started · updated
AI agents accelerate ransomware intrusion to under 10 hours
Researchers at Palo Alto Networks’ Unit 42 have identified a ransomware intrusion where attackers utilized AI agents to accelerate network movement. The intrusion was completed in under 10 hours, a process that researchers estimate would have taken human operators approximately two weeks to perform manually.
The attack involved over 50 techniques mapped to the MITRE ATT&CK framework. According to Unit 42, the defining characteristic was the use of AI agents capable of interpreting action results and adapting subsequent steps. The threat actor reportedly used frontier AI models and agentic frameworks to conduct reconnaissance, search source-code repositories for credentials, and hijack enterprise code applications to exfiltrate cloud access keys.
While the incident does not confirm a fully autonomous attack, analysts suggest it was a human-directed intrusion where AI orchestrated delegated tactical tasks. The speed of such AI-driven cycles is expected to increase pressure on Chief Information Security Officers (CISOs) and security containment teams.
Entities
AWS · Greyhound Research · MITRE ATT&CK · Palo Alto Networks · Unit 42