{"id":15373,"date":"2026-09-17T17:52:39","date_gmt":"2026-09-17T12:22:39","guid":{"rendered":"https:\/\/threatcop.com\/blog\/?p=15373"},"modified":"2026-09-17T17:52:41","modified_gmt":"2026-09-17T12:22:41","slug":"ai-to-defend-against-ai-attacks","status":"publish","type":"post","link":"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/","title":{"rendered":"Using AI to Defend Against AI Attacks: What Actually Works"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">AI now sits inside live malware, not just in the tooling that builds it. Defending against that needs AI in some places and conventional controls in others. The highest-leverage counter to runtime-LLM malware is egress policy and endpoint telemetry, because the malware must reach an outside model to function at all.<\/p><div id=\"ez-toc-container\" class=\"ez-toc-v2_0_87 ez-toc-wrap-center counter-hierarchy ez-toc-counter ez-toc-light-blue ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #414141;color:#414141\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #414141;color:#414141\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#What_AI_Versus_AI_Actually_Means_Right_Now\" >What AI Versus AI Actually Means Right Now<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#What_AI-Enabled_Malware_Looks_Like_in_the_Wild\" >What AI-Enabled Malware Looks Like in the Wild<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#Book_a_Free_Demo_Call_with_Our_Expert\" >Book a Free Demo Call with Our Expert<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#Why_Speed_Is_the_Real_Change\" >Why Speed Is the Real Change<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#Where_AI_Genuinely_Beats_Traditional_Defence\" >Where AI Genuinely Beats Traditional Defence<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#What_Vendors_Mean_by_AI_and_Why_It_Matters\" >What Vendors Mean by AI, and Why It Matters<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#Where_the_AI-for-Defence_Argument_Falls_Apart\" >Where the AI-for-Defence Argument Falls Apart<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#The_Controls_You_Own_Versus_the_Controls_You_Borrow\" >The Controls You Own Versus the Controls You Borrow<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#Egress_Policy_Is_the_Cheapest_Counter_Available\" >Egress Policy Is the Cheapest Counter Available<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#Detection_Engineering_for_Malware_That_Calls_a_Model\" >Detection Engineering for Malware That Calls a Model<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#Where_AI_Attacks_the_Supply_Chain_Instead\" >Where AI Attacks the Supply Chain Instead<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#Attacks_Against_Your_AI_Tools_Are_the_Other_Half\" >Attacks Against Your AI Tools Are the Other Half<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#Why_the_Human_Layer_Gets_Harder_Not_Easier\" >Why the Human Layer Gets Harder, Not Easier<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#A_Framework_for_Where_to_Spend_on_AI_Defence\" >A Framework for Where to Spend on AI Defence<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#A_30-Day_Plan_to_Close_the_Egress_Gap\" >A 30-Day Plan to Close the Egress Gap<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-16\" href=\"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#What_to_Measure_Once_You_Have_Bought_Something\" >What to Measure Once You Have Bought Something<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-17\" href=\"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#Start_With_the_List_of_Hosts_That_May_Call_a_Model\" >Start With the List of Hosts That May Call a Model<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-18\" href=\"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#Frequently_Asked_Questions\" >Frequently Asked Questions<\/a><\/li><\/ul><\/nav><\/div>\n\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_AI_Versus_AI_Actually_Means_Right_Now\"><\/span>What AI Versus AI Actually Means Right Now<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The phrase covers two different things, and treating them as one produces bad buying decisions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">First, attackers use AI as a workbench. They draft phishing copy, write code, translate lures, and research targets faster. That has been happening for years, and it scales an attacker&#8217;s output rather than changing what the attack does.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second is newer and stranger. Malware now calls a large language model while it runs, generating its commands or rewriting itself mid-execution. Google&#8217;s <a href=\"https:\/\/services.google.com\/fh\/files\/misc\/advances-in-threat-actor-usage-of-ai-tools-en.pdf\" target=\"_blank\" rel=\"nofollow noopener\">Threat Intelligence Group<\/a> recorded the first live-operations sighting in November 2025. The distinction matters, because the second category leaves a signature the first never did: an outbound call to a model API from a machine that has no business making one.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Most writing on this subject argues that you need AI to fight AI. That is partly right. It is also the least actionable half of the answer, and it skips the controls you already own, which is the pattern set out in <a href=\"https:\/\/threatcop.com\/blog\/future-of-cybersecurity\/\">how automation is reshaping defence<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_AI-Enabled_Malware_Looks_Like_in_the_Wild\"><\/span>What AI-Enabled Malware Looks Like in the Wild<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Named families give the argument something concrete to sit on. Google&#8217;s Threat Intelligence Group documented several through late 2025 and 2026.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Family<\/strong><\/th><th><strong>What it does<\/strong><\/th><th><strong>Status<\/strong><\/th><\/tr><\/thead><tbody><tr><td>PROMPTSTEAL<\/td><td>Python data miner used by APT28 against Ukrainian targets. Queries Qwen2.5-Coder-32B-Instruct through the Hugging Face API to generate one-line Windows commands at runtime<\/td><td>Live operations<\/td><\/tr><tr><td>PROMPTFLUX<\/td><td>VBScript dropper that calls the Gemini API to rewrite its own source for just-in-time self-modification, and spreads through removable drives and the Startup folder<\/td><td>Development or testing<\/td><\/tr><tr><td>QUIETVAULT<\/td><td>JavaScript credential stealer targeting GitHub and NPM tokens. Uses AI prompts and AI CLI tools already installed on the host to hunt for further secrets before exfiltrating them<\/td><td>Observed in the wild<\/td><\/tr><tr><td>FRUITSHELL<\/td><td>PowerShell reverse shell that establishes command-and-control connections. Carries hard-coded prompts intended to evade LLM-based security analysis<\/td><td>Publicly available<\/td><\/tr><tr><td>PROMPTLOCK<\/td><td>Go ransomware that uses an LLM to generate and execute malicious Lua scripts at runtime for reconnaissance, encryption, and exfiltration<\/td><td>Proof of concept<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Read that table carefully before reacting to it. PROMPTSTEAL is the one Google describes as its first observation of malware querying a model in live operations, and QUIETVAULT was also seen in the wild. PROMPTFLUX, by contrast, was assessed as still under development, lacking any means to compromise a victim network or device, and PROMPTLOCK originated as research rather than as a criminal tool.