TL;DR: Generative AI is being used by attackers to increase attack success rates and to power malicious LLMs such as WormGPT, according to Abnormal AI’s Vision 2024 webinar with Keren Elazari. The governing assumption is collapsing because cybercrime now adapts at AI speed, while traditional detection and user-awareness controls still assume slower, more predictable attacker behaviour.
At a glance
What this is: This is a webinar-based analysis of how generative AI is changing cybercrime, with the central finding that attackers are using it to improve attack success and weaponise malicious LLMs like WormGPT.
Why it matters: It matters because IAM, email security, and identity teams now have to account for faster attacker adaptation, higher-quality social engineering, and AI-assisted abuse that can outpace static controls.
Context
Generative AI is lowering the cost and increasing the speed of criminal tradecraft. The article centres on how attackers are using AI to improve attack success rather than on the model itself, which makes the issue an identity and trust problem as much as a detection problem.
For security and identity programmes, the practical question is how well existing controls handle adversaries that can produce more convincing lures, iterate faster, and adapt content at machine speed. The article points to a shift in attacker capability, not a single new exploit path.
Key questions
Q: How should security teams reduce phishing risk when AI makes scam messages more convincing?
A: Teams should stop relying on obvious spelling mistakes and train people to verify the sender, destination, and request through a separate channel. The better control is a combination of realistic simulations, password managers, and simple confirmation habits for urgent or payment-related messages. That reduces both click risk and downstream credential theft.
Q: Why do AI-assisted cyberattacks reduce the value of static awareness training?
A: Static awareness training assumes attackers reuse predictable language and patterns. AI-assisted campaigns can be rewritten at scale for each target, so training has to be paired with enforcement, anomalous-behaviour detection, and controls that reduce the impact of a successful lure.
Q: What are the signs that attackers are using generative AI to support ransomware operations?
A: Common signs include rapid rewriting of code to evade detection, unusually polished phishing or support messages, repeated use of AI-assisted translation, and workflow steps that suggest content generation at scale. Teams should also watch for suspicious access to AI services, account sharing, and attacker troubleshooting that references model outputs, because those patterns often indicate operational use rather than casual experimentation.
Q: What should teams do first when malicious LLMs start appearing in their threat model?
A: Start by identifying the workflows where generated content could influence trust, such as email, credential prompts, support processes, and payment approvals. Then tighten controls at those decision points so a convincing message cannot move an identity workflow forward on appearance alone.
Background and context
How generative AI changes attacker tradecraft
Generative AI changes the economics of cybercrime by accelerating content creation, variation, and targeting. In practice, that means attackers can produce more convincing phishing, more scalable pretexting, and faster campaign iteration with less manual effort. The key mechanism is not magical autonomy but lower-friction synthesis of language and artifacts that support social engineering and malware-adjacent operations. That shifts the defender’s challenge from spotting obvious poor-quality lures to dealing with large volumes of polished, context-aware deception.
Practical implication: tune detection and user-reporting controls for quality and variability, not just known-bad templates.
Malicious LLMs and the abuse of generative models
Malicious LLMs such as WormGPT represent a distinct risk because they are purpose-built or repurposed to support offensive activity. They can help attackers generate persuasive text, streamline fraud workflows, and reduce the friction of creating malicious content at scale. The important technical distinction is that the model is being used as an enabling layer for crime, not merely as a content tool. That makes abuse harder to measure through traditional signatures alone and increases the value of behavioural and contextual controls.
Practical implication: treat suspicious language generation and campaign variation as abuse signals, not isolated anomalies.
Why legacy controls struggle against AI-assisted attacks
Legacy controls often assume a slower attacker loop, where content can be reviewed, patterns stabilise, and detection rules catch repeated indicators. Generative AI breaks that rhythm by letting attackers continuously rephrase, localise, and tune lures with little overhead. That means the same campaign can arrive in many forms before defenders have tuned rules or awareness materials. For identity teams, the consequence is that trust decisions based on static cues become less reliable because the attacker can manufacture more credible context on demand.
Practical implication: shift from template-based defense to behavioural, identity, and policy-based enforcement around high-risk interactions.
NHI Mgmt Group analysis
Generative AI has become an attack multiplier, not a separate threat class: The article shows that the primary change is speed, scale, and quality in attacker output. That matters because many security programmes still tune controls to catch repetitive, low-quality fraud or phishing artefacts. The practitioner conclusion is that detection quality has to rise as attacker generation quality rises.
