50 techniques in one attack. Hacker with a neural network hacked the corporation literally overnight

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
506
Reaction score
913
Deposit
0$
The speed previously provided by a whole team of specialists has now been available to one person with AI tools. Unit 42 unit Palo Alto Networks investigated an extortion attack in which the operator handed over most of the actions to AI agents and in less than 10 hours carried out the attack on more than 50 technicians from the MITRE ATT&CK base. People would have a comparable job for about two weeks.

The attacker himself told about the use of advanced models and specialized agent platforms during negotiations after the attack. Unit 42 also found independent signs of automation: parallel appeals to multiple models, structured Markdown files to transfer results between agents and sessions, and control scenarios likely created with AI.

After initial penetration through the public interface API, the intelligence agent built a map of internal microservices. Then, individual agents viewed source code repositories, found tokens and service passwords in the files, penetrated the secret repository, and obtained the main administrative credentials that opened root access to the company’s systems.

The next object was CI/CD conveyors, which automatically assemble and deploy the software. The attacker launched unauthorized assemblies, stole cloud keys and tried to introduce backdoors in the Terraform configuration. Hard-protection of the branches stopped the replacement of the code, but the stolen keys allowed to capture cloud access points to the company's models.

The AI infrastructure of the victim was turned into a platform for further action, hiding appeals among ordinary traffic and shifting the cost of the owner. The agents were simultaneously fixed through SSH keys, serverless functions, containers, cloud accounts and development pipelines. The new vulnerability of zero day was not needed, the acceleration was given by the automation of known techniques.

After the invasion, the attacker left an 80-page technical report describing the weak points used. Unit 42 advises immediately recalling OAuth keys and sessions, stopping compromised pipelines, and isolating cloud accounts. Companies are advised to take into account all access points to models, limit the rights and frequency of requests, keep logs, and change the code only after a few approvals.
 
Top Bottom