Artificial Intelligence Drives Global Surge in Targeted Cyberattacks and Custom Malware

Artificial intelligence is helping attackers move from high-volume campaigns to more targeted, adaptive and difficult-to-detect operations. WatchGuard found that network attack volume fell 79% while novel endpoint malware rose more than 2,000% year over year, suggesting greater use of automation, malware-as-a-service and victim-specific payloads. Akamai reported a 300% increase in bot traffic and a 113% rise in daily API attacks, while warning that AI browser extensions, leaked corporate data in chatbot conversations and autonomous-agent technologies are creating additional enterprise risks. Blockchain-based “dead drops,” in which malware retrieves command instructions from immutable transaction records, increased 440% to an average of 11 cases per day, with North Korean- and Iranian-linked groups accounting for much of the tracked activity. Exprivia likewise reported a record peak in AI-driven cyberattacks against Italian organizations during the second quarter of 2026, underscoring the widening gap between rapidly advancing attack capabilities and conventional defenses.
WatchGuard found that nearly 96% of endpoint threats appeared on exactly one machine, indicating that attackers are increasingly creating highly individualized payloads rather than reusing broadly detectable malware.
WatchGuard said attackers are increasingly relying on trusted accounts and native system tools to bypass security layers, reinforcing the need for stronger identity controls alongside perimeter defenses.
Akamai reported that 87% of surveyed organizations experienced an API-related security incident in 2025, up from 76% in 2022, as APIs became a dominant attack surface for enterprises.
Akamai found that 6% of chatbot conversations contain sensitive corporate information, while 47% of AI conversations on enterprise devices use personal identities or accounts that corporate IT teams cannot monitor.
The blockchain dead-drop activity was associated with the spread of powerful Chinese open-source AI models in mid-2025 that imposed few restrictions on generating malicious code; one North Korean-linked campaign used pointers across multiple blockchains, including Tron, Aptos and BNB Smart Chain, to maintain resilient command-and-control links.
Publishers
19
Articles
9
Reach
28