Criminal AI agent swarms
A single attacker with commodity AI coding models can now run an autonomous agent swarm that breaches hundreds of organizations in hours, a capability that used to require a skilled team.
-
ACTA criminal AI-agent swarm breached 395 organizations in under four hours
GreyNoise says an attacker paired OpenAI's Codex and a DeepSeek model to run hundreds of agents against unpatched PaperCut NG/MF servers, compromising 440 instances across 48 countries — 11 organizations breached in 26 seconds. GreyNoise
-
Google's threat-intel team found a separate criminal group harvested thousands of cloud credentials using autonomous AI agents in under six hours. The Hacker News
-
AI-assisted attack tooling is showing up in lower-sophistication criminal breaches now, not just state-linked campaigns
GreyNoise's Sept 21 report traced a WordPress breach chain (wp2shell, two chained CVEs) that stole over 18,000 government and small-business records across 29 countries to a Chinese-speaking actor using custom tools GreyNoise says show signs of LLM generation - a second, independent case from September's state-linked PaperCut swarm. Demonstrated finding, single source. GreyNoise
-
WATCHCisco Talos finds the first AI-directed malware with no human operator
CLOSEDQUORUM, disclosed Sept 22, is a Go implant that queries DeepSeek, Qwen, Mistral and Gemini and picks its next action by model vote, targeting crypto wallets and saved credentials. The public build carries dummy API keys; no confirmed live deployment yet. Cisco Talos