AI-driven cyber attacks: what changes, and what is marketing

Generative AI changes cyber attacks in scale, language quality and personalisation. The underlying techniques remain unchanged. Phishing in flawless Swiss German, deepfake vishing against the finance team, auto-generated malware code and LLM-driven reconnaissance are today's reality. The kill chain, detection logic and the importance of fast response remain unchanged. Attack volume, quality and the ability to bypass security controls based on linguistic or behavioural anomalies are changing.

All

Scope: attack side, not defence side

This page covers how attackers use AI. AI in the SOC explains how a SOC uses AI defensively for triage, correlation, automation and analyst assistance. For the specific attack chain against Microsoft 365, see BEC in Microsoft 365. For token-based attacks, see Token theft and session hijacking.

What changes with AI

Attack phaseBefore generative AIWith generative AI
ReconnaissanceManual OSINT, hours per target.LLM aggregates LinkedIn, commercial register and web presence in seconds into an attack profile.
Phishing contentLanguage errors, often clearly recognisable.Flawless German, French, Italian, even Swiss German in the target organisation's tone.
Vishing / voiceForeign accent, low success rate.Voice cloning from seconds of sample audio, CFO voice in real time.
Malware developmentRequires experienced developers.Code LLMs generate loaders, obfuscation and living-off-the-land scripts on demand.
Target selectionStatic lists, spray-and-pray.Dynamic by role, language, visibility; highly selective spear campaigns at mass-campaign cost.

What does not change

  • The kill chain: initial access, persistence, lateral movement, exfiltration remain structurally the same. AI accelerates the existing steps.
  • Detection logic: behaviour- and telemetry-based detection (EDR, NDR, identity signals) still works because the technical artefacts are identical.
  • Response playbooks: session invalidation, password reset, endpoint isolation and forensic preservation remain unchanged in effect.
  • Baseline hygiene: MFA (phishing-resistant), patching, least privilege remain the biggest lever; AI does not bypass a hard technical control.
What this means for defence

Controls that rely on linguistic or emotional anomalies lose effectiveness, including awareness training focused on poor German and refusals based on gut feeling. Controls that rely on technical artefacts (unknown OAuth consent, impossible travel, unusual process chains) grow relatively more important. See [SOC as a Service Switzerland](/en/soc/soc-as-a-service-switzerland) and [Threat hunting in Switzerland](/en/soc/threat-hunting-switzerland).

Concrete attack patterns in the Swiss context

  • CEO fraud with voice clone: a short voice message from the managing director in Swiss German urgently asks the CFO to release a payment. The sample comes from a public podcast interview.
  • Supplier phishing against SMEs: an LLM generates an invoice in the actual supplier's layout, with correct Swiss IBAN prefixes and a plausible VAT line.
  • Recruiting trap: a fake LinkedIn profile of a Swiss recruiter contacts developers and sends a PDF with an embedded loader. The text and profile are linguistically flawless.
  • Deepfake video call against the board: a short Zoom call with a synthesised board member confirms an M&A payment.
  • Automated application malware: a cover letter in the target language contains flawless text and accompanies a CV PDF that downloads macros. Generic malware detection struggles to identify it.

Common myths

  • Myth: AI creates an entirely new class of attacks. Reality: the techniques are known; AI lowers the barrier to entry and raises quality.
  • Myth: EDR and NDR cannot see AI-generated malware. Reality: detection is based on behaviour and telemetry, not on who wrote the code.
  • Myth: Awareness training is obsolete. Reality: it must shift away from language tells toward process checks (four-eyes on payments, callback on a known number, OAuth reviews).
  • Myth: You need special AI-detection tools. Reality: in most cases, existing detection and response chains cover the exploitation of AI-generated content, if operated correctly.

