Report | AI Security Report 2025 | Check Point Software

Report | AI Security Report 2025

01 INTRODUCTION

INTRODUCTION

The Accelerating Future of AI for Cyber Offenders and Defenders

AI is revolutionizing industries, and cyber crime and cyber security are no different. Adopting AI in enterprises—and unfortunately by threat actors as well—enhances efficiency, scale, and impact. At this point in time, we believe it’s essential to pause and assess the current state and future of AI and cyber security. How are attackers using AI, and what comes next? As cyber defenders, how can we leverage AI to enhance our security efforts and protect our organizations more effectively? These are the questions addressed in the first edition of the Check Point Research AI Security Report.

Our focus zeroes in on:

AI threats are no longer theoretical—they're here and evolving rapidly. As access to AI tools becomes more widespread, threat actors exploit this shift in two key ways: by leveraging AI to enhance their capabilities and targeting organizations and individuals adopting AI technologies. The following pages provide a comprehensive understanding of these threats, allowing readers to navigate the intricate landscape of AI security.

To a secure future of innovation and success, Lotem Finkelstein, Director of Check Point Research

02 AI THREATS

THE AI MODELS USED BY CYBER CRIMINALS

Cyber criminals are closely monitoring trends in mainstream AI adoption. Whenever a new large language model (LLM) is released to the public, underground actors quickly test its potential for misuse (figure 1). Currently, ChatGPT and OpenAI’s API are the most popular models for cyber criminals, while others like Google Gemini, Microsoft Copilot, and Anthropic Claude are quickly gaining popularity. The landscape is changing with the launch of open-source models like DeepSeek and Qwen by Alibaba. These models enhance accessibility, have minimal usage restrictions, and are available in free tiers, making them a key asset to crime.

Figure 1 – Underground forum discussion on harnessing DeepSeek for malware development

The Development of Malicious AI Models

Cyber criminals are exploiting mainstream platforms and creating and selling specialized malicious LLM models explicitly tailored for cyber crime (figure 2). These dark LLM models are designed to circumvent the safeguards established for ethical models and are actively marketed as hacking tools.

Figure 2 – Onion GPT, an example of a dark AI model created in Tor

The notorious AI model WormGPT was created by jailbreaking ChatGPT (figure 3). Marketed as the “ultimate hacking AI,” it can generate phishing emails, write malware, and craft social engineering scripts without ethical constraints. A Telegram channel promotes its use for fraud, botnet creation, and cyber intrusion, offering subscriptions highlighting the commercialization of dark AI.

Figure 3 – Malicious AI service WormGPT advertised on a Telegram channel

A new wave of dark AI models, such as GhostGPT, FraudGPT, and HackerGPT (figure 4), serve specific aspects of cyber crime. Some models wrap around mainstream AI with jailbreaks, while others modify open-source models. As mainstream AI models evolve, so do their dark counterparts.

Figure 4 - HackerGPT capabilities published on a cyber crime forum