THREAT OPS › Threat News › Agentic Ransomware: From Human-Operated to AI-Operated Attacks
Agentic Ransomware: From Human-Operated to AI-Operated Attacks
<h1>Agentic Ransomware: From Human-Operated to AI-Operated Attacks</h1> <p>Ransomware has always needed a human involved somewhere: an affiliate navigating a network by hand, or at minimum, a person who wrote the script the malware executed. Agentic ransomware breaks that assumption. It describes a <a href="https://socradar.io/glossary/ransomware/">ransomware attack</a> where an autonomous AI agen
Attributed threat actors
- INC RansomG1032
MITRE ATT&CK techniques
- MalwareT1587.001
- Local AccountT1087.001
- VulnerabilitiesT1588.006
- Data from Cloud StorageT1530
- System Information DiscoveryT1082
- Exploit Public-Facing ApplicationT1190
- Unsecured CredentialsT1552
- Escape to HostT1611
- Remote ServicesT1021
- Local AccountT1136.001
- Active ScanningT1595
- Command and Scripting InterpreterT1059
- Credentials In FilesT1552.001
- Valid AccountsT1078
- Data Encrypted for ImpactT1486
- CredentialsT1589.001
- PythonT1059.006
- Obtain CapabilitiesT1588
- Data DestructionT1485
- Create AccountT1136
- Network Service DiscoveryT1046
- Develop CapabilitiesT1587
- Active ScanningAML.T0006
- Valid AccountsAML.T0012
- Obtain CapabilitiesAML.T0016
- Develop CapabilitiesAML.T0017
- Exploit Public-Facing ApplicationAML.T0049
- Command and Scripting InterpreterAML.T0050
- Unsecured CredentialsAML.T0055
- Escape to HostAML.T0105
Indicators of compromise
- CVE-2025-3248cve
- CVE-2026-24858cve
- 3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLybtc
- e78393397@proton.meemail
- 45.131.66.106ipv4
- 64.20.53.230ipv4
Original source: https://socradar.io/blog/agentic-ransomware-human-to-ai-attacks/