Report | AI Security Report 2025 | Check Point Software

Report | AI Security Report 2025

INTRODUCTION

The Accelerating Future of AI for Cyber Offenders and Defenders
AI is revolutionizing industries, and cyber crime and cyber security are no different. Adopting AI in enterprises—and unfortunately by threat actors as well—enhances efficiency, scale, and impact. At this point in time, we believe it’s essential to pause and assess the current state and future of AI and cyber security. How are attackers using AI, and what comes next? As cyber defenders, how can we leverage AI to enhance our security efforts and protect our organizations more effectively? These are the questions addressed in the first edition of the Check Point Research AI Security Report.

Our focus zeroes in on:

AI THREATS

THE AI MODELS USED BY CYBER CRIMINALS

Cyber criminals are closely monitoring trends in mainstream AI adoption. Whenever a new large language model (LLM) is released to the public, underground actors quickly test its potential for misuse (figure 1). Currently, ChatGPT and OpenAI’s API are the most popular models for cyber criminals, while others like Google Gemini, Microsoft Copilot, and Anthropic Claude are quickly gaining popularity. The landscape is changing with the launch of open-source models like DeepSeek and Qwen by Alibaba. These models enhance accessibility, have minimal usage restrictions, and are available in free tiers, making them a key asset to crime.
Figure 1 – Underground forum discussion on harnessing DeepSeek for malware development

The Development of Malicious AI Models

Cyber criminals are exploiting mainstream platforms and creating and selling specialized malicious LLM models explicitly tailored for cyber crime (figure 2). These dark LLM models are designed to circumvent the safeguards established for ethical models and are actively marketed as hacking tools.
Figure 2 – Onion GPT, an example of a dark AI model created in Tor

The notorious AI model WormGPT was created by jailbreaking ChatGPT (figure 3). Marketed as the “ultimate hacking AI,” it can generate phishing emails, write malware, and craft social engineering scripts without ethical constraints. A Telegram channel promotes its use for fraud, botnet creation, and cyber intrusion, offering subscriptions highlighting the commercialization of dark AI.
Figure 3 – Malicious AI service WormGPT advertised on a Telegram channel