From Cybercrime-as-a-Service to Agentic AI: AI agents reshape the attack chain – September 2026 | #cybercrime | #infosec


A potential paradigm shift: from Cybercrime-as-a-Service (CaaS) to agentic AI

The emerging agentic AI model changes the division of labour: instead of coordinating multiple human-operated services, an attacker can increasingly delegate reconnaissance, exploitation, persistence, data processing and post-compromise activity to AI agents. Recent cases involving retail intrusions, cloud environments, Docker botnets and AI-integrated malware suggest that AI is moving beyond assisting individual tasks towards managing substantial portions of the attack chain.

A series of cyber incidents and threat-research disclosures in September 2026 point to a potential paradigm shift in the organisation of cybercrime, from Cybercrime-as-a-Service (CaaS) to Agentic AI. CaaS industrialised cybercrime by allowing human operators to purchase or outsource specialised capabilities such as malware, initial access, credentials and infrastructure.

The most concrete indication of agentic AI penetration into cybercrime comes from a campaign investigated by Gambit Security in which three open-source AI-agent frameworks were reportedly used against organisations across retail, hospitality and aviation. Inside the math: Researchers identified 105 attack projects between 10 and 15 September, with at least 27 organisations compromised to varying degrees and more than 600,000 payment-card records reportedly obtained. The agents were used across reconnaissance, vulnerability discovery, exploitation, persistence and post-compromise activity, with human involvement reduced largely to providing objectives and orchestration.

Microsoft has meanwhile documented Storm-3168 activity in Azure involving compromised service principals that performed extensive reconnaissance before executing more than 150 destructive or credential-related operations in a 35-minute sequence, including attempts to delete cloud resources and access credentials. Uncovered by ThreatDown in September 2026 with operational evidence spanning October 2024 to August 2026,

CARBONATO is an AI-powered botnet that exhibits worm-like behavior by scanning neighboring networks every five minutes for exposed, unauthenticated Docker APIs on port 2375. Once a target is found, it instructs the daemon to launch a privileged container for full host access, installs the open-source Hermes Agent framework for persistence and credential collection, and executes remotely directed post-compromise tasks via Telegram.

Agentic AI systems introduce a different architecture in which large language models can become the primary operational layer executing reconnaissance, choosing attack paths, invoking tools and processing results. CLOSEDQUORUM illustrates an even deeper integration: the Windows implant can query DeepSeek, Qwen, Mistral and Google Gemini and use a majority decision to select tactical actions such as credential or cryptocurrency-wallet theft, process injection and persistence. Cisco Talos describes this as “effort displacement”, although it has not confirmed real-world deployment and the available binary is an incomplete template.

Earlier forms of AI-enabled cybercrime largely followed a copilot model: humans selected targets and directed operations while AI helped write code, generate phishing content or analyse information. Meanwhile, these cases, taken together, suggest that the significant technological development is not simply the increased use of generative AI by criminals, but the delegation of operational decision-making to agentic AI systems. The emerging trajectory moves from AI as a tool, to a sidekick, to an operator, and finally to a component of the attack infrastructure. The distinction matters because autonomy and scale can increasingly become properties of the attack architecture itself rather than simply of the human attacker.

Why does it matter?

The emergence of agentic cybercrime marks a transition from automating cybercrime tools to automating the cybercrime process itself. CaaS lowered the technical barrier by allowing criminals to purchase specialised capabilities; Cybercrime-as-a-Sidekick could lower the operational barrier by allowing a much smaller number of humans to orchestrate agents performing the work of reconnaissance, exploitation, persistence and data exploitation at scale.

This convergence between AI agents, cloud infrastructure, open-source frameworks and cybercrime creates a new adversarial-AI landscape in which accountability, human oversight, secure agent design, access controls and responsibilities of AI and infrastructure providers become increasingly central to cybersecurity governance. This connects the evolution of cybercrime directly with the broader governance of increasingly capable AI: the issue is no longer simply how criminals use AI, but how much of a criminal operation AI can conduct on their behalf.

The immediate challenge is that this evolution could alter both the economics and tempo of cyber operations. An agent capable of continuously scanning targets, adapting to responses and executing multi-stage workflows can potentially compress hours or days of human labour into machine-speed processes. Microsoft itself has warned that attackers are using agents to automate execution at unprecedented scale, while also arguing that security operations must adapt to AI speed. Yet the transition should not be interpreted as the disappearance of human operators. Current cases continue to show humans setting objectives, supplying access, selecting targets or controlling infrastructure. The more immediate risk is therefore progressive delegation, rather than complete autonomy.

This creates new defensive and governance challenges: conventional detection based on fixed malware or dedicated Command and Control (C2) infrastructure may become less effective; legitimate AI and cloud services can become part of malicious workflows; and open-source agent frameworks can be repurposed as offensive infrastructure.

The central pending question is how quickly defensive architectures, identity controls, cloud security and AI-provider safeguards can adapt to systems capable of operating across multiple stages of an intrusion.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!



Click Here For The Original Source.

——————————————————–

..........

.

.