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So the honest framing is that PROMPTFLUX previews a technique and PROMPTSTEAL proves it works. Neither justifies panic. Both justify checking whether your detection stack would notice a process on a finance workstation calling a model API.<\/p>\n\n\n\n<meta charset=\"UTF-8\">\n<meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n<title>Threatcop \u2013 Book a Free Demo<\/title>\n<link href=\"https:\/\/fonts.googleapis.com\/css2?family=Outfit:wght@300;400;500;600;700&#038;display=swap\" rel=\"stylesheet\">\n<style>\n  .tc-wrap , .tc-wrap ::before, .tc-wrap ::after { box-sizing: border-box; margin: 0; padding: 0; }\n  .tc-wrap { font-family: 'Outfit', sans-serif; width: 100%; display: flex; justify-content: center; padding: 20px 10px; }\n  .tc-card { width: 100%; max-width: 820px; background: #fff; border-radius: 20px; overflow: hidden; box-shadow: 0 20px 60px rgba(24,57,148,0.13), 0 4px 16px rgba(24,57,148,0.07); display: flex; flex-direction: row; }\n  .tc-left { background: linear-gradient(160deg, #1e44b0 0%, #183994 40%, #0e2570 100%); width: 320px; flex-shrink: 0; padding: 40px 32px; display: flex; flex-direction: column; justify-content: center; position: relative; overflow: hidden; }\n  .tc-left::before { content: ''; position: absolute; inset: 0; background-image: radial-gradient(rgba(255,255,255,0.08) 1.5px, transparent 1.5px); background-size: 22px 22px; }\n  .tc-left::after { content: ''; position: absolute; bottom: -60px; right: -60px; width: 220px; height: 220px; background: radial-gradient(circle, rgba(99,179,255,0.22) 0%, transparent 65%); border-radius: 50%; pointer-events: none; }\n  .tc-panel-inner { position: relative; z-index: 1; }\n  .tc-badge { display: inline-flex !important; align-items: center !important; gap: 6px; background: rgba(255,255,255,0.1) !important; border: 1px solid rgba(255,255,255,0.18) !important; border-radius: 20px !important; padding: 4px 14px 4px 10px !important; font-size: 12.5px !important; font-weight: 600 !important; letter-spacing: .09em !important; text-transform: uppercase !important; color: rgba(255,255,255,0.85) !important; margin-bottom: 18px !important; font-family: 'Outfit', sans-serif !important; line-height: 1.4 !important; }\n  .tc-badge-dot { width: 6px; height: 6px; background: #5cd9a0; border-radius: 50%; box-shadow: 0 0 6px #5cd9a0; flex-shrink: 0; display: inline-block; }\n  .tc-left h1, .tc-left h2, .tc-left h3, .tc-left h4, .tc-left h5, .tc-left h6 { color: #ffffff !important; font-family: 'Outfit', sans-serif !important; font-size: 28px !important; font-weight: 700 !important; line-height: 1.35 !important; letter-spacing: -0.3px !important; margin: 0 !important; padding: 0 !important; background: none !important; -webkit-text-fill-color: #ffffff !important; }\n  .tc-left h2 em { font-style: normal !important; color: #7ec8ff !important; -webkit-text-fill-color: #7ec8ff !important; }\n  .tc-left p, .tc-left .tc-sub { color: rgba(255,255,255,0.78) !important; -webkit-text-fill-color: rgba(255,255,255,0.78) !important; font-family: 'Outfit', sans-serif !important; font-size: 14px !important; font-weight: 300 !important; line-height: 1.65 !important; margin-top: 12px !important; background: none !important; }\n  .tc-right { flex: 1; padding: 32px 32px 28px; display: flex; flex-direction: column; justify-content: center; }\n  .tc-form-title { font-size: 13px !important; font-weight: 600 !important; letter-spacing: .12em; text-transform: uppercase; color: #8fa4cc !important; margin-bottom: 20px !important; display: flex !important; align-items: center !important; gap: 10px; font-family: 'Outfit', sans-serif !important; }\n  .tc-form-title::after { content: ''; flex: 1; height: 1px; background: #eef1fa; }\n  .tc-grid { display: grid; grid-template-columns: 1fr 1fr; gap: 14px; }\n  .tc-field { display: flex; flex-direction: column; gap: 5px; }\n  .tc-field.full { grid-column: 1 \/ -1; }\n  .tc-field label { font-size: 13px !important; font-weight: 600 !important; color: #3a4f7a !important; letter-spacing: .04em; text-transform: uppercase; font-family: 'Outfit', sans-serif !important; display: block !important; }\n  .tc-input-wrap { position: relative; display: flex; align-items: center; }\n  .tc-input-wrap .tc-fi { position: absolute; right: 12px; width: 15px; height: 15px; stroke: #c0ccdf; stroke-width: 1.8; pointer-events: none; fill: none; }\n  .tc-wrap input[type=\"text\"], .tc-wrap input[type=\"email\"], .tc-wrap input[type=\"number\"] { width: 100% !important; border: 1.5px solid #e2e9f7 !important; border-radius: 10px !important; padding: 9px 34px 9px 13px !important; font-family: 'Outfit', sans-serif !important; font-size: 15px !important; font-weight: 400 !important; color: #1e2d50 !important; background: #f8faff !important; outline: none !important; transition: border-color .2s, background .2s, box-shadow .2s; -moz-appearance: textfield; box-shadow: none !important; -webkit-text-fill-color: #1e2d50 !important; }\n  .tc-wrap input[type=\"number\"]::-webkit-inner-spin-button, .tc-wrap input[type=\"number\"]::-webkit-outer-spin-button { -webkit-appearance: none; }\n  .tc-wrap input::placeholder { color: #c0ccdf !important; -webkit-text-fill-color: #c0ccdf !important; opacity: 1; }\n  .tc-wrap input:focus { border-color: #183994 !important; background: #fff !important; box-shadow: 0 0 0 3.5px rgba(24,57,148,0.1) !important; }\n  .tc-phone-row { display: flex; gap: 8px; }\n  .tc-flag-select { position: relative; flex-shrink: 0; }\n  .tc-flag-select select { appearance: none !important; -webkit-appearance: none !important; border: 1.5px solid #e2e9f7 !important; border-radius: 10px !important; padding: 9px 26px 9px 12px !important; font-family: 'Outfit', sans-serif !important; font-size: 14px !important; font-weight: 500 !important; color: #1e2d50 !important; background: #f8faff !important; outline: none !important; cursor: pointer; width: 100px !important; transition: border-color .2s, box-shadow .2s; }\n  .tc-flag-select select:focus { border-color: #183994 !important; box-shadow: 0 0 0 3.5px rgba(24,57,148,0.1) !important; }\n  .tc-flag-select::after { content: ''; position: absolute; right: 10px; top: 50%; transform: translateY(-50%); width: 0; height: 0; border-left: 4px solid transparent; border-right: 4px solid transparent; border-top: 5px solid #a0b0cc; pointer-events: none; }\n  .tc-phone-row .tc-input-wrap { flex: 1; }\n  .tc-btn-submit { width: 100% !important; margin-top: 18px !important; padding: 11px !important; background: #183994 !important; border: none !important; border-radius: 10px !important; color: #fff !important; -webkit-text-fill-color: #fff !important; font-family: 'Outfit', sans-serif !important; font-size: 15px !important; font-weight: 600 !important; letter-spacing: .05em; cursor: pointer; display: flex !important; align-items: center !important; justify-content: center !important; gap: 9px; transition: background .2s, transform .15s, box-shadow .2s; box-shadow: 0 6px 24px rgba(24,57,148,0.28) !important; text-decoration: none !important; }\n  .tc-btn-submit:hover { background: #1d46b5 !important; transform: translateY(-1px); box-shadow: 0 10px 32px rgba(24,57,148,0.35) !important; color: #fff !important; }\n  .tc-btn-submit:active { transform: translateY(0); }\n  .tc-btn-submit svg { width: 16px; height: 16px; stroke: #fff; stroke-width: 2.2; fill: none; flex-shrink: 0; }\n  .tc-trust { margin-top: 10px !important; display: flex !important; align-items: center !important; justify-content: center !important; gap: 5px; font-size: 13px !important; color: #a0b0cc !important; font-family: 'Outfit', sans-serif !important; }\n  .tc-trust svg { width: 12px; height: 12px; stroke: #a0b0cc; stroke-width: 2; fill: none; flex-shrink: 0; }\n  @media (max-width: 680px) {\n    .tc-card { flex-direction: column !important; }\n    .tc-left { width: 100% !important; padding: 28px 24px 24px !important; }\n    .tc-right { padding: 24px 20px !important; }\n    .tc-grid { grid-template-columns: 1fr !important; }\n    .tc-field.full { grid-column: 1 !important; }\n  }\n<\/style>\n\n<div class=\"tc-wrap\">\n  <div class=\"tc-card\">\n    <div class=\"tc-left\">\n      <div class=\"tc-panel-inner\">\n        <div class=\"tc-badge\">\n          <span class=\"tc-badge-dot\"><\/span>\n          People Security Management\n        <\/div>\n        <h2><span class=\"ez-toc-section\" id=\"Book_a_Free_Demo_Call_with_Our_Expert\"><\/span>Book a Free<br><em>Demo Call<\/em><br>with Our Expert<span class=\"ez-toc-section-end\"><\/span><\/h2>\n        <p class=\"tc-sub\">Discover how Threatcop protects your workforce from modern cyber threats.<\/p>\n      <\/div>\n    <\/div>\n    <div class=\"tc-right\">\n      <div class=\"tc-form-title\">Your Details<\/div>\n      <form action=\"https:\/\/threatcop.com\/thankyou-blog\" method=\"get\" target=\"_blank\">\n        <input type=\"hidden\" name=\"BlogForm\" value=\"BlogForm\">\n        <input type=\"hidden\" name=\"PageSource\" id=\"tc-page-source\" value=\"\">\n        <div class=\"tc-grid\">\n          <div class=\"tc-field\">\n            <label>Full Name<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"text\" name=\"FullName\" placeholder=\"Jane Smith\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><circle cx=\"12\" cy=\"8\" r=\"4\"><\/circle><path d=\"M4 20c0-4 3.58-7 8-7s8 3 8 7\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field\">\n            <label>Company Name<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"text\" name=\"CompanyName\" placeholder=\"Acme Corp\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"3\" y=\"3\" width=\"18\" height=\"18\" rx=\"2\"><\/rect><path d=\"M9 3v18M3 9h6M3 15h6\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field full\">\n            <label>Corporate Email<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"email\" name=\"email\" placeholder=\"jane@yourcompany.com\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"2\" y=\"4\" width=\"20\" height=\"16\" rx=\"2\"><\/rect><polyline points=\"2,4 12,13 22,4\"><\/polyline><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field full\">\n            <label>Phone Number<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"number\" name=\"Phone\" placeholder=\"98765 43210\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><path d=\"M22 16.92v3a2 2 0 01-2.18 2A19.79 19.79 0 013.09 4.18 2 2 0 015.07 2h3a2 2 0 012 1.72c.13.96.36 1.9.71 2.81a2 2 0 01-.45 2.11L9.09 9.91a16 16 0 006 6l1.27-1.27a2 2 0 012.11-.45c.91.35 1.85.58 2.81.71A2 2 0 0122 16.92z\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n        <\/div>\n        <button type=\"submit\" class=\"tc-btn-submit\">\n          <svg viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><path d=\"M22 2L11 13M22 2L15 22l-4-9-9-4 20-7z\"><\/path><\/svg>\n          Book My Free Demo\n        <\/button>\n        <div class=\"tc-trust\">\n          <svg viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"3\" y=\"11\" width=\"18\" height=\"11\" rx=\"2\"><\/rect><path d=\"M7 11V7a5 5 0 0110 0v4\"><\/path><\/svg>\n          Your data is safe &amp; never shared with third parties\n        <\/div>\n      <\/form>\n    <\/div>\n  <\/div>\n<\/div>\n<script>document.getElementById('tc-page-source').value = window.location.href;<\/script>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_Speed_Is_the_Real_Change\"><\/span>Why Speed Is the Real Change<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Capability headlines get attention. Timing is what actually breaks defensive assumptions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Google&#8217;s Q2 2026 reporting describes adversaries moving from basic prompting to agentic workflows and automation. The consequence they name is specific: human-in-the-loop latency drops sharply, which compresses the window defenders have to respond.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One observed sequence makes that concrete. Threat actors compromised a cloud resource, then planned, built, and executed an agent-enabled mass credential harvesting campaign in under six hours.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Six hours is shorter than many organizations&#8217; escalation path. It is shorter than a weekend. It is considerably shorter than the time between a suspicious alert and a human deciding it matters. Therefore the argument for automation on the defensive side is not that AI is clever. It is that a six-hour attack cannot be met by a process measured in days.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Where_AI_Genuinely_Beats_Traditional_Defence\"><\/span>Where AI Genuinely Beats Traditional Defence<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Four areas hold up under scrutiny, and they share a trait: high volume, low ambiguity, and a clear ground truth.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Alert triage.<\/strong> Sorting thousands of alerts by likely severity, and suppressing the ones that match known benign patterns<\/li>\n\n\n\n<li><strong>Correlation across sources.<\/strong> Linking an endpoint event to an identity event to a network event faster than an analyst switching consoles<\/li>\n\n\n\n<li><strong>Anomaly detection in volume data.<\/strong> Spotting the outbound pattern that does not match a host&#8217;s history<\/li>\n\n\n\n<li><strong>Drafting and summarising.