< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

AI agents accelerate ransomware attack to under 10 hours

Researchers from Palo Alto Networks’ Unit 42 have identified a significant ransomware attack that utilized AI agents to compress a process typically requiring two weeks into less than ten hours. The attacker used advanced AI models and agent-based frameworks to automate various stages of the intrusion, including reconnaissance, credential harvesting, and privilege escalation.

The attack began by compromising a publicly accessible API. Once inside, specialized AI agents worked in parallel: one mapped internal microservices while others searched code repositories for embedded tokens and passwords. This allowed the attacker to gain root access and move into cloud environments. Notably, the attacker repurposed the victim company’s own cloud AI services to provide the computational resources needed to sustain the attack, effectively hiding malicious traffic among legitimate activities.

While the incident did not rely on unknown zero-day vulnerabilities, it demonstrated a new level of operational efficiency through the “observe-decide-execute-replan” loop enabled by AI. In a highly unusual move, the attacker used a specific AI agent to document the security flaws discovered during the breach, leaving behind an 80-page technical report detailing dozens of vulnerabilities.

Entities

Palo Alto Networks · Unit 42