Dark AI

‘Dark AI’ on the rise: Nation-state hackers step up game

Share

Da Nang, Vietnam: Global cybersecurity firm Kaspersky warns that nation-state cyberattacks in the Asia Pacific (APAC) region will grow more sophisticated with the rise of ‘Dark AI’.

Regional journalists and Kaspersky executives came together during the APAC Cyber Security Weekend 2025, held in Da Nang, Vietnam to discuss how malicious actors, from routine phishing scams to cyber espionage linked to state actors weaponise artificial intelligence (AI).

“Since ChatGPT gained global popularity in 2023, we have observed several useful adoptions of AI, from mundane tasks like video creation to technical threat detections and analysis. In the same breath, bad actors are using it to enhance their attacking capabilities,” said Sergey Lozhkin, Head of Global Research & Analysis Team (GReAT) for META and APAC – Kaspersky.

“We are entering an era in cybersecurity and in our society, where AI is the shield and Dark AI is the sword,” added Lozhkin.

Dark AI refers to the deployment of unrestricted large language models (LLMs) for unethical or malicious purposes. These systems operate outside of standard compliance or governance, enabling deception, cyberattacks, and data abuse.

Black Hat GPTs commonly demonstrate this by using AI models designed or modified to perform illegal activities. These include generating malicious code, crafting phishing emails, producing deepfakes, and supporting cybercrime operations. Examples include WormGPT, DarkBard, FraudGPT, and Xanthorox.

Kaspersky experts are now observing a worrying trend: the involvement of nation-state actors.

“OpenAI recently revealed it has disrupted over 20 covert influence and cyber operations attempting to misuse its AI tools. We can expect threat actors to create more clever ways of weaponising generative AI operating in both public and private threat ecosystems. We should brace for it,” Lozhkin explained.

AI itself doesn’t have a sense of ethics, it simply responds to the given instructions. Even with built-in protections, advanced persistent threats (APTs) continue to find ways around them, according to Lozhkin.

As dark AI tools become more accessible and capable, Lozhkin emphasized that it’s crucial for organisations and individuals in Asia Pacific to strengthen cybersecurity hygiene. He recommended to invest in AI-powered threat detection and gain knowledge on how these technologies can be exploited.

Kaspersky recommends using advanced security solutions, real-time threat intelligence, strict access controls, and establishing a Security Operations Centre (SOC) to counter Dark AI threats.