<\/strong> Turning a messy incident timeline into something a human can read at speed<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Each of those replaces work a person did badly because there was too much of it, not work a person did well. That is the useful test for any AI security purchase. Wider context sits in <a href=\"https:\/\/threatcop.com\/blog\/affects-of-ai-in-cybersecurity\/\">how AI is reshaping cybersecurity<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Vendors_Mean_by_AI_and_Why_It_Matters\"><\/span>What Vendors Mean by AI, and Why It Matters<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;AI-powered&#8221; covers at least three different technologies on a product page. Knowing which one you are buying decides what you can expect from it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Classical machine learning came first and still does most of the work. A model trained on labelled examples scores new events against learned patterns. It is fast, cheap to run, and explainable enough to tune. Spam filtering and malware classification largely run on this, and it has been shipping for over a decade.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Large language models arrived next in the stack. They read unstructured text, so they summarise incidents, explain alerts in plain language, and judge whether a message reads like a pretext. They are slower, more expensive per event, and harder to audit when they get one wrong.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Agentic response is the newest and least proven. Here the system decides and acts, isolating a host or disabling an account without waiting for a person. Speed is the benefit. The risk is an automated action taken on a false positive, at machine scale, against production.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ask any vendor which of the three they mean, and ask what happens when it is wrong. A classifier that misfires generates an alert somebody ignores. An agent that misfires takes your payroll system offline on a Friday afternoon.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The sequencing follows from that. Buy the classifier layer, then the language layer for triage, and treat autonomous response as something you pilot with tight scope rather than switch on across the estate.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Where_the_AI-for-Defence_Argument_Falls_Apart\"><\/span>Where the AI-for-Defence Argument Falls Apart<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The claim gets weaker in three specific places, and vendors rarely mark them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ground truth is the first. Detection models learn from labelled data, and novel attacks have no labels yet. A model trained on last year&#8217;s campaigns recognises last year&#8217;s campaigns, which is the same structural problem that limits signature matching.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Explainability is the second. When an analyst cannot establish why a system scored a message as benign, they cannot fix the miss. Opacity turns every false negative into a mystery rather than a lesson.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">False positives are the third, and they are more expensive than they look. Alerts that prove wrong train people to dismiss alerts, which quietly degrades the human layer you still depend on.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">None of that argues against buying AI defences. It argues for buying them where ground truth exists, and for not expecting them to cover the novel case that made you nervous in the first place.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_Controls_You_Own_Versus_the_Controls_You_Borrow\"><\/span>The Controls You Own Versus the Controls You Borrow<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">One distinction reorganises the whole question of AI defence. Some controls belong to you. Others belong to a vendor and merely benefit you.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Model guardrails belong to the vendor. They are genuinely useful, and they are something an attacker works to bypass rather than something you operate. Google documented exactly that: an actor whose prompt was refused reframed the request as a capture-the-flag exercise, and the model then returned information that could be used to exploit the system. The actor reused the same pretext for phishing, exploitation, and web shell development.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That episode is worth holding onto. A safety layer you do not control, running on infrastructure you do not own, is not a defence you can point to in an audit.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The controls you own are ordinary: egress policy, endpoint telemetry, identity, and detection engineering. They are also the ones that work against runtime-LLM malware, for a reason covered next.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Egress_Policy_Is_the_Cheapest_Counter_Available\"><\/span>Egress Policy Is the Cheapest Counter Available<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Malware that queries a model at runtime has a hard dependency. It must reach that model over the network. Cut the path and the technique fails, regardless of how sophisticated the generation step is.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That gives defenders something unusual: a choke point that does not require predicting the payload. PROMPTSTEAL reaches Hugging Face. PROMPTFLUX reaches the Gemini API. Both calls originate from a process that has no legitimate reason to talk to a model provider.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Practical steps follow directly.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Inventory which hosts legitimately call model APIs.<\/strong> In most companies the list is short, and it is developers.<\/li>\n\n\n\n<li><strong>Default-deny outbound access to model providers<\/strong> from everything not on that list, starting with servers and finance workstations.<\/li>\n\n\n\n<li><strong>Force approved traffic through a proxy<\/strong> so calls are attributable to a host and a user.<\/li>\n\n\n\n<li><strong>Alert on first-time model API contact<\/strong> from any host, which is a cheap and high-signal rule.<\/li>\n\n\n\n<li><strong>Watch for API keys in unexpected places<\/strong>, since runtime-LLM malware must carry credentials to call a hosted model.<\/li>\n\n\n\n<li><strong>Test the path deliberately<\/strong>, because if your threat model now includes payloads generated at runtime, your validation should exercise that route.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Step 4 alone catches the documented families. It costs a detection rule rather than a licence.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Detection_Engineering_for_Malware_That_Calls_a_Model\"><\/span>Detection Engineering for Malware That Calls a Model<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Beyond egress, several behavioural signals distinguish this class from ordinary malware.