Russia, China Using AI to Escalate Cyberattacks on the United States

October 17, 2025

“America’s adversaries — and criminal gangs working with them — are exploiting AI’s potential to make their cyber operations faster, smarter, and harder to detect,” the report said.
ANKARA, TURKIYE - OCTOBER 11: In this photo illustration the Microsoft logo is displayed on a mobile phone screen in Ankara, Turkiye on October 11, 2025. Photo by Anadolu Images.

R

ussia, China, Iran, and North Korea have dramatically ramped up their use of artificial intelligence (AI) to conduct cyberattacks and spread disinformation targeting the United States, according to new findings released by Microsoft on Thursday.

In its annual digital threats report, the tech giant said it identified more than 200 instances in July 2025 of foreign adversaries using AI to create or amplify fake content online — a figure that has doubled since 2024 and increased tenfold since 2023. The report paints a stark picture of how America’s rivals are adapting cutting-edge AI technologies to manipulate information, automate hacking operations, and undermine public trust.

“We see this as a pivotal moment where innovation is going so fast,” said Amy Hogan-Burney, Microsoft’s vice president for customer security and trust. “This is the year when you absolutely must invest in your cybersecurity basics.”

AI transforms cyber warfare

Microsoft researchers found that state-backed hackers and online influence operations have used AI to generate persuasive fake news, clone the voices and faces of public officials, and create deepfake videos to spread disinformation and sow discord. AI tools have also helped attackers craft flawless phishing emails and automate data breaches targeting sensitive government and corporate networks.

“America’s adversaries — and criminal gangs working with them — are exploiting AI’s potential to make their cyber operations faster, smarter, and harder to detect,” the report said.

The company said cybercriminals and state actors share overlapping goals: stealing classified or proprietary information, compromising infrastructure, and manipulating online narratives. While state-linked hackers focus on espionage and disruption, criminal syndicates prioritize financial gain through ransomware and data theft — sometimes with direct support from Moscow or Tehran.

Microsoft noted that AI is enabling these attackers to reach new levels of sophistication. “AI has become a force multiplier for threat actors,” the report stated, warning that its use is now widespread in digital espionage, propaganda, and social engineering campaigns.

The U.S. remains the top target

According to Microsoft, the United States continues to be the primary target of global cyberattacks. American government agencies, private corporations, hospitals, and universities are being hit more frequently than ever before.

Israel and Ukraine rank as the second and third most targeted countries, respectively — a reflection of how digital conflicts have intensified amid the ongoing wars in Gaza and Eastern Europe.

“Cyberattacks have become an extension of geopolitical competition,” Microsoft said, adding that online operations now often accompany military or diplomatic confrontations.

Hogan-Burney urged governments and companies to modernize cybersecurity systems to match the growing threat. “Many organizations are still relying on outdated defenses,” she warned. “Meanwhile, attackers are using AI to innovate every day.”

Foreign governments deny involvement

In response to Microsoft’s findings, the governments of Russia, China, and Iran issued statements denying the allegations.

Beijing’s foreign ministry accused the United States of “spreading lies to smear China,” claiming that Washington itself is “the world’s largest cyber aggressor.”

Similarly, Iran’s mission to the United Nations said in an email to the Associated Press that Tehran “does not initiate any form of offensive cyber operation against any state.”

“As a victim of cyber operations, [Iran] will respond to any such threat in a manner proportionate to its nature and scale,” the statement read.

Moscow and Pyongyang have issued similar denials in the past, despite repeated evidence linking them to hacking campaigns targeting Western infrastructure, election systems, and defense contractors.

One of the report’s most striking revelations involves North Korea’s use of AI-generated personas to infiltrate U.S. companies.

According to Microsoft, North Korean hackers are using AI tools to create fake American identities, complete with realistic résumés, LinkedIn profiles, and video interviews. These false personas apply for remote tech jobs in the U.S., allowing North Korean intelligence agencies to earn hard currency while secretly inserting malware into corporate systems.

Once hired, these operatives gain access to sensitive data and intellectual property, which they exfiltrate to Pyongyang. The regime then uses the stolen information to bypass sanctions and fund its nuclear and missile programs.

“Cyber is a cat-and-mouse game,” said Nicole Jiang, CEO of Fable, a San Francisco cybersecurity firm. “Access, data, information, money — that’s what they’re after. AI just makes it easier to deceive.”

A new era of digital deception

The Microsoft report concludes that AI has ushered in a new era of global cyber warfare, blurring the lines between traditional espionage, information manipulation, and criminal hacking.

Fake content created by AI — including videos, news articles, and social media posts — is increasingly indistinguishable from real material, posing serious challenges for governments and tech companies trying to detect and counter disinformation.

“AI allows bad actors to operate at a scale and speed we’ve never seen before,” Microsoft warned. “What once took days or weeks of manual work can now be done in seconds.”

To combat the growing threat, the company called for stronger international cooperation, AI-driven defense systems, and public awareness campaigns to help citizens identify manipulated content.

As nations race to harness artificial intelligence for economic and military purposes, Microsoft said the world must also confront its darker side.

“Technology itself is neutral,” Hogan-Burney concluded. “But how it’s used — that’s where the danger lies. The next front line of conflict is not on land, sea, or air. It’s online.”

(Source: The Associated Press)

Politics Today is dedicated to publishing insightful analyses in order to understand the changing nature of contemporary politics. It aims to contribute to the sound and constructive discussion of international affairs.