What the First Autonomous Ransomware Case Confirms


Security researchers have documented an AI agent running a full ransomware operation on its own against a live production target, planning, adapting, and executing every step from the first exploit through data destruction. This is early real-world evidence of the shift to autonomous criminal operations that our research forecast.

Agent-run attacks change what defenders can rely on. They produce disposable, per-victim indicators instead of reusable tools and infrastructure, so the defensive weight shifts from sharing and blocking indicators of compromise onto behavior and technique-based detection.

The novelty is automation, not tradecraft. Every weakness the agent used was old and well understood, which concentrates exposure in organizations running internet-facing AI and automation platforms or carrying default and unrotated credentials, and shortens the time available to close those gaps.

The monetization layer failed even though the intrusion succeeded. The agent did not save the encryption key it generated and used a placeholder address instead of real payment infrastructure, so the operation could not have produced a payout even if the victim had complied.

Read more…
Source:  TrendMicro


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Cloudflare blocks another largest recorded DDoS attack – this time, peaking at 11.5 Tbps

    September 3, 2025

    Internet infrastructure provider and global cloud platform, Cloudflare, recently prevented a record-breaking Distributed Denial of Service (DDoS) attack from causing any damage. In a short announcement published on X, Cloudflare said its defenses “have been working overtime” over the past few weeks, autonomously blocking “hundreds of hyper-volumetric DDoS attacks.” Among them was an attack that reached ...

  • Zscaler says it suffered data breach following Salesloft Drift compromise

    September 3, 2025

    We can now add Zscaler to the growing list of Salesloft customers who suffered a third-party cyberattack and lost sensitive customer information after it confirmed data was taken. In the announcement, Zscaler explained it was a customer of Salesloft, whose AI chat platform, Salesloft Drift, was compromised. Since this platform connects with Salesforce, the miscreants managed ...

  • Model Namespace Reuse: An AI Supply-Chain Attack Exploiting Model Name Trust

    September 3, 2025

    Palo Alto Unit 42 research uncovered a fundamental flaw in the AI supply chain that allows attackers to gain Remote Code Execution (RCE) and additional capabilities on major platforms like Microsoft’s Azure AI Foundry, Google’s Vertex AI and thousands of open-source projects. We refer to this issue as Model Namespace Reuse. Hugging Face is a platform ...

  • Jaguar Land Rover production severely hit by cyber-attack

    September 2, 2025

    A cyber-attack has “severely disrupted” Jaguar Land Rover (JLR) vehicle production, including at its two main UK plants. The company, which is owned by India’s Tata Motors, said it took immediate action to lessen the impact of the hack and is working quickly to restart operations. JLR’s retail business has also been badly hit at a ...

  • Cookies: What they are for, associated risks, and what session hijacking has to do with it

    September 2, 2025

    When you visit almost any website, you’ll see a pop-up asking you to accept, decline, or customize the cookies it collects. Sometimes, it just tells you that cookies are in use by default. Kaspersky researchers randomly checked 647 websites, and 563 of them displayed cookie notifications. Most of the time, users don’t even pause to think ...

  • Hackers are now hiding malware in the images served up by LLMs

    August 31, 2025

    As AI tools become more integrated into daily work, the security risks attached to them are also evolving in new directions. Researchers at Trail of Bits have demonstrated a method where malicious prompts are hidden inside images and then revealed during processing by large language models. The technique takes advantage of how AI platforms downscale images ...