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Self-modifying files are one. PROMPTFLUX rewrites its own source on an hourly cadence, which produces a file whose hash changes while its location and purpose stay constant. Hash-based controls miss that. File-integrity monitoring on script directories does not.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Persistence is another, and it is entirely conventional. PROMPTFLUX copies itself to removable drives and the Startup folder, which detection has handled for two decades.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Interpreter behaviour matters too. Python packaged with PyInstaller, or VBScript making outbound HTTPS calls, is unusual on a workstation that does no development. Combined with a model API destination, it is close to conclusive.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Emulation should catch up as well. If the adversary in your threat model generates payloads at runtime and reaches an external model to do it, your purple team exercises should include that path rather than stopping at file-based payloads.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Where_AI_Attacks_the_Supply_Chain_Instead\"><\/span>Where AI Attacks the Supply Chain Instead<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Not every AI-enabled attack targets your endpoints. Some target the tools your developers trust.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Google tracked an actor, UNC6780, using multiple tactics to trick AI coding assistants and LLM security scanners into open-source software supply chain compromises. The target was not a person. It was the automated reviewer that a person relies on.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That inverts a common assumption. Teams adopt AI code review to catch what humans miss, then treat its approval as assurance. An attacker who can manipulate the reviewer gets a compromise signed off by the control that was supposed to prevent it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The defensive answer is unglamorous: treat AI review as one signal, keep human review for dependency changes and build scripts, and pin and verify what you pull. Supply chain exposure of this kind is examined in <a href=\"https:\/\/threatcop.com\/blog\/third-party-data-breaches\/\">third-party breaches reaching brands through vendors<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Attacks_Against_Your_AI_Tools_Are_the_Other_Half\"><\/span>Attacks Against Your AI Tools Are the Other Half<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Two categories of AI risk exist, and they need separate budgets. One is attackers using AI against you. Another is attackers going after the AI you already use.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That second category is growing faster, because adoption outpaced controls. Any model your company runs is an input surface. An agent connected to a tool becomes an authority surface. And an AI code reviewer is a decision surface that an attacker would like to influence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Prompt injection drives most of it. Models read instructions and data through one channel, so they cannot tell a document&#8217;s contents from a command. Hostile text inside a web page, a PDF, an email, or a code comment can redirect the model that processes it. OWASP has ranked prompt injection first in its Top 10 for LLM Applications across consecutive editions for exactly this reason.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Excessive agency compounds it. OWASP moved that risk from sixth place in its 2025 list to third in the 2026 edition, reflecting how much real authority agents now hold. Injection gets an attacker in. Permissions decide what they reach.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The practical consequence is that AI defence spending splits in two. Money spent detecting AI-enabled attacks does nothing to protect the agents in your own environment, and money spent hardening agents does nothing about runtime LLM malware on an endpoint. Confusing the two produces a budget that covers neither properly.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_the_Human_Layer_Gets_Harder_Not_Easier\"><\/span>Why the Human Layer Gets Harder, Not Easier<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">AI-enabled attacks change what employees see. The tells that awareness training taught for a decade are the tells automation removed first.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Bad grammar is gone. Generic salutations are gone. Mismatched branding is gone, and Google&#8217;s June 2026 disruption of a China-based service providing phishing kits for mass brand impersonation shows the industrial version of that. The operators used Gemini to generate code and run campaigns at scale, and Google pursued legal action over the misuse, the first time it has done so.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Consequently recognition training built on surface flaws is depreciating fast. What survives is procedural: verify unexpected requests through a second channel, never act on an instruction that arrives with urgency attached, and report rather than resolve.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Threatcop&#8217;s TLMS delivers that as role-based scenarios rather than one annual module, so the finance team practises the callback and developers practise questioning an approving tool. Programme design for this sits in <a href=\"https:\/\/threatcop.com\/blog\/role-based-security-awareness-training\/\">role-based training matched to job function<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"A_Framework_for_Where_to_Spend_on_AI_Defence\"><\/span>A Framework for Where to Spend on AI Defence<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Use the table rather than the vendor&#8217;s demo. The question in each row is whether ground truth exists and whether speed is the binding constraint.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Defensive job<\/strong><\/th><th><strong>Buy AI?<\/strong><\/th><th><strong>Why<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Alert triage at volume<\/td><td>Yes<\/td><td>Clear ground truth, and humans fail on volume rather than judgment<\/td><\/tr><tr><td>Cross-source correlation<\/td><td>Yes<\/td><td>Speed is the constraint, and the data is structured<\/td><\/tr><tr><td>Outbound egress control<\/td><td>No<\/td><td>A policy decision and a firewall rule already solve it<\/td><\/tr><tr><td>Detecting novel attack classes<\/td><td>Cautiously<\/td><td>No labels exist yet, so expect partial coverage<\/td><\/tr><tr><td>Phishing content detection<\/td><td>Partly<\/td><td>Helps with volume, misses payload-free requests entirely<\/td><\/tr><tr><td>Deciding what an agent may access<\/td><td>No<\/td><td>A permissions question, not a detection question<\/td><\/tr><tr><td>Workforce recognition of pretexts<\/td><td>No<\/td><td>AI cannot make the decision a person makes under pressure<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Two rows say no for the same reason. Some problems look like detection problems and are actually configuration or authority problems, and no model fixes those.