Among threat actors, as we know, the use of generative AI has become widespread at all stages of the cyber kill chain: code development, phishing email creation, deekfakes, vulnerability detection and exploitation, lateral movement, persistence, etc. But until now, the dominant modus operandi was that of the "copilot AI" which assists the malicious actor in their various actions. However, this reality is becoming less and less true.
Recent public threat reports show that we are gradually entering the era of agent attacks. In such a scenario, the attacker no longer controls every step of the intrusion; they define a high-level objective and delegate execution to an agent. The operational advantage is that the human is no longer the bottleneck of the attack. The attack then gains in speed of execution, scale of deployment, and level of persistence, which puts traditional defenses at a disadvantage.
Agent attack is not yet end-to-end
The good news is that, for now, the agent-based approach doesn't seem to work end-to-end. Recent examples show that threat actors use autonomous agents for some phases of an attack, but not all. Here are some concrete examples:
1. From Reconnaissance to Exploitation
Gambit Security analyzed a campaign by a cybercrime actor that automated the targeting and compromise of hundreds of online retailers using three different harnesses: Strix for vulnerability research; Cairn for autonomous operation with the option of automatic skimmer injection; and Hermes for the orchestration. In the space of 5 days, the malicious actor thus managed to compromise 27 companies and collect more than 600,000 bank card numbers… before triggering an automated «wipe» (deletion) of the databases to remove all trace of its passage.
2. Actions on Objectives and Persistence
Google Threat Intelligence Group analyzed PROMPTSPY, An Android malware that uses a module called `GeminiAutomationAgent` to analyze the graphical interface in real time and interact with it, based on an objective provided by the attacker. The malware is also capable of "locking" itself into the "Recent Apps" menu, a persistence technique that relies on the phone's accessibility features and launcher.
3. Command & Control (C2)
Cisco Talos detected CLOSEDQUORUM, This malware replaces the command and control (C2) server with a "quorum" of models (DeepSeek, Gemini, Mistral). The Go binary uses plurality voting to choose the next action (e.g., dumping LSASS). Malicious traffic then blends in with legitimate API calls to AI providers, rendering domain blocking ineffective. Surprisingly, the implant delegates the most critical part—tactical decision-making—to LLMs.

4. Lateral Movement and Escalation of Privileges
A recent report from Microsoft shows how the group Storm-3168 – aka JADEPUFFER – uses agents to navigate and escalate privileges in the cloud via *main services* compromise. AI is able to understand the topology of a cloud tenant and decide on the shortest path to critical resources, showing in passing that autonomy works even in complex environments.
Empower the defense
With this paradigm shift, our traditional response cycles are proving inadequate. Patch windows and human on-call rotations are ill-suited to an agent who can identify, exploit, and exfiltrate data in a matter of hours, without ever getting any sleep. The only viable response is an AI-assisted defense capable of reacting at machine speed. Obviously, such an infrastructure cannot be built in a few days. More agile and less constrained by their organizational processes, malicious actors will have a head start for some time.
Until then, agent-based attacks are likely to disrupt our cybersecurity priorities. Faced with intrusions that will be difficult to counter, companies will have to invest more in resilience to be able to rebuild quickly. Minimum Viable Business.
How Intrinsec protects you against the emergence of autonomous agents
Testing before the attacker: the "Agent-Centric" approach«The rise of agent-based attacks renders traditional security audits insufficient. Our teams Audit and offensive security We now simulate "augmented" attack scenarios, using frameworks and agents similar to those used by adversaries. We test the resilience of your environments to identify and remediate critical access paths before an autonomous agent can discover them.
Detecting the invisible: behavioral and contextual monitoring: Faced with attackers who automate reconnaissance and exploitation, static analysis is obsolete. Our SOC and our MDR services deploy contextual monitoring capable of spotting early signs of an agent-driven intrusion, even when the malware uses generic tools or adapts in real time to bypass defenses.
Anticipating changes in operating methods via CTI The emergence of offensive AI is transforming the speed at which threats spread. Our team of Cyber Threat Intelligence We continuously analyze new attack frameworks and the vulnerabilities of autonomous agents to transform this intelligence into actionable detection rules. We help you shift from a reactive, patch-based approach to a proactive attack surface reduction strategy.
The strength of our approach lies in the interconnectedness of these areas of expertise: CTI identifies new offensive AI tools, offensive security validates their impact on your infrastructure, and the SOC provides continuous monitoring. A complete cycle to counter a threat that is constantly accelerating.
