Agentic AI is compressing attacker intrusion timelines to minutes
Artificial intelligence has moved from a curiosity in the threat landscape to a working part of the intrusion, and agentic adversaries have infiltrated extortion campaigns, espionage operations and hacktivist activity alike. The speed of the tooling, more than any novel attack technique, is what leaves defenders far less time to respond.
That shift is measurable, not theoretical. Security teams that spent last year debating whether attackers would adopt AI are now watching them run entire operations with it, according to Adam Meyers (pictured), senior vice president of intelligence at CrowdStrike Holdings Inc.
“The stat that’s most interesting is we had something like 26 agentic adversaries that we were tracking in the last 30 days. That’s more than we were tracking in the year before that,” Meyers said. “REVENANT SPIDER is a group that we were tracking that was using an agent in the intrusion. AI agents are now part of ransomware operations.”
Meyers spoke with theCUBE’s Dave Vellante and Rebecca Knight at Fal.Con, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed agentic adversaries, intrusion speed and the Sality botnet takedown. (* Disclosure below.)
Agentic adversaries compress the intrusion timeline
Speed is the defining characteristic. CrowdStrike’s threat hunting research already found that exploitation windows are shrinking as AI works its way into adversary operations, and agent-driven intrusions are pushing that further still.
“In 58 minutes, VAULT PANDA had conducted 1,100 commands. It was an agent that was doing it, and we were watching it learn in real time,” Meyers said. “When I talk about breakout time from our global threat report, we were talking this year about 29 minutes on average, 27 seconds was the fastest. I’m talking about an entire intrusion operation conducted in minutes from start to finish.”
Defenders are pushing back with collective action. CrowdStrike worked with law enforcement on the Sality botnet disruption, an effort a decade in the making against a network that had run for 23 years, Meyers noted.
“Bluntly, we do need to bring the fight to the bad guys. I think we need to raise the cost of doing business for them,” Meyers said. “We need to do it in a responsible way”.
Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of Fal.Con:
(* Disclosure: TheCUBE is a paid media partner for the Fal.Con event. Neither CrowdStrike, the sponsor of theCUBE’s event coverage, nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)
Photo: SiliconANGLE
A message from John Furrier, co-founder of SiliconANGLE:
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
- 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
- 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network
Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/
About SiliconANGLE Media
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.