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"A_30-Day_Plan_to_Close_the_Egress_Gap\"><\/span>A 30-Day Plan to Close the Egress Gap<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">None of the AI defence work above requires a procurement cycle. This sequence fits in a month, and it closes the gap the documented malware families depend on.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Week 1.<\/strong> Pull outbound traffic logs and identify every host that contacted a model API provider in the last 90 days. Sort by whether the contact makes sense. Most companies find calls from machines nobody expected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Week 2.<\/strong> Build the allowlist from that review, not from a theory of who should need access. Then write the default-deny policy for everything else, starting with servers, finance workstations, and shared terminals, where legitimate model use is rare.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Week 3.<\/strong> Deploy the first-contact alert. Any host reaching a model provider for the first time generates a single low-noise event. Tune it for a week and accept that developers will trigger it legitimately, since that is the point.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Week 4.<\/strong> Run the test. Have someone simulate the documented technique: a script on a non-developer host that calls a hosted model and acts on the response. Confirm the alert fires, confirm someone sees it, and confirm they know what to do.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Week 4 is the one people skip, and skipping it means you bought a rule rather than a detection. A control nobody has exercised is a control nobody can rely on during the six-hour window this whole post is about.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_to_Measure_Once_You_Have_Bought_Something\"><\/span>What to Measure Once You Have Bought Something<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Vendor metrics describe the product. These describe your position.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Hosts permitted to reach model APIs<\/strong>, which should be a short and shrinking list<\/li>\n\n\n\n<li><strong>Time from first anomalous model API call to analyst review<\/strong>, measured against that six-hour benchmark<\/li>\n\n\n\n<li><strong>Share of alerts closed by automation that a human later reopened<\/strong>, which exposes over-trust<\/li>\n\n\n\n<li><strong>Novel-technique coverage in purple team exercises<\/strong>, including runtime payload generation<\/li>\n\n\n\n<li><strong>Analyst dismissal rate on AI-generated alerts<\/strong>, which measures whether false positives are eroding attention<\/li>\n\n\n\n<li><strong>Reporting rate from employees<\/strong>, because it does not fall when attack quality rises unless training slipped<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The third and fifth are the ones to watch. Both measure whether your AI investment is quietly degrading the human layer it was meant to support.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Start_With_the_List_of_Hosts_That_May_Call_a_Model\"><\/span>Start With the List of Hosts That May Call a Model<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Before evaluating any AI security product, write down which machines in your environment have a legitimate reason to reach a model API. In most companies that list is short, and almost nothing on it is a server or a finance workstation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Then default-deny the rest and alert on first contact. That single rule counters the documented runtime-LLM malware families, costs a configuration change rather than a licence, and gives you a number you can show an auditor.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">After that, spend on AI where volume and speed genuinely beat human capacity, and <a href=\"https:\/\/threatcop.com\/cybersecurity-awareness\">keep training the people<\/a> who still have to judge the requests no model can score.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Frequently_Asked_Questions\"><\/span>Frequently Asked Questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\t\t<div class=\"sp-easy-accordion-block sp-eab-regular-accordion alignwide\"\n\t\t\t\t>\n\t\t\t<div class=\"sp-eab-wrapper sp-eab-vertical-accordion sp-eab-a18d6faf1f25\">\n\t\t\t\t\t\t\t\t<div class='sp-eab-accordion sp-eab-mode-vertical sp-eab-vertical-one sp-d-flex' data-accordion-settings=\"{&quot;mode&quot;:&quot;vertical&quot;,&quot;activeEvent&quot;:&quot;click&quot;,&quot;defaultAccordionOpen&quot;:&quot;first-item&quot;,&quot;selectedItemOpen&quot;:0,&quot;openMultiItemAtaTime&quot;:false,&quot;scrollToTopOnLoad&quot;:false,&quot;scrollToTopOnClick&quot;:false,&quot;accordionItemToUrl&quot;:false,&quot;animationEffect&quot;:false,&quot;applyAccessibility&quot;:true}\">\n        \t    \t\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-7d932c9f1dc8\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-af1f25\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-af1f25'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tDo you need AI to defend against AI attacks?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-af1f25'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Partly. AI genuinely helps where volume and speed are the constraints, such as alert triage and cross-source correlation, and where ground truth exists to train on. It helps far less against novel techniques with no labelled data. Against malware that calls a model at runtime, conventional egress policy and endpoint telemetry are more effective and considerably cheaper.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-3596ebbccbc2\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-af1f25\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-af1f25'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tWhat is AI-enabled malware?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-af1f25'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">AI-enabled malware queries a large language model while running, rather than being merely written with AI assistance. PROMPTSTEAL, used by APT28 against Ukrainian targets, queries a hosted model through the Hugging Face API to generate Windows commands at runtime. PROMPTFLUX calls the Gemini API to rewrite its own source code for just-in-time self-modification, though Google assessed it as still in development.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-045cdbf854d1\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-af1f25\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-af1f25'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tHow do you detect malware that uses an LLM?