What the First Autonomous Ransomware Case Confirms


Security researchers have documented an AI agent running a full ransomware operation on its own against a live production target, planning, adapting, and executing every step from the first exploit through data destruction. This is early real-world evidence of the shift to autonomous criminal operations that our research forecast.

Agent-run attacks change what defenders can rely on. They produce disposable, per-victim indicators instead of reusable tools and infrastructure, so the defensive weight shifts from sharing and blocking indicators of compromise onto behavior and technique-based detection.

The novelty is automation, not tradecraft. Every weakness the agent used was old and well understood, which concentrates exposure in organizations running internet-facing AI and automation platforms or carrying default and unrotated credentials, and shortens the time available to close those gaps.

The monetization layer failed even though the intrusion succeeded. The agent did not save the encryption key it generated and used a placeholder address instead of real payment infrastructure, so the operation could not have produced a payout even if the victim had complied.

Read more…
Source:  TrendMicro


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Divide and conquer: how the new Keenadu backdoor exposed links between major Android botnets

    February 17, 2026

    In April 2025, Kaspersky reported on a then-new iteration of the Triada backdoor that had compromised the firmware of counterfeit Android devices sold across major marketplaces. The malware was deployed to the system partitions and hooked into Zygote – the parent process for all Android apps – to infect any app on the device. This allowed ...

  • China remains embedded in US energy networks ‘for the purpose of taking it down’

    February 17, 2026

    Three new threat groups began targeting critical infrastructure last year, while a well-known Beijing-backed crew – Volt Typhoon – continued to compromise cellular gateways and routers, and then break into US electric, oil, and gas companies in 2025, according to Dragos’ annual threat report published on Tuesday. Dragos specializes in operational technology (OT) security, and as ...

  • OpenClaw AI agents targeted by infostealer malware for the first time

    February 17, 2026

    Thanks to its overnight success and widespread adoption, OpenClaw has painted a large target on its back and is now being attacked by infostealers, after security researchers Hudson Rock claimed to have seen a first-of-its-kind attack in the wild. OpenClaw (previously known as Clawdbot and Moltbot) is an open source AI assistant software designed to actually ...

  • China-linked snoops have been exploiting Dell 0-day since mid-2024, using ‘ghost NICs’ to avoid detection

    February 17, 2026

    China-linked attackers exploited a maximum-severity hardcoded-credential bug in Dell RecoverPoint for Virtual Machines as a zero-day since at least mid-2024. It’s all part of a long-running effort to backdoor infected machines for long-term access, according to Google’s Mandiant incident response team. The US government and Google first warned about this campaign last year after detecting Brickstorm ...

  • Critical Vulnerabilities in Ivanti EPMM Exploited

    February 17, 2026

    Two critical zero-day vulnerabilities (CVE-2026-1281 and CVE-2026-1340) affecting Ivanti Endpoint Manager Mobile (EPMM) are being actively exploited in the wild, affecting enterprise mobile fleets and corporate networks. These vulnerabilities allow unauthenticated attackers to remotely execute arbitrary code on target servers, granting them full control over mobile device management (MDM) infrastructure without requiring user interaction or credentials. Read ...

  • Indian pharmacy chain giant exposed customer data and internal systems

    February 17, 2026

    A major Indian pharmacy chain operated a flawed platform which exposed highly sensitive data of millions of users, experts have warned. DavaIndia Pharmacy, the pharmacy arm of Zota Healthcare, currently runs more than 2,300 stores across the country – however, its platform was bugged in a way that allowed unauthenticated users to create “super admin” ...