The use of artificial intelligence in planning and carrying out cyberattacks takes them to a new level. It allows attackers to find ways around individual defensive mechanisms more quickly, automate intrusion, and run complex operations with a smaller team of skilled specialists. A telling example came on 27 August 2026, when Reuters reported the exposure of the Russian-speaking hacking group Aur0ra. The group used the AI assistant Cursor in attacks on at least seven European companies, including Belgian industrial chemicals manufacturer Christeyns and German door and gate maker Teckentrup.
Researchers at Gambit Security found Aur0ra’s server and, exploiting a misconfigured network, gained access to the system. There they discovered 28 saved chat sessions between the hackers and the Cursor AI agent, covering the period from 8 April to 21 May 2026. Those sessions made it possible to reconstruct how AI was used during the attacks themselves. Investigators found that artificial intelligence helped the attackers work with vulnerabilities, steal credentials, and carry out other tasks. When Cursor refused suspicious requests, the hackers deceived it by framing their activity as security testing. The incident showed how AI can sharply increase the effectiveness of familiar attack methods and make the work of malicious actors far easier. Against that background, five main levels of threat created by the use of AI in unauthorized intrusion deserve examination.
The first level is a reduced need for highly qualified programmers. Finding vulnerabilities, writing scripts, analyzing an unfamiliar system, or modifying malware once required specialists with very different and often narrow skills. Some of those functions can now be performed by AI. Google has already recorded Russia-linked APT groups using Gemini to work with code, analyze malware, and solve technical problems. In May 2026, Google Threat Intelligence noted that adversaries’ use of AI was becoming more systematic. The EU, for its part, stresses that Russia’s cyber ecosystem includes not only state intelligence services but also criminal groups, hacktivists, and private structures with the relevant capabilities.
The second level is the scaling of attacks against large and mid-sized European businesses. AI makes it possible to assess a potential target more quickly, adapt tools, and move on to the next campaign. That increases the number of simultaneous attacks without a matching increase in staff. Mid-sized firms may be especially exposed: they often lack the budgets for robust cybersecurity, yet they sit inside the production, logistics, and IT chains of large corporations. The Christeyns and Teckentrup cases showed that the targets are not only banks, government bodies, or defense contractors, but ordinary industrial companies as well.
The third level is social engineering. AI simplifies the collection and analysis of open information about employees, executives, and partners, and can then generate personalized phishing messages in any language. The approach becomes more targeted and more convincing. Instead of a generic, spam-like email, an employee receives a message styled as coming from management, the IT department, or a real contractor — something that inspires trust. When attackers need access to a particularly valuable target, they may even tailor scripts to a specific person’s traits and interests in order to induce them to open an infected link. AI also helps eliminate the grammatical and linguistic mistakes that once made phishing easy to spot. Voice and image synthesis add further options for fraud and deception.
The fourth, and potentially most dangerous, level is the use of AI inside an already compromised network. Research by Anthropic into hundreds of blocked accounts linked to malicious activity found AI being used at multiple stages of real operations, from reconnaissance to handling credentials. In the Aur0ra case, AI was also used during the intrusion itself. That suggests an attacker no longer needs detailed prior knowledge of a target system’s architecture. AI can help analyze the environment, find vulnerabilities, and decide on the next steps while the attack is under way.
In recent years Russia has built a large-scale infrastructure for cyber operations. On 7 April 2026, Microsoft reported that the GRU-linked group Forest Blizzard — also known as APT28 and Fancy Bear — had since August 2025 been compromising home and office routers and altering DNS settings in order to intercept traffic and mount further attacks. Microsoft identified more than 5,000 compromised devices and more than 200 affected organizations in government, IT, telecommunications, and energy. If AI is added to that infrastructure to analyze access automatically and pick the most promising targets, a single operator could work with far more systems.
The fifth level is industry and critical infrastructure, where the effects of an attack can go well beyond the loss of data. On 13 July 2026, the EU said Russian cyber operations had targeted government networks and critical infrastructure in France, Germany, Poland, the Netherlands, Austria, Romania, Finland, and other states. The Council of the EU imposed sanctions on the pro-Russian group Z-Pentest, which attacked energy and water-supply facilities.
Given the scale and systematic nature of these attacks, responding after the fact and cleaning up the damage is not enough. Faster sharing of information about new methods is needed, along with wider use of AI to detect anomalous activity automatically, stronger protection for mid-sized businesses and critical infrastructure, and more aggressive identification and disruption of hacking groups’ servers and financial networks. The Russian cyber threat existed long before the current boom in artificial intelligence. AI, however, can sharply raise the intensity of attacks without a matching rise in the number of highly skilled programmers.



