An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation | #ransomware | #cybercrime


Unit 42 responded to an incident where a human attacker used frontier AI to breach an enterprise network autonomously as part of a ransom attack. The agents breached the company’s security layers in a methodical manner, each targeting a different layer of defense to achieve a shared goal. The impact was at the scale of a coordinated effort from multiple red teams, which would normally take human operators around two weeks.

The threat actor told us in negotiations that they leveraged frontier AI models and attack-specific agentic AI frameworks. By shifting execution to an automated loop, the attacker compressed weeks of methodical intrusion tradecraft (using more than 50 MITRE ATT&CK techniques) into less than 10 hours.

After they gained initial access, the attacker used agents to map the internal architecture, raid source repositories and seize root credentials. The agents also triggered unauthorized continuous integration/continuous delivery (CI/CD) builds and claimed master keys to the victim’s cloud AI infrastructure.

What made the attack stand out was AI-assisted operational efficiency, without the need for a novel zero-day or super elite tradecraft. The attacker left tactical execution to AI agents that monitored, evaluated, acted and re-planned in real time, increasing speed throughout the attack chain.

The attacker also directed the agent to leave behind a “report” on the organization’s security posture: an 80-page, technical audit detailing dozens of exploited findings.

Inside the Machine-Speed Attack Chain

The adversary ran their operation using current AI-enabled software development processes. We observed multiple indicators consistent with AI usage:

The 10-hour operational timeline included the following:

Figure 1 maps the AI-orchestrated workflow.

Figure 1. AI-orchestrated intrusion workflow. The actor sets objectives and makes consequential decisions. Specialized agents execute, share results and adapt in real time.

Unified Threat Framework Mapping

For illustration, Table 1 below maps some of the techniques used against the MITRE ATT&CK and ATLAS frameworks:

Intrusion StageThreat Actor ActionMITRE ATT&CK® MappingMITRE ATLAS™ (AI-Specific) Mapping
Initial Access and ReconPublicly accessible web service breach; automated service mapping via service discovery toolT1190: Exploit Public-Facing Application

T1046: Network Service Discovery

AML.T0000: Initial Access

AML.T0002: AI-Automated Reconnaissance

Credential AccessCode scraping for secrets across code reposT1552.001: Credentials In FilesAML.T0014: Credentials Harvesting
Privilege EscalationInfiltrating secrets manager to harvest admin system secretsT1555: Credentials from Password StoresAML.T0016: Privilege Escalation via Automated Pivot
Pipeline AbuseExecuting CI/CD actions; attempting cloud provisioning tool editsT1578: Modify Cloud Compute InfrastructureAML.T0010: ML/DevOps Pipeline Interception
AI Infrastructure AbuseInvoking cloud AI models via stolen keysT1078: Valid AccountsAML.T0043: LLM Invocations via Stolen API Keys

Table 1. Major MITRE ATT&CK and MITRE ATLAS techniques used by the attacker.

Key Lessons: Addressing Agentic Attacks

This incident exposes how an attacker who understands how to deploy frontier AI agents effectively can dramatically speed up the pace of their attack. We assess that attackers will increasingly add AI agents to their tool sets. Organizations should take note of the following to address agentic attacks:

Defending Against Machine-Speed Attacks

Defending against automated agent loops requires matching the speed and adaptability of AI-driven attacks:

Learn more about how Unit 42 can help defend against AI-driven threats through Unit 42 Frontier AI Defense.

Updated Sept. 3, 2026, at 5:25 a.m. PT to clarify that the attack was an intrusion, and not a ransomware attack. 

Updated Sept. 4, 2026, at 6:42 a.m. PT for minor clarifying copyedits. 



Click Here For The Original Source.

——————————————————–

..........

.

.