When Microsoft and OpenAI published their February 2024 list of state-linked groups probing large language models, one detail jumped out at me from Kathmandu: among the targets attributed to the group Microsoft calls "Charcoal Typhoon" were entities in Nepal. The frontier of AI-enabled cyber-offense isn't an abstraction happening exclusively in Redmond or Pyongyang — it had already brushed against my own corner of the map before I ever started researching this piece, which made verifying the rest of it feel less optional.
State-linked actors, caught using LLMs
The Microsoft-OpenAI disclosure from February 14, 2024 is the anchor primary source for this entire story, and it's dual-published — both companies confirmed the same account terminations independently. The named groups were Forest Blizzard, Emerald Sleet, Crimson Sandstorm, Charcoal Typhoon, and Salmon Typhoon, each linked to a different state actor, each caught using LLM accounts for tasks like translation, code debugging, and reconnaissance rather than anything novel. Microsoft's own characterization of the activity as "largely iterative" is worth taking seriously rather than glossing over — the finding wasn't that LLMs invented new attack techniques, but that they made existing tradecraft faster to execute.
CrowdStrike's threat reporting shows that trajectory accelerating. Its 2025 Global Threat Report documented 304 incidents in 2024 attributed to the eCrime group FAMOUS CHOLLIMA, roughly 40% involving insider access. Its 2026 Global Threat Report, published February 24, 2026, found AI-enabled adversary activity up 89% year-over-year, identified FANCY BEAR using LLM-enabled malware CrowdStrike calls "LAMEHUG," and clocked an average eCrime breakout time of 29 minutes — with the fastest observed breakout at 27 seconds. The same report names GenAI-built malware families Funklocker and SparkCat as further evidence that generative tools are now a routine part of criminal tooling, not a novelty.
AI-Enabled Threat Activity
CrowdStrike 2026 Global Threat Report, Feb 24, 2026
+0%
AI-enabled adversary activity, YoY (CrowdStrike 2026 GTR)
0 min
Average eCrime breakout time (CrowdStrike 2026 GTR)
0 sec
Fastest observed breakout time (CrowdStrike 2026 GTR)
The ransomware that writes itself
The single most concrete proof-of-concept in this space is ESET's PromptLock, disclosed August 27, 2025 and confirmed by ESET's own research team as the first known AI-powered ransomware proof-of-concept. PromptLock uses OpenAI's open-weight gpt-oss:20b model, run locally via Ollama, to generate Lua scripts on the fly rather than shipping a fixed payload — the malware itself is written in Golang and uses SPECK 128-bit encryption. It's linked conceptually to an academic prototype out of NYU, "Ransomware 3.0: Self-Composing and LLM-Orchestrated," which independently demonstrates the same idea: ransomware that writes its own attack logic at runtime instead of executing a hardcoded script. Both are proof-of-concept work rather than malware observed at scale in the wild, and that distinction matters — PromptLock demonstrates the capability is real and locally runnable, not that it's already a dominant criminal tool.
What a deepfake actually costs, and what shadow AI adds to a breach
The clearest dollar figure in this entire space comes from a case that had nothing to do with malware code at all. In early 2024, engineering firm Arup's Hong Kong branch lost HK$200 million — roughly $25.6 million — across 15 transactions in a single day, after an employee was deceived by a video call featuring deepfaked colleagues, including a deepfaked CFO. The case was reported to police in January 2024, made public in February, and Arup itself confirmed the incident in May 2024. It remains one of the largest publicly confirmed AI-deepfake fraud losses on record, and it's a useful corrective to any assumption that AI-enabled crime is mostly about malicious code — the Arup loss came entirely from a real-time synthetic-video social-engineering attack.
IBM's Cost of a Data Breach reports supply the aggregate picture. The 2025 edition found the global average breach cost fell to $4.44 million — the first decline in five years — while the US average hit a record $10.22 million. Within that data, shadow AI (unsanctioned or unmanaged AI tool use inside an organization) added a specific $670,000 premium to breach costs and was a contributing factor in 20% of breaches. IBM also found that 16% of breaches in 2025 involved attackers using AI directly, split roughly 37% phishing and 35% deepfake-based techniques. For comparison, the 2024 edition of the same report found a global average breach cost of $4.88 million, with AI and automation defensive tooling cutting response costs by roughly $1.88 million where deployed — a useful reminder that AI is showing up on both sides of this breach-cost ledger, not just the attacker's.