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-af1f25'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Watch outbound traffic to model API providers from hosts that have no reason to reach them, and alert on first-time contact. Add file-integrity monitoring to catch self-rewriting scripts whose hashes change while their location does not. Flag interpreters such as PyInstaller-packaged Python or VBScript making outbound HTTPS calls on non-developer machines.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-31b6d3841e9c\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-af1f25\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-af1f25'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tAre AI model guardrails a security control?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-af1f25'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Model guardrails help, and they are not a control you own. Google documented an actor whose request was refused, who then reframed it as a capture-the-flag exercise and received usable exploitation information. A safety layer running on infrastructure you do not operate cannot be evidenced in an audit or tuned to your environment, so treat it as a vendor benefit rather than a defence.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-df662ecfae3d\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-af1f25\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-af1f25'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tHow fast are AI-enabled attacks?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-af1f25'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Faster than most escalation processes. Google&#8217;s Threat Intelligence Group observed adversaries compromise a cloud resource and then plan, build, and execute an agent-enabled mass credential harvesting campaign in under six hours. The reported effect is a sharp reduction in human-in-the-loop latency on the attacker&#8217;s side, which compresses the defender&#8217;s window to respond.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>AI now runs inside live malware. See where AI defence genuinely helps, where egress policy beats it, and a 30-day plan that needs no procurement cycle.<\/p>\n","protected":false},"author":27,"featured_media":15390,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[424],"tags":[],"class_list":["post-15373","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Using AI to Defend Against AI Attacks: What Works<\/title>\n<meta name=\"description\" content=\"AI now runs inside live malware. See where AI defence genuinely helps, where egress policy beats it, and how to detect malware that calls a model at runtime.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Using AI to Defend Against AI Attacks: What Works\" \/>\n<meta property=\"og:description\" content=\"AI now runs inside live malware. See where AI defence genuinely helps, where egress policy beats it, and how to detect malware that calls a model at runtime.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/\" \/>\n<meta property=\"og:site_name\" content=\"Threatcop\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-17T12:22:39+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-17T12:22:41+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Using-AI-to-Defend-Against-AI-Attacks-blog-banner.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Adhish Chakma\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatcop\" \/>\n<meta name=\"twitter:site\" content=\"@threatcop\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Adhish Chakma\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"15 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-to-defend-against-ai-attacks\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-to-defend-against-ai-attacks\\\/\"},\"author\":{\"name\":\"Adhish Chakma\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/person\\\/7ce86f95d6eb24f0c7c51619b704defa\"},\"headline\":\"Using AI to Defend Against AI Attacks: What Actually Works\",\"datePublished\":\"2026-09-17T12:22:39+00:00\",\"dateModified\":\"2026-09-17T12:22:41+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-to-defend-against-ai-attacks\\\/\"},\"wordCount\":3177,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-to-defend-against-ai-attacks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Using-AI-to-Defend-Against-AI-Attacks-blog-banner.png\",\"articleSection\":[\"AI &amp; Cybersecurity\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-to-defend-against-ai-attacks\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-to-defend-against-ai-attacks\\\/\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-to-defend-against-ai-attacks\\\/\",\"name\":\"Using AI to Defend Against AI Attacks: What Works\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-to-defend-against-ai-attacks\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-to-defend-against-ai-attacks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Using-AI-to-Defend-Against-AI-Attacks-blog-banner.png\",\"datePublished\":\"2026-09-17T12:22:39+00:00\",\"dateModified\":\"2026-09-17T12:22:41+00:00\",\"description\":\"AI now runs inside live malware. See where AI defence genuinely helps, where egress policy beats it, and how to detect malware that calls a model at runtime.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-to-defend-against-ai-attacks\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-to-defend-against-ai-attacks\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-to-defend-against-ai-attacks\\\/#primaryimage\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Using-AI-to-Defend-Against-AI-Attacks-blog-banner.png\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Using-AI-to-Defend-Against-AI-Attacks-blog-banner.png\",\"width\":1280,\"height\":720,\"caption\":\"Threatcop blog banner reading Using AI to Defend Against AI, What Actually Works, over an abstract stacked bar graphic on a dark navy background\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-to-defend-against-ai-attacks\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Using AI to Defend Against AI Attacks: What Actually Works\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\",\"name\":\"Threatcop\",\"description\":\"Cybersecurity Blogs, News, Updates, and Articles\",\"publisher\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\",\"name\":\"Threatcop\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/threatcop-logo-black-1.png\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/threatcop-logo-black-1.png\",\"width\":432,\"height\":102,\"caption\":\"Threatcop\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/people\\\/Threatcop\\\/100083109892339\\\/\",\"https:\\\/\\\/x.com\\\/threatcop\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/threatcop\\\/\",\"https:\\\/\\\/www.instagram.com\\\/threatcop_official\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/person\\\/7ce86f95d6eb24f0c7c51619b704defa\",\"name\":\"Adhish Chakma\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/avatar_user_27_1789477673-96x96.jpeg\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/avatar_user_27_1789477673-96x96.jpeg\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/avatar_user_27_1789477673-96x96.jpeg\",\"caption\":\"Adhish Chakma\"},\"description\":\"Adhish Chakma is a Senior Product Manager at Kratikal, where he leads product initiatives focused on cybersecurity and AI-powered solutions. With experience in product management and cybersecurity, he works on developing practical technologies that address evolving security challenges. His areas of interest include People Security Management, cybersecurity awareness, AI-driven security, email security, and human-layer risk. He is passionate about building security products that make organizations more resilient against emerging cyber threats.