Kaspersky’s Global Research and Analysis Team (GReAT) expects state-affiliated actors and cybercriminals will continue to use artificial intelligence (AI) in their advanced persistent threat (APT) attacks.
In 2024, AI has played a key role in more sophisticated attacks. The Lazarus Group used AI-generated images to exploit vulnerabilities in Chrome, stealing cryptocurrency. APT groups are also embedding malicious code into AI models and datasets, distributing backdoored versions that are difficult to detect. These tools, such as large language models (LLMs), enable attackers to automate tasks like vulnerability detection and malicious script generation.
“AI is a double-edged sword — while cybercriminals use it to enhance their attacks, defenders can harness its power to detect threats faster and strengthen security protocols,” Maher Yamout, lead security researcher at Kaspersky’s GReAT, said in a media release. “However, cybersecurity experts must approach this powerful tool with caution, ensuring that its use doesn’t inadvertently open new avenues for exploitation.”
The Kaspersky report anticipates the widespread use of deepfake technology for impersonating individuals. Cybercriminals could exploit this to create realistic messages or videos, deceiving employees and stealing sensitive information.
Hacktivism
Increased attention was also given to supply chain attacks targeting open-source projects. With modern versions of C++ and Go becoming standard in open-source ecosystems, attackers are adapting malware to exploit these languages. GReAT predicts a rise in such attacks as open-source adoption grows.
IoT devices, forecasted to hit 32 billion by 2030, are another growing concern. Many devices run on outdated firmware, exposing them to vulnerabilities. Attackers could exploit these weaknesses during production or through compromised apps, leaving defenders struggling to mitigate risks.
Hacktivist alliances are expected to escalate, with groups forming networks to share tools and launch coordinated campaigns. The BYOVD (bring your own vulnerable driver) technique, where attackers exploit low-level vulnerabilities, continues to evolve, posing a growing challenge in 2025.