Agentic AI–Based Cyberattacks

2026-09-28
Agentic AI–Based Cyberattacks

Artificial intelligence is moving beyond simple chatbot-style systems and becoming a more sophisticated Swiss army knife of productivity tool. But in order to push the capability of AI to the max, software engineers have found ways to grant AI a degree of autonomy, so it can not only carry out certain tasks on its own, but also decide what tasks it needs to do next. These newer systems, often described as agentic AI, are designed to plan tasks, pursue goals over time, and adapt their behaviour based on feedback. While this shift creates clear benefits in automation and efficiency, it also introduces a new dimension of risk in cybersecurity. The same qualities that make these systems useful can also make them dangerous when used to carry out malicious activity.

At its core, agentic AI is simply a much more adaptable form of artificial intelligence. It does not need to be given the exact steps to solve a problem, or to be prompted to go from step one to step two. Instead, it can work out those steps itself, experiment with different strategies to achieve the desired result, and refine its approach as it interacts with its environment. As a tool for carrying out cyberattacks, this allows it to operate at a much more sophisticated level, closer to how a human attacker might behave, but at a much larger scale, and at far higher speeds.

Accessing Networks Autonomously

In the context of cyber attacks, the autonomy granted to agentic AI drastically changes how attacks can be conducted. As an example, traditionally an attacker would perform reconnaissance on a network manually using a suite of tools that allow them to map a system and gather information about accounts and privilege hierarchies, files, connected devices, installed software and so on. With agentic AI, that process can not only be automated, but made into a continuous and self-correcting task. An autonomous system can continuously monitor network activity, scan for vulnerabilities, and update its understanding of a target in real time. This allows it to identify mechanisms for deeper system access in a way that possibly surpasses even experienced hackers.

Another area where agentic AI has implications is in social engineering, which is an extremely dangerous methodology used by hackers to infiltrate target networks. Phishing attacks have already been observed as using AI to generate more convincing messages, but agentic systems extend this further by allowing for ongoing interaction. Instead of sending a single email, an AI agent could hold a conversation, adjust its tone based on responses, and refine its approach to increase credibility. This makes such attacks more persuasive and harder to detect, as they begin to resemble genuine human communication rather than scripted deception.

So the crux of the issue is that agentic AI supercharges a hacker's ability to infiltrate and map out a network, but that is still not the full story. Research has shown that agentic AI has the capability not only to fully exploit these networks, to embed itself in a way that makes it not only hard to detect but also hard to remove, and potentially even rewrite its own malware payload ad hoc, to adapt to whatever network it finds itself in.

Exploiting Systems and Adapting Malware

The potential for autonomous exploitation is significant. Rather than relying on a fixed set of known vulnerabilities, an agentic system can test multiple approaches, abandon those that fail, and continue searching for alternatives. In practice, this means attacks can become more exploratory and adaptive. The agent is not simply executing a plan of attack, but continuously developing one as it progresses, responding to obstacles in ways that traditionally have required experienced human judgment.

Once access is achieved, maintaining that access is one of the more complex aspects of a cyberattack, and hackers have to work around the clock in order to stay ahead of the defensive capabilities of antivirus software. Agentic AI introduces the possibility of persistence establishment that reacts to defensive measures in real time. If one method is patched, the agent can look for another. If activity is detected, either from a user or from some other interfering software, it can alter its behaviour to reduce its visibility. This ability to adapt on-the-fly makes long-term intrusion more feasible, and hackers will make good use of this capability, slowly extracting data in a way which will not raise any alarms, and even providing them with the opportunity to sell that access at a later date.

There is also growing concern around the idea of malware that can evolve. Conventional malicious software tends to follow a fixed design, even if it includes some obfuscation techniques. By contrast, software guided by agentic AI could alter its structure or behaviour in response to the environment it encounters. It might behave differently on a corporate network than it does on a personal device, or change its approach when it detects security monitoring. This creates a moving target for defenders, complicating efforts to identify and neutralise threats.

