Unit 42: AI agents complete ransomware intrusion in under 10 hours; LLM-orchestrated campaigns target Latin American government, utilities, and finance (CL-CRI-1131, CL-CRI-1163)
Palo Alto Networks Unit 42 disclosed (2026-09-03) a ransomware intrusion completed by AI agents in under 10 hours — work estimated at roughly two weeks for human operators — using 50+ MITRE ATT&CK techniques. It also tracks two ongoing AI-assisted clusters in…
Two Unit 42 disclosures on 2026-09-03 (reported by CSO Online and Unit 42) plus a 2026-09-10 follow-up (GBHackers) describe AI-accelerated intrusions. In the ransomware case, AI agents moved through an enterprise network in under 10 hours, work Unit 42 estimates would have taken human operators roughly two weeks, and used over 50 MITRE ATT&CK techniques. The attacker entered via a public-facing API endpoint, ran automated reconnaissance to map microservices, searched source-code repositories for credentials, and accessed a secrets-management system. They hijacked enterprise code workflows to exfiltrate cloud access keys, attempted Terraform backdoors that were blocked by branch protection controls, and used stolen credentials to access the victim's own AI services as attack infrastructure; the actor confirmed using frontier AI models and agentic frameworks during negotiations. Separately, Unit 42 tracks two ongoing AI-assisted intrusion clusters in Latin America: CL-CRI-1131, which compromised a transportation organization, Mexican federal ministries, and water utilities in Mexico and Ecuador (CSO Online/Unit 42 initially described municipal water utilities in Mexico), and CL-CRI-1163, which targeted Brazilian financial organizations. Both clusters use living-off-the-land techniques, SOCKS5 relays, and custom RATs, and appear orchestrated via commercial LLMs such as Claude and GPT-4.1 accessed behind a self-hosted NextChat interface, evidenced by iterative batch scripts, AI-generated tunneling tool naming, and exposed NextChat instances and open directories revealing iterative, LLM-assisted script development and attacker staging environments. CL-CRI-1131 used native Windows tools and Volume Shadow Copies to dump the SAM registry hive and NTDS.dit, and — also reported by CloudSEK as Operation Escaneo — exfiltrated sensitive data via dynamic-DNS infrastructure using rotated multi-SAN TLS certificates between February and June 2026, with rotating certificates exposing target profiles including geolocation, intel, and vaccines subdomains. CL-CRI-1163 used job-themed phishing, custom RATs, and a Go-based reverse SOCKS5 tunneling utility named SockTz, with nine versions deployed within roughly two hours. GBHackers adds that Trend Micro tracks related AI-augmented activity as SHADOW-AETHER-040 and SHADOW-AETHER-064, and Unit 42 advises defenders to watch for shadow-copy activity, SAM/NTDS.dit access, numbered script creation, anomalous SOCKS5 tunnels, and…
- Unit 42 investigated a ransomware incident where AI agents completed the intrusion in under 10 hours, vs roughly two weeks if performed manually, using over 50 MITRE ATT&CK techniques (CSO Online, 2026-09-03).
- Ransomware attack chain: entry via a public-facing API endpoint, automated reconnaissance mapping microservices, source-code repository credential search, and access to a secrets-management system.
- Attackers hijacked enterprise code workflows to exfiltrate cloud access keys; attempted Terraform backdoors were blocked by branch protection controls; stolen cloud credentials were used to access the victim's own AI services as attacker…
- The ransomware actor confirmed using frontier AI models and agentic frameworks during negotiations.
- Unit 42 tracks two AI-assisted clusters: CL-CRI-1131 (transportation organization, Mexican federal ministries, water utilities in Mexico and Ecuador) and CL-CRI-1163 (Brazilian financial sector), with overlapping/shared SOCKS5 relay…
- Both clusters use living-off-the-land techniques, SOCKS5 relays, and custom RATs, and appear orchestrated via commercial LLMs (Claude, GPT-4.1) behind a self-hosted NextChat interface (GBHackers, 2026-09-10).
- CL-CRI-1131 used native Windows tools and Volume Shadow Copies to dump the SAM registry hive and NTDS.dit; exposed NextChat instances and open directories revealed iterative, LLM-assisted script development and staging environments.
- The Mexican campaign, also reported by CloudSEK as Operation Escaneo, exfiltrated sensitive data via dynamic-DNS infrastructure with rotated multi-SAN TLS certificates between February and June 2026; rotating certificates exposed target…
Coverage timelineoldest first · each row is one article
- · 13d agoAI agents help compress ransomware intrusion to under 10 hours, raising stakes for CISOs
CSO Online· 78
Unit 42 reports AI agents compressed a ransomware intrusion from weeks to under 10 hours, using 50+ MITRE ATT&CK techniques against an enterprise network.