Created
September 2, 2026 05:32
-
-
Save fr0gger/d8c2e3b1e34805877433ec688f352b6c to your computer and use it in GitHub Desktop.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| | Date | Named threat / item | Primary report or advisory | | |
| | ----------- | ----------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | |
| | 14 Feb 2024 | Charcoal Typhoon, Salmon Typhoon, Crimson Sandstorm, Emerald Sleet, Forest Blizzard | [OpenAI report](https://openai.com/index/disrupting-malicious-uses-of-ai-by-state-affiliated-threat-actors/) · [Microsoft companion report](https://www.microsoft.com/en-us/security/blog/2024/02/14/staying-ahead-of-threat-actors-in-the-age-of-ai/) | | |
| | 30 May 2024 | Bad Grammar, Doppelganger, Spamouflage | [OpenAI: Covert Influence Operations](https://openai.com/index/disrupting-deceptive-uses-of-ai-by-covert-influence-operations/) | | |
| | 26 Jun 2024 | DRAGONBRIDGE | [Google TAG report](https://blog.google/threat-analysis-group/google-disrupted-dragonbridge-activity-q1-2024/) | | |
| | 9 Jul 2024 | Meliorator bot farm | [FBI and partner advisory](https://www.ic3.gov/Media/News/2024/240709.pdf) | | |
| | 3 Oct 2024 | Hosted-model hijacking | [Permiso PØ Labs report](https://permiso.io/blog/exploiting-hosted-models) | | |
| | 29 Jan 2025 | Multi-actor model misuse | [Google GTIG: Adversarial Misuse of Generative AI](https://cloud.google.com/blog/topics/threat-intelligence/adversarial-misuse-generative-ai) | | |
| | 23 Apr 2025 | Influence-as-a-service network | [Anthropic: Detecting malicious uses of Claude](https://www.anthropic.com/news/detecting-and-countering-malicious-uses-of-claude-march-2025) | | |
| | 17 Jul 2025 | LAMEHUG | [CERT-UA advisory](https://cert.gov.ua/article/6284730) | | |
| | 27 Aug 2025 | Data-extortion actor | [Anthropic: Detecting and countering misuse of AI](https://www.anthropic.com/news/detecting-countering-misuse-aug-2025) | | |
| | 25 Sep 2025 | postmark-mcp | [Snyk: Malicious MCP Server Harvests Emails](https://snyk.io/blog/malicious-mcp-server-on-npm-postmark-mcp-harvests-emails/) | | |
| | 5 Nov 2025 | PROMPTSTEAL / QUIETVAULT | [Google GTIG AI Threat Tracker](https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools) | | |
| | 13 Nov 2025 | GTG-1002 | [Anthropic: AI-orchestrated cyberespionage](https://www.anthropic.com/news/disrupting-AI-espionage) | | |
| | 5 Dec 2025 | MCP sampling attack research | [Unit 42 MCP sampling research](https://unit42.paloaltonetworks.com/model-context-protocol-attack-vectors/) | | |
| | 5 Feb 2026 | ToxicSkills | [Snyk ToxicSkills study](https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub/) | | |
| | 23 Feb 2026 | AMOS through poisoned skills | [Trend Micro: Malicious OpenClaw Skills](https://www.trendmicro.com/en_us/research/26/b/openclaw-skills-used-to-distribute-atomic-macos-stealer.html) | | |
| | 11 May 2026 | SHADOW-AETHER-040 | [Trend Micro: Vibe Hacking](https://www.trendmicro.com/en_us/research/26/e/vibe-hacking-two-ai-augmented-campaigns-target-government-and-financial-sectors-in-latin-america.html) | | |
| | 3 Jun 2026 | ATT\&CK account mapping | [Anthropic: Mapping AI-enabled cyber threats](https://www.anthropic.com/news/AI-enabled-cyber-threats-mitre-attack) | | |
| | 1 Jul 2026 | JADEPUFFER | [Sysdig: Agentic ransomware for database extortion](https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion) | | |
| | 14 Jul 2026 | Patriot Bait | [Trend Micro: Six Minutes to Compromise](https://www.trendmicro.com/en/research/26/g/actor-behind-patriot-bait-used-ai-to-deploy-c2-botnet.html) | | |
| | 12 Aug 2026 | Deadbugz | [Pillar Security: Active MCP supply-chain campaign](https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign) | | |
| | 20 Aug 2026 | UAT-10147 | [Cisco Talos: Agentic AI in post-compromise operations](https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/) | |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment