AI Adoption Creates New Opportunities for Attackers

AI Adoption Creates New Opportunities for Attackers

AI Adoption Creates New Opportunities for Attackers

https://www.infosecurity-magazine.com/news/attackers-ai-adoption-malware/

Publish Date: 2026-06-04 10:00:00

Source Domain: www.infosecurity-magazine.com

The Microsoft Detection and Response Team (DART) has issued advice on how organizations and their security teams should respond to the rising issue of AI-powered cyber threats.

“AI is amazing, it makes our job easier. “But the same AI that’s useful can be easily manipulated by threat actors, we’ve seen it in social engineering and in our day-do-day investigations,” said Mary Asaolu, senior security researcher at Microsoft, during Infosecurity Europe on June 3.

In addition, while AI is being deployed within the enterprise to provide benefits to organizations and employees, if not managed correctly, AI code can introduce cybersecurity risks.

“AI really is the emergent angle,” said Meaghan Bradshaw, principal security researcher at Microsoft. “But AI code introduces another layer of risk. Nearly half of AI code contains flaws. Attackers can exploit it to compromise applications or data.”

This is not a theoretical concept: cyber criminals have already exploited AI tools as part of the attack chain, as demonstrated during Microsoft’s Infosecurity Europe talk titled ‘Securing AI in the Age of Intelligent Threats’, which detailed a campaign dubbed ‘JustAskJacky’.

The JustAskJacky attack tricks users into downloading what looks like a legitimate AI assistant, but is in fact a backdoor which cybercriminals use to deliver malware.

The campaign combines this with professional-looking interfaces and valid digital signatures which make it harder for both users and security tools to distinguish it from legitimate software, thus allowing it to stay under the radar.

In fact, the malicious AI assistant was so good at avoiding detection that it was only discovered when Microsoft DART was brought into an organization to investigate a separate issue.

“They found this application was masquerading as an AI assistant to help day-to-day workflows,” Bradshaw added

At first glance, it appears to function normally; however, during installation, a…

Source