Cyberattakers step into the Agentic AI era
Expert of the InfoSec division
2026.07.30
Artificial intelligence has supported cybercrime for years by generating phishing emails, modifying malware and researching targets. Now, AI agents are beginning to take a more active role: executing commands, troubleshooting failures and progressing through attacks with limited human involvement.
The techniques are often familiar, but AI makes them faster, easier to reproduce and more scalable.
From AI-assisted to AI-driven attacks
In AI-assisted attacks, humans remain responsible for decisions while AI helps to:
- generate phishing messages;
- write malicious code;
- research vulnerabilities;
- analyze stolen data;
- create deepfakes.
AI-operated attacks go further. An agent can interact with systems, execute code, interpret results and automatically correct failed attempts.
A botnet rebuilt in six minutes
In 2026, Trend Micro analyzed Gemini CLI sessions associated with the threat actor “bandcampro”. The attacker used the terminal-based AI agent to manage infrastructure controlling eight compromised computers.
Gemini wrote server code, deployed it, configured Cloudflare tunnels and resolved connection issues. When the command-and-control environment became unstable, the AI rebuilt it on a new server in approximately six minutes.
The human operator contributed only a small proportion of the session. This shows how AI can make criminal infrastructure portable, disposable and easy to recreate.

Ransomware that corrects itself
Sysdig documented JADEPUFFER, an agentic ransomware operation that exploited a vulnerable Langflow server, collected credentials and moved laterally into production systems.
The attacker created an administrator account and encrypted more than 1,300 configuration records. When a login attempt failed, the agent diagnosed the problem and corrected its approach within 31 seconds.
The attack relied on common weaknesses:
- known vulnerabilities;
- exposed services;
- default credentials;
- insufficiently protected administration interfaces.
AI connected these weaknesses into a complete attack chain and executed it at machine speed.

AI-driven extortion
Anthropic also reported a campaign in which Claude Code supported attacks against at least 17 organizations.
The AI automated reconnaissance, credential theft and data analysis. It also helped calculate ransom amounts and generate personalized extortion messages, with some demands exceeding USD 500,000.
This approach, described as “vibe hacking”, allows attackers to define the objective while AI performs much of the technical work. It also lowers the entry barrier for less experienced cybercriminals.

What changes for defenders?
AI does not remove the importance of traditional weaknesses, but it changes how quickly they can be exploited.
- Attack cycles become shorter: failed actions can be corrected within seconds.
- The entry barrier falls: fewer specialist skills are required.
- Attacks scale more easily: messages, scripts and infrastructure can be regenerated on demand.
- Intrusions become adaptive: blocking one method may only trigger another.
- SOC teams face a growing speed gap: manual investigation cannot easily match machine-speed attacks.
Defending against AI-enabled attacks
Organizations must continue to patch exposed systems, remove default credentials, protect administrative interfaces, restrict privileges and secure API keys.
However, they must also reduce the time between detection, investigation and response. Alerts need to be rapidly connected with asset data, threat intelligence, user activity and historical context.
Responding faster with PULZARIS Analyst AI
PULZARIS Analyst AI adds an AI-supported investigation layer to security operations.
It analyzes alerts, correlates related entities, enriches incidents with threat intelligence and creates a structured investigation brief containing:
- a likely verdict and confidence level;
- affected users and systems;
- contextual findings;
- risk-based prioritization;
- recommended response steps.
PULZARIS follows a human-in-the-loop approach. AI accelerates analysis, while the analyst validates the findings and remains responsible for final decisions.
In our SOC environment, PULZARIS Analyst AI has already supported the analysis of nearly 3,000 incidents, with an average processing time of approximately 2.5 minutes per incident.
Cybercriminals are already using AI to compress attack cycles into minutes. The key question is whether defenders can investigate and respond at comparable speed.
Read the full article on our International subsidiary’s website by clicking on the logo:
