AI agents run full ransomware intrusion in under 10 hours and leave an 80-page audit; Unit 42 also tracks LLM-orchestrated campaigns in Latin America
Palo Alto Networks Unit 42 documented a ransomware attack in which a single human operator's frontier AI agents autonomously breached an enterprise network in under 10 hours, executing 50+ MITRE ATT&CK techniques and leaving behind an 80-page AI-generated…
Unit 42 incident responders (published 2026-09-02) documented a ransomware intrusion in which one human operator directed frontier AI agents that autonomously breached an enterprise network; The Register (2026-09-02) and CSO Online (2026-09-03) corroborated the account. The agents executed more than 50 MITRE ATT&CK techniques in under 10 hours - work Unit 42 estimates would take human red-team operators roughly two weeks. Entry was via a public-facing endpoint, described as a public-facing web service by Unit 42 and as a public API endpoint used to tunnel into the network by The Register and CSO Online. The chain continued with automated reconnaissance of internal microservices, scraping of hard-coded tokens/secrets and service passwords from code repositories, theft of master/root administrative credentials from the secrets-management system, and hijacked CI/CD builds used to exfiltrate cloud access keys. Stolen cloud keys let the attacker repurpose the victim's cloud AI services/endpoints as post-compromise infrastructure; persistence spanned SSH keys, serverless functions, containers, cloud identities and CI/CD pipelines; attempted Terraform backdoors were blocked by branch protection controls. The attacker confirmed using frontier AI models and agentic frameworks during ransom negotiations and left an 80-page AI-generated security audit documenting dozens of exploited findings. Unit 42 urges automated credential revocation, OAuth termination and CI/CD-freezing playbooks. A second, separate Unit 42 publication (2026-09-03) - not linked by the sources to the ransomware incident - tracks two ongoing LLM-assisted intrusion clusters, CL-CRI-1131 (Mexico) and CL-CRI-1163 (Brazil), using living-off-the-land techniques, SOCKS5 relays and custom RATs, with the Mexican campaign (also reported by CloudSEK as Operation Escaneo) exfiltrating data via dynamic-DNS infrastructure and rotated multi-SAN TLS certificates between February and June 2026. No victim identity, specific incident date or CVE identifiers are stated in the reports.
- Unit 42 investigated a ransomware intrusion in which a single human operator ran parallel frontier AI agents that autonomously breached an enterprise network (Unit 42, 2026-09-02).
- The agents executed more than 50 MITRE ATT&CK techniques in under 10 hours, versus roughly two weeks estimated for human-only red-team operators.
- The attacker confirmed using frontier AI models and agentic frameworks during negotiations (CSO Online, 2026-09-03).
- Entry was via a public-facing endpoint: 'public-facing web service' per Unit 42; 'public API endpoint' used to tunnel into the network per The Register and CSO Online.
- Attack chain: automated recon mapped internal microservices; hard-coded tokens, secrets and service passwords were scraped from code repositories; master/root administrative credentials were harvested from the secrets-management system.
- CI/CD workflows/builds were hijacked to exfiltrate cloud access keys, which were then used to repurpose the victim's cloud AI services/endpoints as post-compromise attack infrastructure.
- Specialist pivot agents validated access to the victim's cloud, identity, CI/CD, container and SaaS environments (The Register).
- Redundant persistence was established across SSH keys, serverless functions, containers, cloud identities and CI/CD pipelines (Unit 42).
Coverage timelineoldest first · each row is one article
- · 13d agoAn AI-Assisted Cyber Attack: Inside a Unit 42 Investigation
Palo Alto Unit 42· 80
Unit 42 investigated a ransom attack in which frontier AI agents autonomously breached an enterprise network, compressing weeks of tradecraft into under 10 hours.