AI Driven Cyberwarfare and National Security
Artificial intelligence has quietly enhanced the structure of modern conflict. Earlier cyber-attacks were solely dependent on the skills and patience of human beings, but now in the technology driven world artificially intelligent algorithms are able to create realistic deep fakes, phishing emails and along with that they can easily refine malicious codes, analysis of the network at the speed that no human professionals can match. An example includes, in April 2024, a hacker group called TA547 also known as Scully Spider used Aito write the hacking codes. It was a PowerShell script which helped in installing a malware called Rhadamanthys which steals sensitive information like password and data. A cybersecurity company named Proofpoint identified that, this attack targeted organizations in Germany. Artificial intelligence is not developing completely new forms of threat but they significantly reduce the cost, enhances the speed and extends the impact of existing threats. It infers that India must turn from a reactive approach to a preventive defensive strategy, intelligence driven and independent cyber strategies so as to protect its strategic infrastructure, societal trust and strategic self-reliance in the years ahead. Analytically, this pattern can be understood as scaling up of the cyber operation. AI does not replace a threat actor instead it lowers the skills, time and resources required to execute an operation. Therefore, the strategic impact is the expansion of the adversary and the reduction in the defensive response time.
Introduction
In modern times, warfare begins on a screen rather than on a battlefield. In a single generation, cyberspace has become the 5th domain of warfare in addition to land, sea, air and space in which AI act as an enhancer which redefines this domain. Microsoft Threat Intelligence team was monitoring more than 300 different threat actors including 160 nation state groups, their findings come to the point that several states were already experimenting with large language models to improve their attacks, it includes data collection to deceptive exploitation. On the security side, the Indian Computer Emergency Response Team (CERT-In) dealt with over 29.44 lakh cyber issues in the year 2025 exclusively, announcing 1530 alerts and 390 vulnerability notes amid escalating artificial intelligence powered scams, phishing and ransomware which aims at the critical digital infrastructures.
The issue is highly significant for India, as being surrounded by two nuclear armed neighbors and increased dependency on digital public infrastructure such as Digi locker, UPI, Aadhaar makes the country in situation they cannot consider, AI Enhanced Cyber Warfare just as a hypothetical concern. AI driven cyber warfare is considered as an immediate strategic concern that already disrupts hospital, banks, defense system, the perception and thinking of the ordinary citizen. Therefore, this article puts forward a simple and time sensitive question: How AI is changing the nature of cyber warfare and what India must do, to secure itself in the evolving digital battlefield? India strategic steadiness relies much on digital confidence as on territorial defence this thought made me frame this question
This creates a digital security dilemma as, the same digital infrastructure that enhances the efficiency of the nation also contributes to nation’s insecurity. Thus, the protection of national security must be assessed through a combination of military preparedness, backup systems and public trust.
How does AI change cyberwarfare in terms of speed, scale and deception?
Cyber-attacks are transformed by AI in three measurable dimensions which includes speed, scale and deception. Regarding scale and speed, the Joint Report of Microsoft and open AI have mentioned several state sponsored threat groups using large language models for activities such as satellite and radar-based intelligence gathering to phishing email generations. These states include Russia, North Korea, Iran, China, but these reports do not cover the complete list of all countries who uses AI in cyber operations instead it includes only the cases of misuse that researches were able to observe. These reports indicates that LLM did not implement new skills but significantly shortened the time required by human labor to two minutes of machine output, which made attacking faster.
These three dimensions are analytically interconnected rather than separate. Greater speed increases the number of operations that can be attempted, greater scale multiplies the number of targets, and greater deception weakens the human processes used to verify information. Together they create a continuous cycle in which technical efficiency produces strategic and psychological effects.
Regarding deception AI is significant as it helps in manipulating human thinking rather than just attacking technical systems. The best example that shows deception includes in March 2022 soon after Russia’s invasion of Ukraine, a deep fake video showing President Vladimir Zelinsky ordering his soldiers to surrender was placed by hackers on Ukraine 24 news ticker. Despite the technical limitations it was considered as the first deep fake that was purposefully used as a weapon in the war and experts noted it as the start of a wider information warfare. In January 2024, two years later, a finance employee of the engineering firm ARUP transferred 25 million US dollars after attending a video conference in which every other participant was AI generated including the chief financial officer. This strategic and financial cases show that deepfake technologies can be directed against citizens, soldiers and stakeholders alike. Deception is the most dangerous among all these dimensions as it focuses on decision making of humans rather than digital systems.
