Skip to content

Cybersecurity

AI in offensive cybersecurity: from payloads to APT operations

Artificial intelligence does not create autonomous threats, but it makes attacks faster and more variable. What changes for those defending OT environments.

2 min read
Screen showing malware code and AI symbols highlighting automated payload generation

AI as an accelerator, not an autonomous weapon

In recent months, the debate on artificial intelligence applied to cyberattacks has become more concrete. The most balanced reading, shared by much of the OT security research community, is that today AI acts mainly as an efficiency accelerator: it does not introduce radically new offensive capabilities, but it shortens development time, multiplies variants, and automates decisions that previously required manual work.

In other words, defenders are not yet facing fully autonomous threats. They are, however, already facing attacks that are faster, noisier, and more diverse from one another.

Where attackers are using AI

The integration of AI into malicious campaigns follows three main directions:

  • Development and red-teaming assistance: models help write, refine, and port code across different languages.
  • Direct payload generation: scripts and backdoors produced semi-automatically, often recognizable by unusually verbose comments.
  • Runtime integration: malware that queries a language model during execution to make dynamic decisions.

A few documented examples make the picture tangible:

Threat Use of AI
Slopoly AI-generated PowerShell C2 backdoor for fast post-compromise access
Konni APT PowerShell backdoor with extensive comments, a hint of automated generation
APT36 Mass production of variants by porting logic across Nim, Zig, Go, and .NET
PromptLock Ransomware that queries an LLM at execution time for dynamic choices
PROMPTFLUX VBScript dropper that regenerates obfuscated code in real time

Why signature-based detection is faltering

The critical point for defenders is this: AI-assisted development makes it possible to create many functionally identical but structurally different samples. By changing language, structure, and obfuscation at every iteration, attackers erode the effectiveness of detection based on static signatures.

AI does not generate new attack techniques, but it makes it cheap to produce infinite variants of the same one.

It must be said that many of these implementations remain experimental and still depend on traditional delivery and human intervention. The trajectory, however, is clear.

The MON5 angle: visibility and anomalies in OT environments

For those managing industrial and OT infrastructure, the practical consequence is that you cannot rely on static indicators alone. When the payload mutates at every execution, what stays stable is behavior: the sequence of actions, the execution context, the anomalous flows.

On this ground, OT defense has a few specific levers:

  • Complete asset visibility: knowing which devices talk, to whom, and over which protocols is the basis for recognizing what is out of place. An unexpected API communication toward an LLM service from an unauthorized control system is already a strong signal.
  • Correlating vulnerabilities with plant context: a CVE is not worth the same everywhere. Weighing it against exposure, process criticality, and network segmentation makes it possible to prioritize what really matters.
  • Anomaly monitoring without stopping production: passive analysis of industrial traffic spots behavioral deviations without interfering with operational continuity, which in OT is non-negotiable.

In summary

Offensive AI is an operational reality, but its main effect is quantitative: more speed, more variants, more noise. The answer is not to chase every new signature, but to shift the center of gravity of defense toward behavior, context, and continuous visibility. For OT environments, where process integrity comes before everything, this is exactly the approach MON5 puts at the center.

Analysis and commentary by MON5 based on public-domain research and data from the OT/ICS sector.

Do you have visibility into your OT network?

MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.

MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
© 2026 MON5 · All rights reserved
Get certifications
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna