Cyberattacks are increasingly built around familiar actions: signing in, approving a payment, or using a trusted app. Artificial intelligence can help attackers repeat those actions at speed, making financial fraud and network intrusion harder to spot before damage is done.

The threats take different forms. Some automate parts of a network break-in, while others imitate executives on video calls, hide inside mobile apps, or place fake payment forms over legitimate checkouts.

The shared weakness is misplaced trust in an apparently normal interaction. These attacks require continuous checks of identity and behavior, not just trust in a login.

The report brings together espionage, mobile malware, fraud, and extortion rather than describing one new malware family. The consequences range from stolen phone data and payment details to large fraudulent transfers and reputational damage.

Trellix said in a report shared with Cyber Security News (CSN) that the attackers use automation to adjust their methods, a convincing screen or recognizable voice may no longer provide enough assurance that a request is genuine.

Autonomous Attacks Exploit Digital Trust

In the China-linked GTG-1002 espionage campaign, AI agents reportedly handled 80% to 90% of operational tasks. Human operators made about four to six key decisions, including target selection and data theft approval, while the software carried out much of the work between them.

The case illustrates how an intrusion can move faster when attackers delegate routine steps to software. Earlier coverage of AI orchestrated espionage describes how the campaign used automated reconnaissance, credential harvesting, and exploit development to pursue targets across several sectors.

On phones, PromptSpy shows a narrower but practical use of AI. The Android malware reads what appears on a device screen and requests instructions for interacting with it. Instead of relying on fixed button positions, it can adapt its actions to the interface it sees.

It uses accessibility permissions to keep its app present and place invisible layers over controls that might stop or remove it. Our report on PromptSpy mobile malware explains how it can also capture screen activity and lockscreen information, giving attackers a route to sensitive personal data.

Trellix advises restricting accessibility permissions and using Safe Mode to remove the app when its overlays block normal uninstallation. For organizations, the broader lesson for security teams is to review unusual device behavior rather than assuming a familiar interface means the device itself is safe.

Fraud Hides Behind Familiar Actions

Deepfake calls can turn a routine approval into a costly mistake. Trellix describes a case in which fake video and audio of company leaders persuaded a finance employee to authorize a $25 million transfer. The caller appeared to fit the expected chain of command.

Such scams exploit the pressure to respond quickly to senior staff. Previous coverage of deepfake business fraud shows why a face on a call or a familiar voice should not, by itself, settle whether a payment request is real.

Online checkout attacks use a different kind of familiarity. In double-tap skimming, a fake payment form first captures card details, then appears to fail and sends the shopper to the real form. The final purchase can still succeed, leaving the earlier theft easy to miss.

The pattern is explored in reporting on double tap skimming, where a fake checkout overlay passed shoppers back to a legitimate payment flow. Trellix recommends simulated checkout tests and regular store audits to catch disruptions or unauthorized forms before customers encounter them.

The report also discusses LunaLock, which it says uses AI to find sensitive material in stolen data and sharpen extortion demands.

Trellix reports that the group compromised more than 95,000 accounts linked to an artists’ marketplace, underscoring how exposed files can remain a problem after systems are restored.

For high-value payments, Trellix recommends checking requests through a separate, established channel, such as a callback or prearranged code.

It also urges phishing-resistant authentication, ongoing exposure checks, and encryption of sensitive documents. Those steps test the action itself, not merely the identity that appears to request it.