Identity trust is now a more fragile security control surface: When attackers can rapidly generate convincing messages and context, the weak point is often not the model but the human and workflow trust decisions around it. Email security, IAM, and access workflows all rely on some level of contextual judgment, and that context can now be manufactured cheaply. Practitioners need to treat trust as a governed control surface, not an assumption.
Malicious LLMs are operational evidence of cybercrime industrialisation: The article’s mention of WormGPT signals a market where offensive capability is being productised for repeatable misuse. That changes the governance question from whether AI can be abused to how quickly abuse can be commoditised and re-used across campaigns. The practitioner takeaway is to align detection, response, and user education to reusable attacker tooling rather than one-off incidents.
Static awareness programmes no longer match adaptive adversaries: Traditional training often assumes that bad messages can be described in advance and recognised later. Generative AI undermines that assumption because each lure can be re-authored for a specific target, making yesterday’s examples less useful. The conclusion for security leaders is that awareness must be paired with enforcement and behavioural controls, not left as a standalone compensating measure.
AI-driven cybercrime is already compressing the defender’s reaction window: Since ChatGPT launched, the article says cybercrime has transformed materially, which means the response cycle is now part of the attack surface. Every delay in updating detection logic or policy gives attackers more room to refine prompts, messages, and delivery. Practitioners should assume the attacker learns faster than most control-update cycles.
What this signals
Campaign quality is now a control problem: Security teams should expect more polished lures, faster rewrites, and wider campaign variation than most legacy detections were designed to handle. The practical response is to anchor controls in behaviour, identity context, and response speed rather than static content matching.
Malicious LLM abuse will keep compressing defender timelines: Once offensive content can be generated and re-generated cheaply, the gap between first detection and attacker adaptation becomes a real risk variable. Programmes that rely on slow human review cycles will struggle to keep pace with that change.
Trust workflows need stronger enforcement boundaries: Identity and email programmes should treat user trust decisions as governable events, not soft outcomes. That means reducing the number of places where a convincing message alone can advance access, payment, or approval.
For practitioners
- Harden email and identity trust points Reassess the controls that decide whether a message, login attempt, or workflow request should be trusted when the content is AI-generated and highly variable.
- Update detection for AI-assisted variation Tune detections to look for campaign behaviour, intent, and abnormal interaction patterns rather than fixed phrasing or repeated lures.
- Train users on AI-shaped social engineering Refresh awareness content so staff can recognise highly polished, personalised, and rapidly reworded attempts instead of obvious spam cues.
- Review controls around malicious LLM abuse Map where generative AI could lower the effort needed for phishing, fraud, or impersonation inside your environment and tighten policy at those points.
- Shorten the response loop for campaign adaptation Make sure threat hunting, mailbox controls, and user reporting can feed rule updates quickly enough to keep pace with attacker rephrasing.
Key takeaways
- Generative AI is changing cybercrime by improving the quality and speed of attacker output, which weakens controls built around predictable, repetitive threats.
- The article’s mention of WormGPT shows that malicious LLMs are becoming a practical enablement layer for phishing, fraud, and impersonation at scale.
- Security teams should move beyond content matching and focus on behavioural detection, tighter trust boundaries, and faster policy updates.
Key terms
- Generative AI abuse: The use of text, code, or media generation systems to improve the speed, scale, or believability of offensive activity. In security practice, this usually means better phishing, more convincing pretexts, or faster campaign variation that increases the odds of identity compromise.
- Malicious LLM: A large language model used or adapted for offensive purposes, often to remove safety guardrails that restrict harmful output. For practitioners, the concern is not the label alone but the operational effect: more persuasive social engineering, faster iteration, and higher campaign throughput.
- AI-powered social engineering: AI-powered social engineering is the use of generated text, voice, video, or interface content to manipulate a target into taking an unsafe action. The goal is not just deception, but trust transfer, where the attacker convinces a legitimate identity holder to approve, disclose, or execute something harmful.
- Trust Boundary: A trust boundary is the point where one system’s authority should stop and another system’s authority should begin. For internal automation, weak trust boundaries let monitoring, remediation, and execution share privileges that should have remained separate.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org