Findings/early-attacker-llm-use-was-productivity

AI providers’ early reports found threat actors using LLMs mainly as productivity tools for research, scripting help and content, without novel attack capabilities.

Supersededobserved2 evidence records from 2 independent sourcesassistant-drafted
Scope: what this does not show

Covers provider reports from February 2024 to January 2025, based on activity the providers could see on their own services; actors using other or self-hosted models were outside this view.

Superseded: Replaced by a newer measurement of the same thing. Kept for the trend.

Evidence

How it relates to other findings

supportsqualifiescontestssupersedes
ReportedCorroboratedQualifiedContestedSupersededRevalidate· node size = evidence records · columns group by topic

Select a finding to see how it relates to others. Arrows point from the newer finding to the one it supports, qualifies, contests, or supersedes.

Status history

  1. 2024-02-14ReportedMicrosoft and OpenAI report productivity-level use by state-affiliated actors. · record
  2. 2025-01-29CorroboratedGoogle independently reports the same pattern in Gemini use. · record
  3. 2025-11-05SupersededGTIG reports malware that uses LLMs during execution in live operations, a capability beyond productivity use. · record