Rodrigo Leme
In the early days of hacking, it started as a game.
Teenagers in basements, university pranksters, rogue insiders. They weren’t chasing millions or manipulating geopolitics—they were poking around. Testing limits. Seeing if they could.
But over time, those hobbyists turned into organizations. And those organizations became operations.
What started as rebellion became a business. And now, hacker groups using AI have ushered in the next evolution of that business: autonomous, adaptive cybercrime.
The move to artificial intelligence isn’t a future threat. It’s already happening. And if you’re still defending against yesterday’s tactics, you’re not just behind—you’re exposed.
A Brief History of Hacker Groups: From Curiosity to Global Threats

Let’s take a step back.
In the 1980s and ’90s, hacking was mostly underground. Groups like the Legion of Doom or Cult of the Dead Cow were famous for publishing exploits, but rarely did they aim to destroy. Many were ideologically driven or sought fame in niche circles.
But by the 2000s, the stakes changed. Advanced persistent threats (APTs) emerged—state-sponsored actors with long-term missions, infinite resources, and clear objectives: espionage, infrastructure disruption, or financial theft.
Many of these operations are now tracked by frameworks like MITRE ATT&CK, which catalog adversary behaviors used by known threat groups.
Groups like APT28 (Fancy Bear), Lazarus Group, and Sandworm didn’t care about credit. They cared about access.
By the 2010s, financially motivated syndicates entered the scene. Ransomware-as-a-service, credential marketplaces, and automated hacking tools turned cybercrime into an enterprise. And now, with generative AI in hacking, it’s entering a new era.
One where the line between human attacker and machine attacker is blurring.
The Rise of AI-Powered Hacking Groups
We’ve seen this shift up close. What used to take hours—crafting a lure, scanning a system, impersonating a voice—can now be done autonomously using artificial intelligence.
Here’s what today’s AI-driven cyber threats actually look like:
– Deepfake cyber attacks using cloned executive voices for wire fraud
– AI phishing scams that mimic real-time company news and internal tone
– AI malware creation that adapts to bypass endpoint detection
– Chatbots impersonating employees in live help desk chats
– Machine learning in cyber attacks that helps prioritize high-value targets
– AI-enhanced cyber espionage that scans, filters, and interprets documents faster than any analyst
What ties them together? Speed. Scale. Realism. And the fact that they’re built not just by coders—but by threat actors using AI models to scale deception and automate trust.

3 Hacker Groups You Should Know — and Why They Matter
Scattered Spider
This international collective was responsible for the 2023 MGM Resorts breach. But what made it stand out wasn’t just the entry—it was the method. Using large language models, they crafted adaptive phishing emails and impersonated IT staff with alarming realism. Their tactics blend AI hacking techniques with SIM swapping and social manipulation.
TA453 (aka Charming Kitten / APT42)
Iranian state-linked operators with a focus on human targets: journalists, researchers, activists. They’ve been linked to AI-assisted cybercrime involving voice cloning, targeting people in academia and government with deepfake vishing calls that sound like colleagues or institutions.
UNC3944 (aka 0ktapus)
Specialists in large-scale credential harvesting and AI-enabled cyber breaches. They’ve used chatbots to fool help desk personnel into resetting MFA for accounts they’re targeting. It’s AI social engineering, but with a feedback loop that makes each attack smarter than the last.
These are just three of the ten most active hacker groups using AI today. If you want the full snapshot—including how they’re blending deepfakes, malware, and automation—grab the datasheet below.
10 Hacker Groups Weaponizing AI
Why This Isn’t a Training Problem Anymore
In my experience, most breaches don’t happen because someone didn’t know better. They happen because the thing in front of them looked and sounded exactly right.
That’s the power of AI in cybercrime. It turns trust into a vulnerability. And it means we can’t keep relying on quarterly training or generic simulations.
You need defenses that move as fast—and as intelligently—as the threats.
That’s why more organizations are turning to AI cybersecurity defense strategies that involve:
– Behavior-based phishing simulations that evolve in real time
– Training generated from your actual policies and threat reports, transformed into video content in minutes
– Deepfake voice simulations that teach people to pause and verify, not panic
– And autonomous agents that personalize training by role, risk profile, and behavioral signals
This is what modern human risk management looks like. Because when attackers are scaling social engineering with AI, the best response is to train your people with the same tools—before attackers reach them.
Final Word: This Is the New Normal
The world of hacker groups using AI is no longer hypothetical.
Whether it’s AI malware, phishing scams, or AI-enhanced espionage, these tactics are being deployed right now—against people just like yours.
The question isn’t if you’ll face one of these attacks.
It’s whether your organization will recognize it when it happens.
Want to see how they actually operate?
Grab our snapshot of 10 real-world groups and learn what they’re doing — and how to prepare.