\",\"sameAs\":[\"https:\\\/\\\/threatcop.com\\\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Using AI to Defend Against AI Attacks: What Works","description":"AI now runs inside live malware. See where AI defence genuinely helps, where egress policy beats it, and how to detect malware that calls a model at runtime.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/","og_locale":"en_US","og_type":"article","og_title":"Using AI to Defend Against AI Attacks: What Works","og_description":"AI now runs inside live malware. See where AI defence genuinely helps, where egress policy beats it, and how to detect malware that calls a model at runtime.","og_url":"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/","og_site_name":"Threatcop","article_publisher":"https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/","article_published_time":"2026-09-17T12:22:39+00:00","article_modified_time":"2026-09-17T12:22:41+00:00","og_image":[{"width":1280,"height":720,"url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Using-AI-to-Defend-Against-AI-Attacks-blog-banner.png","type":"image\/png"}],"author":"Adhish Chakma","twitter_card":"summary_large_image","twitter_creator":"@threatcop","twitter_site":"@threatcop","twitter_misc":{"Written by":"Adhish Chakma","Est. reading time":"15 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#article","isPartOf":{"@id":"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/"},"author":{"name":"Adhish Chakma","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/person\/7ce86f95d6eb24f0c7c51619b704defa"},"headline":"Using AI to Defend Against AI Attacks: What Actually Works","datePublished":"2026-09-17T12:22:39+00:00","dateModified":"2026-09-17T12:22:41+00:00","mainEntityOfPage":{"@id":"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/"},"wordCount":3177,"commentCount":0,"publisher":{"@id":"https:\/\/threatcop.com\/blog\/#organization"},"image":{"@id":"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#primaryimage"},"thumbnailUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Using-AI-to-Defend-Against-AI-Attacks-blog-banner.png","articleSection":["AI &amp; Cybersecurity"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/","url":"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/","name":"Using AI to Defend Against AI Attacks: What Works","isPartOf":{"@id":"https:\/\/threatcop.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#primaryimage"},"image":{"@id":"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#primaryimage"},"thumbnailUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Using-AI-to-Defend-Against-AI-Attacks-blog-banner.png","datePublished":"2026-09-17T12:22:39+00:00","dateModified":"2026-09-17T12:22:41+00:00","description":"AI now runs inside live malware. See where AI defence genuinely helps, where egress policy beats it, and how to detect malware that calls a model at runtime.","breadcrumb":{"@id":"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#primaryimage","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Using-AI-to-Defend-Against-AI-Attacks-blog-banner.png","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Using-AI-to-Defend-Against-AI-Attacks-blog-banner.png","width":1280,"height":720,"caption":"Threatcop blog banner reading Using AI to Defend Against AI, What Actually Works, over an abstract stacked bar graphic on a dark navy background"},{"@type":"BreadcrumbList","@id":"https:\/\/threatcop.com\/blog\/ai-to-defend-against-ai-attacks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/threatcop.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Using AI to Defend Against AI Attacks: What Actually Works"}]},{"@type":"WebSite","@id":"https:\/\/threatcop.com\/blog\/#website","url":"https:\/\/threatcop.com\/blog\/","name":"Threatcop","description":"Cybersecurity Blogs, News, Updates, and Articles","publisher":{"@id":"https:\/\/threatcop.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/threatcop.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/threatcop.com\/blog\/#organization","name":"Threatcop","url":"https:\/\/threatcop.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/threatcop-logo-black-1.png","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/threatcop-logo-black-1.png","width":432,"height":102,"caption":"Threatcop"},"image":{"@id":"https:\/\/threatcop.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/","https:\/\/x.com\/threatcop","https:\/\/www.linkedin.com\/company\/threatcop\/","https:\/\/www.instagram.com\/threatcop_official\/"]},{"@type":"Person","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/person\/7ce86f95d6eb24f0c7c51619b704defa","name":"Adhish Chakma","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/avatar_user_27_1789477673-96x96.jpeg","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/avatar_user_27_1789477673-96x96.jpeg","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/avatar_user_27_1789477673-96x96.jpeg","caption":"Adhish Chakma"},"description":"Adhish Chakma is a Senior Product Manager at Kratikal, where he leads product initiatives focused on cybersecurity and AI-powered solutions. With experience in product management and cybersecurity, he works on developing practical technologies that address evolving security challenges. His areas of interest include People Security Management, cybersecurity awareness, AI-driven security, email security, and human-layer risk. He is passionate about building security products that make organizations more resilient against emerging cyber threats.","sameAs":["https:\/\/threatcop.com\/"]}]}},"_links":{"self":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15373","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/comments?post=15373"}],"version-history":[{"count":3,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15373\/revisions"}],"predecessor-version":[{"id":15398,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15373\/revisions\/15398"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/media\/15390"}],"wp:attachment":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/media?parent=15373"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/categories?post=15373"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/tags?post=15373"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}