All of these developments contribute to a broader shift in the threat landscape. Attacks can be carried out at a pace and scale that were previously impractical or impossible. Hackers no longer need to be experts in their field, since the AI handles a lot of the complexity. Campaigns can run continuously, refining themselves without direct intervention. Taken together, these factors suggest a future where cyberattacks become even harder to defend against than before.

Considerations for Defence

For defenders, this presents a distinct set of challenges. Traditional security measures often rely on recognising known patterns or signatures, but adaptive systems do not behave in consistent ways. Their actions may vary depending on the environment, which makes them harder to predict and model. At the same time, the speed at which these systems can operate creates a gap between attack and response, putting pressure on human-led security teams.

However, the same technologies can also be used to strengthen defence. Security systems powered by AI can, just like the malicious kind, monitor networks continuously, identify anomalies, and respond in real time. Autonomous defensive agents can investigate suspicious activity and take action without waiting for human input. This suggests that the future of cybersecurity may involve systems on both sides acting with increasing independence, leading to an environment shaped by interactions between competing offensive and defensive models.

The rise of agentic AI also raises important ethical and regulatory questions. When a system acts autonomously, assigning responsibility becomes more complex. Questions emerge around what kind of data they should be able to access, what level of privilege they should be given, how their use should be governed, and what safeguards are necessary to prevent misuse. These issues extend beyond cybersecurity into broader discussions about the role of AI in society.

Conclusion

In conclusion, agentic AI represents a significant shift in how cyber attacks can be conceived and executed. By enabling systems that can plan, adapt, and persist, it transforms attacks from static operations into ongoing processes. While the technology is still developing, its trajectory suggests that both attackers and defenders will increasingly rely on autonomous systems. Preparing for this change will require not only technical adaptation but also careful consideration of the risks and responsibilities that come with it.

Sources

https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/careful-adoption-of-agentic-ai-services

https://www.ncsc.gov.uk/report/impact-ai-cyber-threat-now-2027

https://blog.google/innovation-and-ai/technology/safety-security/google-threat-intelligence-group-report-ai-november-2025/

https://socket.dev/blog/enisa-s-2025-threat-landscape-ai-reshapes-cyber-attacks

https://arcticwolf.com/resources/glossary/what-are-initial-access-brokers/

https://www.infosecurity-magazine.com/news/aienabled-malware-actively/

https://www.gov.uk/government/collections/ai-cyber-security

 

The information contained in this article is provided for informational purposes only and does not constitute professional advice and is not guaranteed to be accurate, complete, reliable, current or error-free.

 

Copyright protector

Related news

Job scam alert: fake CrowdStrike offers spread malware White Blue Ocean
Phishing via Recruitment: The Rise of Crypto Investment Scams Masquerading as Job Offers
2025-07-18

In early 2025, cybercriminals launched a phishing attack posing as CrowdStrike recruiters, tricking users into installing cryptomining malware. The scam mimics real job processes and highlights rising risk in digital hiring.

Read more
AI Voice Scams: how to detect and stay safe from deepfake audio White Blue Ocean
AI? Call me never
2025-07-04

This article explores the growing threat of AI voice scams, where sophisticated deepfake technology mimics familiar voices and manipulate victims into revealing sensitive information or transferring money. Learn how to protect yourself from falling victim to these digital threats.

Read more
SharePoint exploit: the ToolShell attack timeline White Blue Ocean
ToolShell and SharePoint: A Hackathon Gone Wrong
2025-09-25

This article summarizes the timeline of the ToolShell exploit, a Microsoft SharePoint zero-day vulnerability. It covers the exploit's rapid spread, which affected critical US government departments, and highlights how slow patching contributed to the attacks.

Read more
Social Engineering threats on Microsoft Teams White Blue Ocean
Is Microsoft Teams Secure? A Look at Emerging Threats
2025-08-22

Trusted by millions of people, Microsoft Teams is now a playground for cybercriminals. This article explores social engineering tactics, real malware campaigns like DarkGate, and offers practical steps to stay safe in today’s evolving threat landscape.

Read more

Contacts

Let's talk

Please fill in the form below (fields with * are mandatory) and we will respond to your request as soon as possible!