Priorities for Swiss organisations

  1. Phishing-resistant MFA (FIDO2, passkeys) on all privileged accounts, then broaden the rollout.
  2. Process controls for payments: four-eyes above a defined threshold, mandatory callback on a stored number, no releases via voice message.
  3. OAuth and app-consent governance in M365 and Google Workspace: consent review and alerting on new third-party apps.
  4. 24/7 detection and response: AI-accelerated attacks run outside business hours, see SOC 24/7 operations.
  5. Process-focused awareness: training must teach verification procedures and move beyond grammar recognition.
  6. Tabletop exercises with AI scenarios (voice-clone CFO, deepfake board call), so playbooks work under stress.

Frequently asked questions

Does AI fundamentally change the kill chain?

AI leaves the kill chain structurally unchanged, including initial access, persistence, lateral movement and exfiltration. AI accelerates and personalises individual steps while retaining existing techniques. Detection and response chains still work because they use telemetry independently of code authorship.

Does EDR detect AI-generated malware?

EDR detects AI-generated malware when it uses behaviour and telemetry. An LLM can vary syntax while retaining technical actions such as process injection, LSASS access and unusual PowerShell chains. Those signals persist. See [EDR vs MDR](/en/soc/soc-siem-edr-xdr-mdr-terms) and [What is EDR](/en/glossary/edr).

How realistic are deepfake voice attacks today?

Deepfake voice attacks are very realistic. A few seconds of audio sample are enough for a usable voice clone. Board members, executives and communications leads with public exposure (podcasts, interviews, conferences) are primary targets. Require callbacks on stored numbers and prohibit payment approvals via voice messages.

Do you need special anti-AI detection tools?

Most organisations do not need special anti-AI detection tools. Correctly operated standard detection (EDR, NDR, identity, email security) can cover the exploitation of AI-generated content. Prioritise investment in detection coverage and response speed over niche products. See [SOC provider comparison](/en/soc/soc-provider-comparison-checklist).

Does awareness training need a complete rethink?

Awareness training needs a change in focus. The old message of watching for poor language no longer holds. Training should focus on verification procedures (callbacks, two-person checks), OAuth consent reviews and handling voice or video calls outside established channels. See [Security awareness](/en/services/security-awareness-training).

Continue reading in this cluster
Detecting and stopping Business Email Compromise in Microsoft 365
Business Email Compromise (BEC) in Microsoft 365 rarely involves malware. The attack chain involves phishing, session or token theft, inbox rules and OAuth consent abuse. A SOC detects BEC by correlating signals from Entra ID, Exchange Online and Defender for Cloud Apps. The email body alone is insufficient for detection. Responders revoke sessions, remove inbox rules, withdraw OAuth consents and enforce MFA again. They document these actions in line with ISG and insurance requirements.
Detecting and stopping token theft and session hijacking
Token theft means attackers steal the session or refresh token of an already authenticated user and use it to bypass MFA. The classic path is reverse-proxy phishing (adversary-in-the-middle), increasingly also endpoint info-stealers. A SOC detects this from token usage outside the user context, not from the login itself. Defence means phishing-resistant MFA, Continuous Access Evaluation, token binding and detection on refresh-token replay.
Threat hunting in Switzerland: when detection rules stop being enough
Threat hunting is the hypothesis-driven search for adversaries that slip past existing detection rules. It complements SIEM and EDR alerts, it does not replace them. The goal is to structurally reduce how long adversaries stay undetected; Mandiant M-Trends 2026 reports a median of 14 days. Analysts actively search for tactics, techniques and procedures (TTPs) before an alert fires.
Security awareness training: turning click risk into reporting behaviour
Security awareness training is a measurable behavioural process, beyond a mandatory e-learning module. The target is not a zero click rate but a reporting rate for suspicious mail in the 40 to 50 percent target band before the SOC escalates. ANOMAL combines short role-specific modules, realistic phishing simulations and a reporting interface in Microsoft 365 so awareness becomes a detection source. The 'Regular security awareness training with phishing simulations' requirement of most Swiss cyber insurers is documented in the process.
SOC as a Service in Switzerland: The Complete Guide
SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.