in tactics requires a new mindset where organizations must act just as quickly to stay ahead.
Key Findings from KELA’s 2025 AI Threat Report:
- Jailbreaking methods are evolving rapidly: Threat actors are continuously refining AI jailbreaking techniques to bypass security restrictions in public AI systems. KELA observed a 52% increase in discussions related to jailbreaking methods on cybercrime forums in 2024 compared to the previous year.
- Threat actors are increasingly leveraging AI in cybercrime forums: KELA’s platform recorded a 200% increase in mentions of malicious AI tools and tactics in 2024, highlighting a growing underground market for AI-assisted cybercrime.
- Dark AI tools are proliferating: Cybercriminals are distributing and selling jailbroken AI models and customized malicious AI tools, such as WormGPT and FraudGPT, to automate phishing, malware creation, and fraud operations.
- AI-driven phishing campaigns are becoming more sophisticated: AI-generated phishing and social engineering tactics have increased in effectiveness, with deepfake technologies being used to impersonate executives and trick employees into executing fraudulent transactions.
- Malware development is becoming more efficient with AI assistance: Threat actors are using AI tools to generate at scale sophisticated, evasive malware, including ransomware and infostealers, making detection and mitigation more challenging for security teams.
“We are witnessing a seismic shift in the cyber threat landscape,” said Yael Kishon, AI Product & Research Lead at KELA. “Cybercriminals are not just using AI – they are building entire sections in the underground ecosystem dedicated to AI-powered cybercrime. Organizations must adopt AI-driven defenses to combat this growing threat.”
To combat the rising AI-powered cyber threats, KELA urges organizations to invest in employee training, monitor evolving AI threats and tactics, and implement AI-driven security measures including automated intelligence-based red teaming and adversary emulations for Generative AI models.
The 2025 AI Threat Report: How Cybercriminals are Weaponizing AI Technology is available here.
Also read: Viksit Workforce for a Viksit Bharat
Do Follow: The Mainstream formerly known as CIO News LinkedIn Account | The Mainstream formerly known as CIO News Facebook | The Mainstream formerly known as CIO News Youtube | The Mainstream formerly known as CIO News Twitter
About us:
The Mainstream formerly known as CIO News is a premier platform dedicated to delivering latest news, updates, and insights from the tech industry. With its strong foundation of intellectual property and thought leadership, the platform is well-positioned to stay ahead of the curve and lead conversations about how technology shapes our world. From its early days as CIO News to its rebranding as The Mainstream on November 28, 2024, it has been expanding its global reach, targeting key markets in the Middle East & Africa, ASEAN, the USA, and the UK. The Mainstream is a vision to put technology at the center of every conversation, inspiring professionals and organizations to embrace the future of tech.