Case Study I- Not Petya (2017)
Not Petya has already shown what a single piece of code could do, even before AI entered into picture. It was released in June 2017 through a hacked Ukrainian Tax software update and later through investigation found out that it is related to Russian military intelligence, within certain hours the malware had expanded across the Ukraine. It caused destruction to certain global companies like Maersk, Merck and FedEx with damages of more than 10 billion US dollars. It is considered as one of the most destructive cyber-attacks in the history at that time. Not Petya is an important case study for this article because it acts as a pre-AI example. It shows that, a single cyber weapon can cause global destruction even without AI, so with the use of AI, cyberattacks will become even more dangerous, harder to control and more precise. This case study act as the foundation for the study showing if a pre malicious software can cause such a global damage, the effects of AI enabled alternatives require immediate concern.
Case Study II– AIIMS Delhi Ransomware (2022)
India received its own clear warning on 23rd November 2022 when the was disrupted by a malware attack that encoded the data of millions of people including senior politicians and administrators, which forced the hospital to run in a paper-based system for almost two weeks. The investigators found digital traces linking the operation to Hong Kong and Henan province in China. As per the investigation the encoded files and Proton Mails used in the attack were linked to these locations. However, the exact hackers were not identified. The AIIMS cyber-attack was notable not only because of its system disruption but because, it also made clear how vulnerable is India’s critical infrastructures like hospitals, transports facilities and public services, which reveals India’s systems are still vulnerable to hackers linked with foreign governments. According to the CERT-In data cyber incidents have increased from 14 lakh to 29.44 lakh in the years of 2021 to 2025, which confirms that AIIMS was not an individual attack but was part of a widening warfare, as the cases are more than doubling in four years. In my opinion AIIMS attack was a critical moment for India as it exposed the weaknesses in public services targeted by foreign actors.
Case Study -III (Zelensky Deepfake (2022) And Arup Fraud (2024))
The Zelensky and Arup deepfake cyber-attacks introduced Deception Frontier. Public morale during armed conflict was the target of Zelensky deepfake, and Arup deepfake targeted on the financial reserves of an engineering firm during a usual video conference. In the Arup case the Hong Kong police found out that scammers used AI generated videos and voices of different company officers, convincing a junior finance officer and made him transfer 200 million Hong Kong dollars to 15 bank accounts. For India where the financial fraud being the most registered crime, this case study shows a serious risk that AI driven deep fakes can scam humans and overcome security checking and systems because they completely believe in humanly faces and voices.
The comparison also shows that deception operates across different levels of security. In the Zelensky case it sought to influence collective behavior during conflict, whereas in the Arup case it manipulated an individual decision inside an organization. The common mechanism is the exploitation of trust, which makes human verification a central part of cyber defence.
Key Effects on India
AI provides very little time for the military and political leaders for decision making which is a major concern. The idea of traditional deterrence theory weakens in cyber warfare due to the attribution problem. Since the impact is sudden India began to respond through various organizations like CERT-In, the Defense Cyber Agency and also through AI based border surveillance. It shows that nearly 3 million cyber-attack incidents have been reported in 2025. Even though India’s defensive capabilities are increasing, incidents like AIIMS cyber-attack proves that cyber defense should be more advanced and intelligence led. India’s key challenge lies in the attribution problem which controls both deterrence and fast reaction.
This suggests that India’s principal vulnerability is not simply the absence of technology, but the interaction between technological dependence, shared accountability, and limited attribution. A resilient strategy should therefore combine prevention, rapid recovery, and credible attribution, because deterrence is weakened when an attack cannot be confidently linked to its source.
Conclusion
AI driven cyber warfare is not a future threat it is an ongoing existing threat, that states like India should work on. The same AI system that are used to advance healthcare, governance and transport systems can be applied for espionage, deception and disruption. The Not Petya attack, Zelensky Deepfake, Arup Deepfake and AIIMS malware attack show that each era of attack is more advanced, faster, cheaper and harder to trace. These four case studies show that AI can increase the intensity of cyber-attacks.