Breach Economics, 2025
IBM, Cost of a Data Breach Report 2025
$0.00M
Global average breach cost — first decline in 5 years (IBM 2025)
$0.00M
US average breach cost, a record high (IBM 2025)
+$0K
Cost premium when shadow AI is involved (IBM 2025)
AI-Involved Breach Vectors
IBM, Cost of a Data Breach Report 2025
Vector breakdown among the 16% of 2025 breaches involving attacker AI use — IBM, Cost of a Data Breach Report 2025
Verified Timeline
Primary-sourced events only — dates independently confirmed
- Feb 2024Microsoft–OpenAI joint disclosurestate-linked groups using LLM accounts terminated
- May 2024Arup deepfake fraud confirmed$25.6M lost across 15 transactions
- Aug 2025ESET discloses PromptLockfirst known AI-powered ransomware PoC
- Feb 2026CrowdStrike 2026 Global Threat ReportAI-enabled activity +89% YoY
What I'm leaving out
One statistic that circulates confidently in secondary coverage of this topic — that MIT CSAIL research found AI-generated malware achieves an 87.2% evasion rate against a 78.5% baseline for conventional malware — does not trace to any paper I could locate. I looked specifically for it because it's exactly the kind of precise-sounding percentage that's easy to repeat and hard to verify, and after not finding a primary source, I'm dropping it rather than including it with a soft caveat. Similarly, three well-known AI-malware proof-of-concepts often cited alongside PromptLock — BlackMamba (HYAS Labs, March 2023), Morris II (Cornell/Technion/Intuit researchers, March 2024), and WormGPT (first reported by SlashNext, July 2023) — are real and widely reported, but I did not independently re-verify their specific technical claims and dates for this piece, so I'm naming them without asserting details I haven't checked line by line. And while the defensive stack against all of this — CrowdStrike Falcon, SentinelOne Singularity, Microsoft Defender XDR, Illumio, Zscaler, Exabeam — is real and vendor-confirmed, any specific detection-rate percentage attributed to one of these products should be checked against the vendor's own published benchmark before being repeated. It's worth noting this threat picture sits alongside two other shifts I've covered separately: the same agentic AI systems being deployed defensively and offensively across cloud infrastructure, and the parallel, slower-moving migration to post-quantum cryptography — a reminder that "AI security" and "cryptographic security" are separate races running on different clocks.
The view from Kathmandu
What sits with me most from this research isn't the malware — PromptLock is a proof-of-concept, not something I'd expect to encounter deployed at scale yet. It's that Charcoal Typhoon's target list, disclosed by two of the most scrutinized companies in the industry, already included my country before most of the coverage of "AI cybersecurity threats" had settled on a single narrative. The honest shape of this story, based on what actually holds up, is narrower than the scariest headlines and more concrete than the vaguest ones: LLMs haven't yet produced an unstoppable new weapon, but they've measurably lowered the cost of running a deepfake fraud (Arup's $25.6M), measurably increased the cost of ignoring unsanctioned AI tool use (IBM's $670K shadow-AI premium), and measurably sped up how fast state-linked and criminal actors move once they're in (CrowdStrike's 29-minute average, 27-second fastest breakout). None of that requires exaggeration to be worth taking seriously.
Sources
- microsoft.com — "Staying ahead of threat actors in the age of AI," Feb 14, 2024 (state-linked group disclosures, including Charcoal Typhoon)
- openai.com — "Disrupting malicious uses of AI by state-affiliated threat actors," Feb 14, 2024 (joint disclosure, account terminations)
- crowdstrike.com — 2025 Global Threat Report (FAMOUS CHOLLIMA, 304 incidents); 2026 Global Threat Report, Feb 24, 2026 (AI-enabled activity +89% YoY, LAMEHUG, 29-min average / 27-sec fastest breakout, Funklocker, SparkCat)
- eset.com; welivesecurity.com — PromptLock disclosure, Aug 27, 2025 (gpt-oss:20b via Ollama, Golang, SPECK 128-bit)
- CNN — Arup Hong Kong deepfake fraud, May 16, 2024 ($25.6M / HK$200M, 15 transactions); Financial Times via CFO Dive — additional reporting
- ibm.com — Cost of a Data Breach Report 2025 ($4.44M global avg, $10.22M US avg, $670K shadow-AI premium, 16% AI-involved breaches); newsroom.ibm.com — Cost of a Data Breach Report 2024 ($4.88M global avg, ~$1.88M AI/automation cost reduction)
Written by Abhishek Kushwaha, founder and writer at Global Tech Search, based in Kathmandu, Nepal.
