Global Threat Intelligence Report:
2026 Mid Year Edition
Data, insights, and key takeaways on the most impactful threats of 2026—from AI and infostealers to ransomware and vulnerabilities.
Artificial Intelligence (AI) Cybersecurity Threats
This section leverages natural language processing (NLP) analysis of Flashpoint’s primary-source repositories, encompassing over 3.9 petabytes of continuously monitored illicit forum communications and closed chat channels. The intelligence presented here reflects activity directly observed from January 1, 2026, to June 30, 2026.
Artificial Intelligence Overview
January 2026 – June 2026
22M
Total Mentions of
AI and Illicit Activity
4.2M
KYC Bypass
AI Advertisements
What are the Emerging AI Cyber Threats?
During the first half of 2026, Flashpoint documented a highly integrated and mature AI threat landscape, capturing over 22M illicit posts discussing or advertising AI for criminal-related activities. Flashpoint collections also reveal a profound operational shift: threat actors have gained commoditized access to open-source AI technologies. As a result, Flashpoint analysts are seeing individual threat actors increasingly deploy automated tooling locally, reducing the need to rely on public underground networks to seek or build specialized AI deployment services.
However, for those that do still need these services, cybercrime-trained AI offerings remain overwhelmingly concentrated within rapid-delivery messaging platforms and open-source infrastructure. These platforms, such as Telegram, are commonly utilized by illicit communities, followed by Reddit, GitHub, and Pastebin. The high-density spamming and sales cadence across these channels highlights how tightly integrated automated AI tools have become within the cybercriminal supply chain, serving as an easily accessible distribution layer for malware, evasion code, and social engineering scripts.
How Are 2026 Malicious AI Trends Accelerating Adversarial Automation?
The Rise of Decentralized Cybercrime LLMs and Localized AI Tooling
The cybercriminal underground has moved past their service-reliant and exploratory phase of AI, where threat actors frequently engaged in collaborative development, troubleshooting, and public outsourcing throughout illicit communities. Now in H1 2026, the ecosystem has reached a level of technological proficiency where pre-packaged, cybercrime-trained AI tools are widely available for localized deployment.
This transition has effectively decentralized AI threats. Threat actors now possess the technical maturity and software frameworks required to run customized, illicitly-trained models or jailbroken variants directly on their own private infrastructure. By leveraging local systems, threat actors eliminate the need to converse with developers or purchase access on public forums. This shift creates a major visibility gap for defenders, as the generation of malicious code, automated exploit scripts, and hyper-targeted phishing campaigns are now occurring mostly within closed, isolated attacker environments.
Custom Malicious LLMs Serve as Autonomous Attack Acceleration Hubs
LLMs have been structurally altered by the adversary underground to function as dedicated, unfiltered attack platforms. In the first half of 2026, Flashpoint has observed threat actors systematically developing bespoke, malicious LLMs or engineering complex API bypass frameworks against mainstream commercial models. These malicious variants are stripped of all ethical safeguards, content moderation filters, and security parameters, allowing criminals to rapidly generate high-quality, harmful assets.
These specialized LLMs are actively deployed as turnkey weapon engines across multiple distinct phases of the attack lifecycle. Threat actors utilize them to generate highly persuasive, contextually accurate phishing copy tailored to specific corporate languages and regional industries. They are also used to accelerate rapid malware prototyping by producing functional malware blocks and specialized evasion scripts designed to alter file structures and bypass traditional endpoint signature detection. Furthermore, adversaries use them to analyze disclosed software vulnerabilities to output functional proof-of-concept exploit code, drastically compressing the timeline between a zero-day discovery and broad-scale network exploitation.
What Are the Key Takeaways for AI Security Threats?
1
Custom LLMs Function as Turnkey Attack Accelerators
Custom LLMs Function as Turnkey Attack Accelerators By removing all ethical constraints and content filters, custom, malicious LLMs function as turnkey engines that automate complex phases of the cyberattack lifecycle. Unsophisticated threat actors can leverage this accessible distribution network to instantly generate phishing lures, malware components, and deploy automated scanners. This complete monetization of independent AI tools allows attackers to execute target profiling and initial access at a speed and scale that can potentially overpower human-reliant security operations.
2
Cybercriminals Shift to Private, Local Infrastructure
Threat networks are transitioning away from the initial collaborative development phase of generative AI. Instead of public forum troubleshooting, attackers are taking what they learned and building their own safeguard-free LLMs on private localized infrastructure. This migration into closed environments will make it difficult for organizations, as it potentially erases traditional external threat hunting signatures.
How Can Enterprises Proactively Defend Against Malicious AI?
The Rise of Decentralized Cybercrime LLMs and Localized AI Tooling
The cybercriminal underground has moved past their service-reliant and exploratory phase of AI, where threat actors frequently engaged in collaborative development, troubleshooting, and public outsourcing throughout illicit communities. Now in H1 2026, the ecosystem has reached a level of technological proficiency where pre-packaged, cybercrime-trained AI tools are widely available for localized deployment.
This transition has effectively decentralized AI threats. Threat actors now possess the technical maturity and software frameworks required to run customized, illicitly-trained models or jailbroken variants directly on their own private infrastructure. By leveraging local systems, threat actors eliminate the need to converse with developers or purchase access on public forums. This shift creates a major visibility gap for defenders, as the generation of malicious code, automated exploit scripts, and hyper-targeted phishing campaigns are now occurring mostly within closed, isolated attacker environments.
The Rise of Decentralized Cybercrime LLMs and Localized AI Tooling
The cybercriminal underground has moved past their service-reliant and exploratory phase of AI, where threat actors frequently engaged in collaborative development, troubleshooting, and public outsourcing throughout illicit communities. Now in H1 2026, the ecosystem has reached a level of technological proficiency where pre-packaged, cybercrime-trained AI tools are widely available for localized deployment.
This transition has effectively decentralized AI threats. Threat actors now possess the technical maturity and software frameworks required to run customized, illicitly-trained models or jailbroken variants directly on their own private infrastructure. By leveraging local systems, threat actors eliminate the need to converse with developers or purchase access on public forums. This shift creates a major visibility gap for defenders, as the generation of malicious code, automated exploit scripts, and hyper-targeted phishing campaigns are now occurring mostly within closed, isolated attacker environments.