< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

2 clusters · 5 sources · 5 days · First seen · Last updated

AI-driven ransomware intrusion escalation

Overview

Researchers at Palo Alto Networks’ Unit 42 identified a ransomware intrusion where attackers utilized AI agents to accelerate network movement. The intrusion was completed in under 10 hours, a process estimated to take human operators approximately two weeks to perform manually. The attack involved over 50 techniques, using frontier AI models and agentic frameworks to conduct reconnaissance, search source-code repositories for credentials, and hijack enterprise code applications to exfiltrate cloud access keys.

Further details revealed that the attack began by compromising a publicly accessible API. Specialized AI agents worked in parallel to map internal microservices and search for embedded tokens, allowing the attacker to gain root access and move into cloud environments. In a notable development, the attacker repurposed the victim company’s own cloud AI services to provide the computational resources for the attack, masking malicious traffic as legitimate activity.

The breach demonstrated high operational efficiency through an “observe-decide-execute-replan” loop. In a highly unusual move, the attacker used a specific AI agent to document the security flaws discovered during the breach, leaving behind an 80-page technical report detailing dozens of vulnerabilities.

Entities

Unit 42 · Palo Alto Networks · MITRE ATT&CK · Greyhound Research · AWS

Timeline

  1. 5 days ago

    [TECHNOLOGY] 3 sources
    AI agents accelerate ransomware attack to under 10 hours

    A ransomware attack using AI agents completed in under 10 hours a task that usually takes humans two weeks, according to Palo Alto Networks' Unit 42.

  2. 9 days ago

    [TECHNOLOGY] 2 sources
    AI agents accelerate ransomware intrusion to under 10 hours

    Palo Alto Networks researchers report that ransomware attackers used AI agents to compress network intrusion times from weeks to under 10 hours, using adaptive frameworks to automate tactical tasks.

Sources

atmarkit.co.jp · csoonline.com.au · cybernoz.com · informacija.rs · scan.netsecurity.ne.jp