From AI to Aye-Aye, Captain! Charting the Landscape of AI Dangers

No ratings

Presented at BlueHat IL 2025 by

As enterprises increasingly adopt AI technologies, attackers are discovering innovative ways to weaponize these legitimate tools. This session analyzes the evolving threat landscape of AI-powered tools in enterprise environments, focusing on how adversaries exploit built-in AI capabilities to execute sophisticated Living-Off-the-Land (LotL) attacks—without relying on traditional malware. Through real-world examples, we’ll explore how AI assistants and AI-driven softwares are repurposed for malicious activities across the attack lifecycle: Initial Access: AI-enhanced phishing and data exposure exploitation. Reconnaissance: Analyzing internal documents, emails, and data repositories to extract sensitive information. Lateral Movement: AI-generated messages that mimic trusted personnel for seamless network access. Privilege Escalation: Abusing AI-driven workflow automation to gain unauthorized privileges. Data Exfiltration: Leveraging trusted communication channels, unauthorized APIs, and AI-generated scripts to evade detection. Persistence: Embedding malicious commands in AI-driven tasks and workflows for long-term access. We’ll showcase techniques like automated AI workflows for data extraction, file size manipulation for stealthy exfiltration, and exploiting under-monitored communication channels. Key Takeaways: How to integrate AI-specific threat models into security frameworks. Strategies for continuous monitoring of AI-driven anomalies. Building a security-aware culture that recognizes AI as a critical threat vector. AI isn’t just a productivity enhancer—it’s the next attack surface. Join this session to learn how to defend against AI-driven threats before adversaries outsmart your defenses.