Reports
KELA’s 2026 Mid-Year AI Threat Landscape Report: AI Is Becoming Both the Weapon and the Target

Artificial intelligence is no longer simply helping cybercriminals work faster—it is increasingly becoming an active participant in sophisticated attacks. That is the central conclusion of KELA’s 2026 Mid-Year AI Threat Landscape Report, which argues that cybersecurity has entered a new era where agentic AI, open-source large language models, and autonomous attack techniques are dramatically changing how cybercrime is conducted. The report describes a threat landscape in which AI is accelerating everything from vulnerability discovery and ransomware operations to phishing campaigns and corporate espionage, while simultaneously creating entirely new attack surfaces for defenders to secure.
The Rise of Autonomous Cyberattacks
For years, AI has largely served as a productivity tool for developers, security professionals, and attackers alike. KELA argues that 2026 marks a fundamental shift from AI assistants to AI systems capable of carrying out multi-step objectives with limited human involvement. Instead of merely generating code or answering questions, these systems can identify vulnerabilities, analyze software, chain exploits together, escalate privileges, and assist throughout an attack lifecycle with remarkable speed.
While early demonstrations of these capabilities came from proprietary frontier models, KELA believes the greater long-term concern is the rapid adoption of open-source models such as DeepSeek, Qwen, and Kimi. Because these models can be self-hosted, modified, and stripped of safety restrictions, criminal groups no longer depend on commercial AI providers and can build offensive AI systems entirely under their own control.
The Patch Window Is Disappearing
Perhaps the report’s most alarming prediction concerns what it calls Autonomous Vulnerability Discovery and Exploitation (AVDE). Traditionally, organizations had valuable time between the public disclosure of a vulnerability and the widespread appearance of working exploits. That window allowed security teams to test patches and secure systems before attackers could take advantage of them.
Agentic AI threatens to eliminate that advantage. Rather than relying only on previously known vulnerabilities, these systems can analyze enormous codebases, reason through complex software logic, identify flaws, validate them automatically, and generate exploit code far faster than human researchers. Once a software patch becomes public, AI systems can reverse engineer it to determine the underlying vulnerability, dramatically compressing the time available for defenders to respond. What once unfolded over months may increasingly happen within hours.
Ransomware Groups Are Integrating AI Into Daily Operations
Rather than replacing human operators, AI is becoming a force multiplier for ransomware organizations.
One example highlighted in the report examines leaked communications allegedly connected to the ransomware group known as TheGentlemen. According to KELA’s analysis, members used AI to accelerate software development, troubleshoot infrastructure problems, analyze logs, refine malicious code, draft ransom negotiations, process stolen corporate data, and build internal tools. The conversations suggest the operators viewed AI as an operational accelerator that significantly improved efficiency across nearly every stage of their campaigns, even if human oversight remained necessary.
This reflects a broader trend throughout the cybercriminal ecosystem, where AI increasingly functions as another member of the team rather than simply another tool.
Nation-State Operations Are Becoming More Automated
The report also argues that advanced persistent threat groups are beginning to automate large portions of their operations.
One case study describes an espionage campaign attributed to the China-aligned group GTG-1002, which allegedly automated between 80% and 90% of an intrusion workflow. According to KELA, AI handled vulnerability discovery, exploit generation, privilege escalation, lateral movement, and data prioritization with minimal human involvement. Whether these operations originate from nation-state actors or organized cybercrime groups, the report suggests that AI is steadily becoming the execution layer responsible for carrying out increasingly complex attacks.
Attackers Are Learning How to Manipulate AI Itself
One of the report’s more fascinating concepts is something KELA calls “Vibe Hacking.”
Instead of attempting to bypass an AI model with obvious jailbreak prompts, attackers increasingly manipulate the AI by framing malicious activities as legitimate tasks. Rather than instructing an AI to ignore its safety rules, they persuade it that it is participating in authorized security testing, software development, or internal troubleshooting. Once the AI accepts that context, it may willingly perform actions that support offensive operations.
KELA documents several examples involving AI coding assistants and Model Context Protocol servers, illustrating how carefully engineered prompts can persuade AI agents to inspect sensitive files, expose secrets, or execute portions of an attack chain while believing they are performing legitimate work.
Social Engineering Is Becoming More Convincing
Artificial intelligence is also transforming one of cybersecurity’s oldest attack methods: social engineering.
The report describes an expanding underground marketplace where criminals sell AI-powered phishing platforms, multilingual voice phishing systems, deepfake services, voice cloning technology, and AI-assisted credential harvesting tools. Some services advertise the ability to conduct hundreds of automated calls while mimicking real customer service representatives, complete with multilingual support and realistic conversational abilities.
These offerings significantly reduce the technical expertise required to launch convincing attacks, allowing criminals to purchase sophisticated capabilities through subscription services rather than developing them internally.
Infostealers Are Now Stealing Organizational Knowledge
One of the report’s most important observations involves the evolution of infostealer malware.
Historically, infostealers focused on passwords, browser cookies, cryptocurrency wallets, and authentication tokens. Today’s malware increasingly targets what KELA describes as the “cognitive layer” of AI usage. Rather than stealing only credentials, attackers now seek prompt libraries, AI memory files, cached conversations, automation workflows, business instructions, and persistent context stored by AI assistants.
This changes the nature of compromise entirely. An infected workstation no longer exposes only access credentials—it may reveal how an organization operates, the reasoning behind business decisions, proprietary workflows, strategic planning, software architecture, and internal knowledge accumulated through months of AI-assisted work.
The report estimates that KELA observed more than one million unique infected machines during just the first four months of 2026 while also documenting continued growth in macOS-focused malware targeting developers and executives.
Session Cookies Have Become More Valuable Than Passwords
KELA argues that authenticated AI sessions are rapidly becoming premium targets for cybercriminals.
Instead of stealing usernames and passwords, attackers increasingly seek browser session cookies that allow them to bypass multi-factor authentication altogether. Once they gain access to an authenticated AI session, they may inherit not only conversations but also connected developer tools, cloud services, code repositories, automation workflows, and enterprise integrations.
The report documents a growing underground market dedicated specifically to buying, validating, and reselling authenticated AI platform sessions, suggesting that session hijacking may become one of the most effective ways to compromise AI-powered enterprise environments.
AI Infrastructure Has Become an Attack Surface
As organizations deploy AI orchestration layers, inference endpoints, vector databases, Model Context Protocol servers, and autonomous agents, cybercriminals are adapting their reconnaissance efforts accordingly.
Rather than scanning only for traditional web applications, attackers increasingly search for exposed AI infrastructure that can provide direct access to models, APIs, cloud credentials, or enterprise automation systems. KELA highlights offensive platforms capable of automating internet-wide discovery of exposed AI services before validating and organizing stolen credentials into immediately usable intelligence.
The result is a cybercrime ecosystem where reconnaissance, credential harvesting, exploitation, and post-compromise analysis are becoming increasingly automated, dramatically lowering the skill barrier required to launch sophisticated attacks.
Defending the Agentic Era
KELA concludes that organizations cannot rely solely on traditional defensive strategies as AI continues to accelerate the pace of cyberattacks. Instead, enterprises must assume that AI agents, prompt libraries, memory stores, autonomous workflows, and machine identities are now critical assets requiring the same level of protection once reserved for servers, credentials, and databases.
The overarching message of KELA’s 2026 Mid-Year AI Threat Landscape Report is that artificial intelligence is reshaping cybersecurity from both directions. AI is empowering defenders with new capabilities, but it is also transforming the economics and speed of cybercrime. As businesses integrate AI deeper into their operations, securing not only their infrastructure but also the knowledge, context, and autonomous decision-making embedded within their AI systems may become one of the defining cybersecurity challenges of the decade.