When it comes to India, the government responses cannot be reactive every time. It must unite autonomous AI capability, public private cooperation, long term investment in CERT-In, cyber commands and in addition to that digital literacy of the citizen must be enhanced as citizens act as ultimate defense against deepfake attacks and wrong information’s. In the current digitalized world national security is not just the protection of borders but also of digital systems, screen and human perception. National security in the AI era should be a combined responsibility of both state and citizen. It is necessary for the stability of India’s digital systems.
The broader implication is that national cyber resilience should be measured by the ability to absorb, continue and recover from disruption, rather than only by the ability to prevent every intrusion. This shifts the policy focus from a purely reactive security model towards comprehensive resilience involving technology, institutions, and citizens.
References:
1.Microsoft Threat Intelligence (2024). Staying Ahead of Threat Actors in the Age of AI. Microsoft Security Blog, 14 February 2024. https://www.microsoft.com/en-us/security/blog/2024/02/14/staying-ahead-of-threat-actors-in-the-age-of-ai/
2.Press Information Bureau, Government of India (2025). CERT-In: India's Frontline Defender against Cyber Threats. https://www.pib.gov.in/PressReleasePage.aspx?PRID=2217537®=3&lang=1
3.Greenberg, A. (2018). The Untold Story of NotPetya, the Most Devastating Cyberattack in History. WIRED, 22 August 2018.
https://www.wired.com/story/notpetya-cyberattack-ukraine-russia-code-crashed-the-world/
4.Allyn, B. (2022). Deepfake Video of Zelenskyy Could Be 'Tip of the Iceberg' in Info War, Experts Warn. NPR, 16 March 2022.
5.Chen, H. & Magramo, K. (2024). Finance Worker Pays Out $25 Million after Video Call with Deepfake 'Chief Financial Officer'. CNN, 4 February 2024.
https://www.cnn.com/2024/02/04/asia/deepfake-cfo-scam-hong-kong-intl-hnk
6.MediaNama (2024). China-Backed Hacker Group Behind 2022 AIIMS Attack: Report. 24 June 2024.
https://www.medianama.com/2024/06/223-china-backed-hacker-group-behind-aiims-attack-report/
7.CyberPeace Foundation (2025). AI-Powered Espionage: How India's Cybersecurity Strategy Must Evolve.
8.CERT-In (2025). Annual Report 2024. Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology, Government of India.
https://www.cert-in.org.in/Downloader’pageid=22&type=2&fileName=ANUAL-2025-0001.pdf
9.Kirk, J. (2024). Proofpoint: 'TA547' Used AI-Written PowerShell in German Phishing Campaign. Proofpoint Threat Insight Blog, April 2024.
10.World Economic Forum (2025). Building security into India's digital public infrastructure. WEForum.org, October 2025.
https://www.weforum.org/stories/2025/10/security-by-design-india-digital-public-infrastructure/
11.CloudSEK (2025). Annual ThreatLandscape Report 2024. CloudSEK Research, January 2025.
https://www.cloudsek.com/whitepapers-reports/cloudsek-annual-threat-landscape-report-2024
12.Microsoft (2024). Microsoft Digital Defense Report 2024. Microsoft Security, October 2024.
13.National Cyber Security Centre (2024). The near-term impact of AI on the cyber threat. NCSCUK, 24 January 2024.
https://www.ncsc.gov.uk/report/impact-of-ai-on-cyber-threat
14.Gandhi, P., & Pahwa, S. (2024). All India Institute of Medical Sciences (AIIMS), Delhi: Cyberattack puts digitalisation under scanner. IMIB Journal of Innovation and Management. https://doi.org/10.1177/ijim.241240911
(The views expressed are those of the author and do not represent the views of CESCUBE)
Photo by Steve A Johnson on Unsplash
Irina Treasa Jomy is a third semester B.Sc. Defence and Strategic Studies student at Rashtriya Raksha University, Karnataka Campus. Her research interests include national security, geopolitics, strategic studies, cyber warfare, artificial intelligence, emerging technologies, maritime security, and regional security. She has a particular interest in the shifting nexus of technology and national security, including AI-enabled cyber warfare, geopolitical trends, strategic alliances, and the security impact of emerging technologies. She has presented her research on deterrence theory in cyber warfare at a criminological conference in Navi Mumbai.