AI-powered tools are already being leveraged in real-world cyberattacks, from initial recon to generating malicious code. That's the key takeaway from the F6 report covering 2025 and the first half of 2026.
What the F6 Report Reveals
Analysts found that in the past year and a half, at least 18 APT groups pulled off attacks using AI. The report details documented cases where models and related tools were used in live campaigns—from prepping and automating content to the technical nuts and bolts of the attack.
GTG-1002 Case: LLMs Supercharge Phishing
One standout episode centers on the GTG-1002 group. According to the report, they used language models to whip up phishing emails: the messages were tailored for specific targets and slipped right past standard spam filters.
Context
The F6 findings show AI moving out of the lab and into the daily toolkit of attackers. All the examples and metrics in the report cover the period from 2025 through the first half of 2026.
