Unit 42 investigated a ransomware incident in which a human-directed threat actor used frontier AI models and attack-specific agentic frameworks to compromise an enterprise network in under 10 hours—activity assessed to resemble roughly two weeks of coordinated red-team work. After exploiting a public-facing API endpoint, the automated operation used more than 50 MITRE ATT&CK techniques to enumerate internal services, harvest repository secrets, compromise the organization’s secrets-management platform, and abuse CI/CD workflows.
The attackers used stolen cloud credentials to access the victim’s AI infrastructure and attempted to establish Terraform backdoors, although branch-protection controls blocked that persistence attempt. The operators also left an 80-page technical audit detailing the weaknesses they had exploited, underscoring how AI agents can rapidly automate established intrusion tradecraft without relying on a zero-day flaw or exceptional operator capability.

Track how attackers are adapting to this technology.
9 events from the most recent confirmed update back to the earliest known activity.
Unit 42 observed parallel calls to frontier AI agents, structured Markdown files shared across agents or sessions, and custom scripts assessed with high confidence to be AI-generated. The attacker also left an approximately 80-page report documenting exploited security weaknesses.
Unit 42 responded to the ransomware incident and assessed that AI-enabled agents compressed activity comparable to roughly two weeks of coordinated human red-team work into less than 10 hours. The actor told Unit 42 during negotiations that it used frontier AI models and attack-specific agentic frameworks.
The intrusion established persistence through SSH keys, serverless functions, container restart policies, cloud identities, and CI/CD pipelines.
The attacker attempted to implant backdoors in Terraform configurations, but the victim's branch-protection controls prevented the modifications.
The attacker used stolen cloud keys to invoke and hijack the victim's cloud AI endpoints and used victim compute resources for subsequent malicious activity.
The attacker hijacked an enterprise code application through custom workflows to exfiltrate cloud access keys and triggered unauthorized CI/CD builds.
Using exposed tokens, the attacker accessed the victim's secrets-management system, harvested master administrative credentials, and obtained root-level system control.
Automated reconnaissance mapped internal microservices, while sub-agents searched enterprise code repositories for hard-coded tokens and service passwords.
A human-directed threat actor breached a public-facing API endpoint and tunneled into the victim enterprise network, using an operation Unit 42 assessed as AI-assisted.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
9 references tracked. Mallory keeps watching after this page renders.
cyberaccord.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcecyberveille.ch
Open sourcemalware.news
Open sourcedatabreaches.net
Open sourcescworld.com
Open sourcetheregister.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.