All articles
RESEARCH · 8 min read

New Attacker Tooling in 2026: What's Actually Changing Hands

Every year the criminal-forum chatter shifts a little. This year the shift is structural: AI didn't just make existing tools faster, it created entirely new categories of tooling that didn't exist three years ago.

AI-assisted C2 and payload generation

Forum listings now advertise "AI-obfuscated" loaders that rewrite their own signatures per build. The barrier to entry for polymorphic malware dropped from "skilled malware dev" to "anyone with API access."

Auto-weaponization of N-days

Time from CVE disclosure to a working, sold exploit keeps shrinking — AI-assisted patch diffing and PoC generation compress what used to take a skilled researcher days into hours.

  • Patch-diff-to-PoC pipelines advertised as a service
  • Exploit kits bundled with AI-written phishing lures
  • Vulnerability triage bots prioritizing targets by exploitability, not just CVSS

Deepfake-as-a-service

Voice cloning from a 30-second sample and real-time video deepfakes are now commodity offerings, aimed squarely at BEC and executive-impersonation fraud.

What this means for defenders

Signature-based detection degrades faster than ever against AI-mutated payloads. Behavior-based detection, identity verification out-of-band, and treating any urgent financial request as suspicious by default all matter more this year, not less.

Tools mentioned

VirusTotalAlienVault OTXRecorded FutureGreyNoiseShodanHave I Been Pwned
⟩ takeaway

The tooling changed the economics of attack, not the fundamentals of defense. Behavior-based detection and out-of-band verification beat signature-chasing every time AI mutates the payload.

⟩ keep reading

Related articles