AI-driven cyber attacks: what changes, and what is marketing
Generative AI changes cyber attacks in scale, language quality and personalisation. The underlying techniques remain unchanged. Phishing in flawless Swiss German, deepfake vishing against the finance team, auto-generated malware code and LLM-driven reconnaissance are today's reality. The kill chain, detection logic and the importance of fast response remain unchanged. Attack volume, quality and the ability to bypass security controls based on linguistic or behavioural anomalies are changing.
Scope: attack side, not defence side
This page covers how attackers use AI. AI in the SOC explains how a SOC uses AI defensively for triage, correlation, automation and analyst assistance. For the specific attack chain against Microsoft 365, see BEC in Microsoft 365. For token-based attacks, see Token theft and session hijacking.
What changes with AI
| Attack phase | Before generative AI | With generative AI |
|---|---|---|
| Reconnaissance | Manual OSINT, hours per target. | LLM aggregates LinkedIn, commercial register and web presence in seconds into an attack profile. |
| Phishing content | Language errors, often clearly recognisable. | Flawless German, French, Italian, even Swiss German in the target organisation's tone. |
| Vishing / voice | Foreign accent, low success rate. | Voice cloning from seconds of sample audio, CFO voice in real time. |
| Malware development | Requires experienced developers. | Code LLMs generate loaders, obfuscation and living-off-the-land scripts on demand. |
| Target selection | Static lists, spray-and-pray. | Dynamic by role, language, visibility; highly selective spear campaigns at mass-campaign cost. |
What does not change
- The kill chain: initial access, persistence, lateral movement, exfiltration remain structurally the same. AI accelerates the existing steps.
- Detection logic: behaviour- and telemetry-based detection (EDR, NDR, identity signals) still works because the technical artefacts are identical.
- Response playbooks: session invalidation, password reset, endpoint isolation and forensic preservation remain unchanged in effect.
- Baseline hygiene: MFA (phishing-resistant), patching, least privilege remain the biggest lever; AI does not bypass a hard technical control.
Controls that rely on linguistic or emotional anomalies lose effectiveness, including awareness training focused on poor German and refusals based on gut feeling. Controls that rely on technical artefacts (unknown OAuth consent, impossible travel, unusual process chains) grow relatively more important. See [SOC as a Service Switzerland](/en/soc/soc-as-a-service-switzerland) and [Threat hunting in Switzerland](/en/soc/threat-hunting-switzerland).
Concrete attack patterns in the Swiss context
- CEO fraud with voice clone: a short voice message from the managing director in Swiss German urgently asks the CFO to release a payment. The sample comes from a public podcast interview.
- Supplier phishing against SMEs: an LLM generates an invoice in the actual supplier's layout, with correct Swiss IBAN prefixes and a plausible VAT line.
- Recruiting trap: a fake LinkedIn profile of a Swiss recruiter contacts developers and sends a PDF with an embedded loader. The text and profile are linguistically flawless.
- Deepfake video call against the board: a short Zoom call with a synthesised board member confirms an M&A payment.
- Automated application malware: a cover letter in the target language contains flawless text and accompanies a CV PDF that downloads macros. Generic malware detection struggles to identify it.
Common myths
- Myth: AI creates an entirely new class of attacks. Reality: the techniques are known; AI lowers the barrier to entry and raises quality.
- Myth: EDR and NDR cannot see AI-generated malware. Reality: detection is based on behaviour and telemetry, not on who wrote the code.
- Myth: Awareness training is obsolete. Reality: it must shift away from language tells toward process checks (four-eyes on payments, callback on a known number, OAuth reviews).
- Myth: You need special AI-detection tools. Reality: in most cases, existing detection and response chains cover the exploitation of AI-generated content, if operated correctly.
Priorities for Swiss organisations
- Phishing-resistant MFA (FIDO2, passkeys) on all privileged accounts, then broaden the rollout.
- Process controls for payments: four-eyes above a defined threshold, mandatory callback on a stored number, no releases via voice message.
- OAuth and app-consent governance in M365 and Google Workspace: consent review and alerting on new third-party apps.
- 24/7 detection and response: AI-accelerated attacks run outside business hours, see SOC 24/7 operations.
- Process-focused awareness: training must teach verification procedures and move beyond grammar recognition.
- Tabletop exercises with AI scenarios (voice-clone CFO, deepfake board call), so playbooks work under stress.
Frequently asked questions
Does AI fundamentally change the kill chain?
AI leaves the kill chain structurally unchanged, including initial access, persistence, lateral movement and exfiltration. AI accelerates and personalises individual steps while retaining existing techniques. Detection and response chains still work because they use telemetry independently of code authorship.
Does EDR detect AI-generated malware?
EDR detects AI-generated malware when it uses behaviour and telemetry. An LLM can vary syntax while retaining technical actions such as process injection, LSASS access and unusual PowerShell chains. Those signals persist. See [EDR vs MDR](/en/soc/soc-siem-edr-xdr-mdr-terms) and [What is EDR](/en/glossary/edr).
How realistic are deepfake voice attacks today?
Deepfake voice attacks are very realistic. A few seconds of audio sample are enough for a usable voice clone. Board members, executives and communications leads with public exposure (podcasts, interviews, conferences) are primary targets. Require callbacks on stored numbers and prohibit payment approvals via voice messages.
Do you need special anti-AI detection tools?
Most organisations do not need special anti-AI detection tools. Correctly operated standard detection (EDR, NDR, identity, email security) can cover the exploitation of AI-generated content. Prioritise investment in detection coverage and response speed over niche products. See [SOC provider comparison](/en/soc/soc-provider-comparison-checklist).
Does awareness training need a complete rethink?
Awareness training needs a change in focus. The old message of watching for poor language no longer holds. Training should focus on verification procedures (callbacks, two-person checks), OAuth consent reviews and handling voice or video calls outside established channels. See [Security awareness](/en/services/security-awareness-training).
Related terms
- Phishing Phishing is an attack that uses fake emails and messages to trick people into taking an action.
- BEC Business Email Compromise is a type of corporate fraud where attackers trick staff into making payments to accounts controlled by the attackers.
- Malware Malware is the umbrella term for malicious software such as ransomware, Trojans or infostealers that damage systems or steal data.
- CTI Cyber Threat Intelligence (CTI) provides processed information about attackers, their tools, and their objectives.