Skip to content
Criminals Use AI to Build Botnets, Steal Crypto, and Hijack Live Cameras

Criminals Use AI to Build Botnets, Steal Crypto, and Hijack Live Cameras

Technadu August 5, 2026

Threat actors are weaponizing artificial intelligence (AI) , according to cybersecurity researchers who drew on prompt log artifacts recovered from tools like Claude Code, CodeX, Cursor, and Gemini. Cisco Talos has published a data-driven analysis of how detailing it observed no sophisticated encoding or jailbreak trickery.

Actors relied on ownership claims, Capture the Flag or bug bounty labeling, task decomposition, and persona conditioning – and it worked, consistently, across every model and platform Talos examined, the report said .

When one censored model refused a request, an operator simply pivoted to an uncensored version and got what they wanted without further resistance.

A novice DDoS operator, with seemingly little programming knowledge, built tooling controlling nearly 2,000 Android TVs by claiming the devices were his own test infrastructure. A more advanced actor used the "Tubely" domain to run a bulk-mail validation platform spanning tens of millions of records, disguising cold outreach as account-update notices.

A francophone operator turned public React2Shell vulnerability research into a credential harvester fed by a 90-million-URL input list, while a Turkish-speaking actor mined Monero across a cryptojacking fleet built on compromised Deluge and qBittorrent torrent clients.

A Russian fraud actor embedded persistent AI memories to strip guardrails permanently, rather than re-arguing the case in every session. A Spanish-speaking operator built an autonomous OpenClaw agent named "Alex" targeting Telegram Mini Apps and cryptocurrency wallets.

The Hephaestus red team framework automated compromise across Southeast Asia by splitting attacks across more than a dozen narrowly scoped AI agents.

The report also mentions a Brazilian Portuguese-speaking pentester that issued more than 500 shell actions during reconnaissance and exploitation work, and a Chinese-speaking operator tht targeted ZLMediaKit streaming platforms, exposing live camera feeds from surveillance systems.

In July, reports detailed 140+ malicious npm packages that turned web proxies for students into a DDoS botnet, and fake AI skills tricking Claude Code, Gemini, and ChatGPT into spreading malware. In June, researchers warned that free smart TV apps embed Bright Data SDK to build an AI web-scraping proxy network.