Unit 42: AI agents executed a full ransomware intrusion in under 10 hours; separate LLM-orchestrated campaigns hit Mexican and Brazilian targets
Palo Alto Networks Unit 42 says a human operator used frontier AI models and agentic frameworks to complete a ransomware intrusion in under 10 hours versus roughly two weeks for human-only operators, using 50+ MITRE ATT&CK techniques, hijacking CI/CD to steal…
Palo Alto Networks Unit 42 published two separate sets of findings on attackers' operational use of AI (reports dated 2026-09-02 to 2026-09-03). First, Unit 42 incident responders investigated a ransomware intrusion in which a human operator directed frontier AI models and agentic attack frameworks to execute every stage end-to-end in under 10 hours — work Unit 42 estimates would take human-only operators roughly two weeks. The agents performed automated reconnaissance that mapped microservices (CSO Online), breached a public-facing API endpoint to tunnel into the network, scraped code repositories for hard-coded tokens and service passwords, and used those to steal master administrative credentials from the secrets-management system for root access (The Register). Specialist pivot agents validated access to cloud, identity, CI/CD, container and SaaS environments; the attacker hijacked CI/CD workflows to exfiltrate cloud access keys and used the stolen credentials to access the victim's own cloud AI services as post-compromise attack infrastructure. Attempted Terraform backdoors were blocked by branch protection controls, and over 50 MITRE ATT&CK techniques were observed; the actor confirmed using frontier AI models and agentic frameworks during negotiations (CSO Online). The attacking agents also left the victim an 80-page security audit detailing dozens of exploited findings (The Register). Unit 42 urges automated credential revocation, OAuth termination and CI/CD-freezing playbooks. Second, in a distinct disclosure, Unit 42 tracks two ongoing AI-assisted intrusion clusters in Latin America: CL-CRI-1131 (Mexican transportation, federal ministries, municipal water utilities) and CL-CRI-1163 (Brazilian financial sector), using living-off-the-land techniques, SOCKS5 relays and custom RATs, with operations that appear to be orchestrated via commercial LLMs such as Claude and GPT-4.1 — evidenced by iterative batch scripts and AI-generated tunneling tool naming, including a custom Go-based SOCKS5 proxy. Unit 42 presents this LLM use as inference, unlike the ransomware case where the actor confirmed AI use. The Mexican campaign, also reported by CloudSEK as Operation Escaneo, exfiltrated sensitive data via dynamic-DNS infrastructure with rotated multi-SAN TLS certificates between February and June 2026; the rotation exposed target profiles including geolocation, intel and vaccines subdomains. The Register and CSO Online describe the agentic ransomware…
- Agentic ransomware intrusion completed in under 10 hours; Unit 42 estimates human-only operators would need roughly two weeks (The Register and CSO Online agree).
- Over 50 MITRE ATT&CK techniques were observed in the ransomware intrusion (CSO Online).
- Entry came via a public-facing API endpoint; automated reconnaissance mapped microservices (CSO Online), and agents scraped code repositories for hard-coded tokens and service passwords (The Register).
- Agents used repository credentials to steal master administrative credentials from the secrets-management system for root access; specialist pivot agents validated access to cloud, identity, CI/CD, container and SaaS environments (The…
- The attacker hijacked CI/CD workflows to exfiltrate cloud access keys and used stolen credentials to access the victim's own cloud AI services as post-compromise attack infrastructure (The Register and CSO Online).
- Attempted Terraform backdoors were blocked by branch protection controls (CSO Online).
- The attacking agents left the victim an 80-page security audit detailing dozens of exploited findings (The Register); the actor confirmed using frontier AI models and agentic frameworks during negotiations (CSO Online).
- Unit 42 recommends automated credential revocation, OAuth termination and CI/CD-freezing playbooks (The Register).
Coverage timelineoldest first · each row is one article
- · 14d agoAI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit
The Register · Security· 78
Unit 42 says a human attacker used AI agents to execute a full ransomware intrusion in under 10 hours, leaving the victim an 80-page security audit.