This incident report from Unit 42 details a sophisticated ransomware attack where human operators utilized frontier AI and agentic frameworks to autonomously navigate and breach an enterprise environment. By delegating tactical execution to AI agents, the attackers were able to compress a multi-week intrusion process—involving over 50 MITRE ATT&CK techniques—into a timeframe of less than 10 hours. The operation showcased a high level of efficiency, targeting public APIs, code repositories, and CI/CD pipelines to gain root access and hijack cloud AI infrastructure.
The attackers leveraged AI for rapid reconnaissance, secrets harvesting, and establishing redundant persistence across various layers of the network. Notable indicators of this machine-speed attack included parallel LLM calls, the use of structured Markdown for data passing between agents, and AI-generated scripts. To defend against such automated threats, the report emphasizes the need for synchronized containment playbooks, strict governance of AI infrastructure, and the detection of behavioral loops that signify automated agent activity.
Top comments (0)