For a long time, writing malware able to target critical infrastructure required rare skills and much time. That barrier is crumbling. A previously unknown group had an artificial intelligence write the code launched against power grids, and the time to get inside a system is now counted in minutes. This dossier describes no technique: it follows an economic shift. When the cost of attack tends toward zero and its speed toward the instant, the balance between offense and defense breaks.
1 The attack of the day
The fact: malware handed to the machine.
The fact
Malware written by an AI
In 2026, security vendor Kaspersky documented a previously unknown group it named "Armored Likho." Its distinctive trait: it used a large language model to generate the first-stage malicious code, deployed against government bodies and power grids in Russia, Kazakhstan and Brazil. Initial access came through booby-trapped emails — a classic method — but the crafting of the malware itself was handed to the machine. This is not an isolated technical feat: it is the sign of a practice becoming routine.
2 The machine's signature
The clue: one fingerprint erases another.
The clue
The model's mark erases the author's
How do we know an AI wrote the code? By its manner: verbose, tutorial-style comments, emojis in the middle of source, redundant blocks — the signature style of a language model, not of a rushed developer. But the crux is a paradox. Usually, the way one codes betrays its author: their habits, their language, their tics serve as a fingerprint for investigators. Code written by AI no longer carries that fingerprint: its style reflects the model's training data, not a particular hand. The machine's signature erases the human's.
3 The barrier that falls
The shift: from rare talent to mere intent.
The shift
The bottleneck moves from talent to intent
Until now, writing effective malware required rare know-how, long to acquire. That was a barrier: it limited the number of actors able to hit a serious target. Generative AI lowers that barrier. It puts within reach of a mediocre actor what once demanded an expert team; it democratizes offensive capability. The bottleneck moves: it is no longer talent that is scarce, it is intent that suffices. And there are always more ill-intentioned people than skilled ones.
4 The tempo that accelerates
The speed: reaction time evaporates.
The speed
The gap between intent and execution
The second shift is tempo. Defenders measure "breakout time": the gap between the moment an attacker gains a foothold in a network and the moment it begins to spread laterally. Per the CrowdStrike 2026 report, that average has fallen to 29 minutes — 65% faster than in 2024 — and the shortest ever observed to 27 seconds; in one case, data exfiltration began four minutes after intrusion. AI compresses the gap between intent and execution. A human team, meanwhile, often takes hours merely to notice the attack.
Average breakout time
29 min
before lateral movement; 65% faster than in 2024 (record: 27 seconds).
Fastest exfiltration
4 min
after initial access: the defender no longer has time to react.
5 The scale of the phenomenon
The measure: industrialization, not an incident.
The measure
AI, both weapon and battlefield
Armored Likho is not an isolated case. The same report puts the rise in AI-assisted adversary operations at +89% year over year. Several state-linked groups have deployed malware driven by language models to automate reconnaissance and document collection; others use it to erase their tracks or fabricate fake identities at scale. In a new development, AI systems themselves are becoming targets: attackers inject malicious prompts into the AI tools of dozens of organizations. AI is now both the weapon and the battlefield.
6 The offense-defense asymmetry
The theoretical core: one flaw against all.
The theoretical core
When attack costs less than defense
Here is the pivot. Cybersecurity obeys a fundamental asymmetry: the attacker need only find a single flaw; the defender must close them all, at all times. Political scientist Robert Jervis formalized the idea of an "offense-defense balance": when attacking costs less than defending, the world becomes unstable. AI is shifting precisely that balance to the wrong side: it lowers the cost of offense faster than that of defense. The "defender's dilemma" — having to be right every time, when the attacker can be wrong a thousand times — is thereby worsened.
7 Attribution blurred
The strategic consequence: no signature, no retaliation.
The strategic consequence
No attribution, no deterrence
The erasure of the fingerprint reaches beyond the investigation. All deterrence, in cybersecurity as in geopolitics, rests on attribution: to retaliate, you must know who struck. If the code no longer accuses its author, tracing it back becomes more uncertain — and uncertain retaliation does not deter. By blurring attribution, AI weakens not only the investigation: it erodes the very mechanism — the fear of reprisal — that stayed the attackers' hand.
8 Why the power grid
The target: the foundation of everything else.
The target
Insecurity as an externality
The choice of target is not innocent. The power grid is the foundation of everything else: hospitals, drinking water, telecoms, transport, finance. A failure never stays isolated: it spreads in cascade. Its security is a common good; its insecurity, an externality the whole of society bears, far beyond the operator attacked. It is also a "political" target: to strike the grid is to signal a capability, test a defense, exert pressure — without necessarily firing a single shot.
9 Defense arms up too
The other side: the race is on.
The other side
But the tempo favors offense
It would be wrong to paint AI as a pure offensive advantage. It arms defenders too: spotting anomalies in oceans of logs, triaging alerts, automating part of the response, patching flaws faster. The race is on, and nothing says it will be lost. But an imbalance persists today: it is simpler to automate a precise strike than to armor an entire, old and heterogeneous system. The tempo, for now, leans to the side of attack — and it is that imbalance that must be worked back the other way.
10 Limits and nuance
The right measure: neither magic nor fate.
The right measure
Take the threat seriously without mythologizing it
Two excesses lie in wait. The first is catastrophism: AI does not (yet) invent radically new attacks; it accelerates, industrializes and democratizes the existing. Part of the ambient discourse is, moreover, fear marketing, sustained by an industry that sells protection. The second excess would be denial: the figures — breakout in minutes, operations sharply up — are real, and humans remain, for now, in the loop of the most serious attacks. Clarity lies between the two: take the threat seriously without mythologizing it, and remember that the sturdiest defenses are often the most basic (segmentation, backups, digital hygiene).
11 Defending when offense automates
The close: what shifts is the economics of attack.
The meaning of the shift
The question is no longer "who wrote the code?"
At bottom, what shifts is not the nature of attacks, but their economics. When the cost of writing offensive code tends toward zero, its speed toward the instant, and its signature fades, the balance that protected infrastructure breaks. The right question is therefore no longer "who wrote this code?" — the machine, in part — but "how do we rebuild deterrence and resilience when offense automates?" The answer will not be only technical: it will also be economic and political — making attack more costly, defense faster, and infrastructure robust enough to absorb what cannot be prevented.
The compass
①
AI collapses the cost, skill and time needed to write attack code: offense democratizes and accelerates.
②
The asymmetry widens. The attacker needs only one flaw and a few minutes (breakout down to 29 minutes); the defender must cover everything, at all times.
③
The machine's code erases the human signature: attribution blurs, deterrence weakens. The question becomes "how do we defend when offense is automated?" This sheet sets out a debate; it is not advice.
Read alongside: Vibe Coding: when AI becomes DeFi's architect and Harvest today, decrypt tomorrow. Reference: abbreviations & acronyms (AI, APT, LLM).