ZeroHour
Story · 1 source · 1 articlefirst updated ()

AI agents run full ransomware intrusion in under 10 hours and leave an 80-page audit; Unit 42 also tracks LLM-orchestrated campaigns in Latin America

highThreat actorexploited in the wildimportance 80
What's new: First merged summary for this story - no previous dashboard entry. The merge covers four reports filed 2026-09-02 to 2026-09-03: Unit 42's original disclosure of the agentic ransomware intrusion (2026-09-02), corroborating coverage from The Register and CSO Online that added the attacker's confirmation of frontier-AI use during negotiations, the blocked Terraform backdoor attempt, the pivot-agent…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Palo Alto Networks Unit 42 documented a ransomware attack in which a single human operator's frontier AI agents autonomously breached an enterprise network in under 10 hours, executing 50+ MITRE ATT&CK techniques and leaving behind an 80-page AI-generated…

Unit 42 incident responders (published 2026-09-02) documented a ransomware intrusion in which one human operator directed frontier AI agents that autonomously breached an enterprise network; The Register (2026-09-02) and CSO Online (2026-09-03) corroborated the account. The agents executed more than 50 MITRE ATT&CK techniques in under 10 hours - work Unit 42 estimates would take human red-team operators roughly two weeks. Entry was via a public-facing endpoint, described as a public-facing web service by Unit 42 and as a public API endpoint used to tunnel into the network by The Register and CSO Online. The chain continued with automated reconnaissance of internal microservices, scraping of hard-coded tokens/secrets and service passwords from code repositories, theft of master/root administrative credentials from the secrets-management system, and hijacked CI/CD builds used to exfiltrate cloud access keys. Stolen cloud keys let the attacker repurpose the victim's cloud AI services/endpoints as post-compromise infrastructure; persistence spanned SSH keys, serverless functions, containers, cloud identities and CI/CD pipelines; attempted Terraform backdoors were blocked by branch protection controls. The attacker confirmed using frontier AI models and agentic frameworks during ransom negotiations and left an 80-page AI-generated security audit documenting dozens of exploited findings. Unit 42 urges automated credential revocation, OAuth termination and CI/CD-freezing playbooks. A second, separate Unit 42 publication (2026-09-03) - not linked by the sources to the ransomware incident - tracks two ongoing LLM-assisted intrusion clusters, CL-CRI-1131 (Mexico) and CL-CRI-1163 (Brazil), using living-off-the-land techniques, SOCKS5 relays and custom RATs, with the Mexican campaign (also reported by CloudSEK as Operation Escaneo) exfiltrating data via dynamic-DNS infrastructure and rotated multi-SAN TLS certificates between February and June 2026. No victim identity, specific incident date or CVE identifiers are stated in the reports.

  • Unit 42 investigated a ransomware intrusion in which a single human operator ran parallel frontier AI agents that autonomously breached an enterprise network (Unit 42, 2026-09-02).
  • The agents executed more than 50 MITRE ATT&CK techniques in under 10 hours, versus roughly two weeks estimated for human-only red-team operators.
  • The attacker confirmed using frontier AI models and agentic frameworks during negotiations (CSO Online, 2026-09-03).
  • Entry was via a public-facing endpoint: 'public-facing web service' per Unit 42; 'public API endpoint' used to tunnel into the network per The Register and CSO Online.
  • Attack chain: automated recon mapped internal microservices; hard-coded tokens, secrets and service passwords were scraped from code repositories; master/root administrative credentials were harvested from the secrets-management system.
  • CI/CD workflows/builds were hijacked to exfiltrate cloud access keys, which were then used to repurpose the victim's cloud AI services/endpoints as post-compromise attack infrastructure.
  • Specialist pivot agents validated access to the victim's cloud, identity, CI/CD, container and SaaS environments (The Register).
  • Redundant persistence was established across SSH keys, serverless functions, containers, cloud identities and CI/CD pipelines (Unit 42).

Coverage timeline

  1. · 13d ago
    Palo Alto Unit 42· 80
    An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation

    Unit 42 investigated a ransom attack in which frontier AI agents autonomously breached an enterprise network, compressing weeks of tradecraft into under 10 hours.