A single threat actor leveraged artificial intelligence to execute a sophisticated cyberattack against a large Amazon Web Services (AWS) environment, completing the operation in just 72 hours before successfully extorting the targeted organization, according to new findings from cybersecurity and incident response firm Sygnia.
The research reveals that the financially motivated attacker relied on agentic AI workflows to significantly speed up multiple stages of the attack, including reconnaissance, tool creation, command generation, and adapting techniques to the victim's cloud environment.
While cybercriminals have increasingly used large language models (LLMs) to craft phishing emails, generate malware, and automate various stages of cyberattacks, Sygnia's investigation highlights a more advanced use case where AI enabled a single operator to carry out a large-scale cloud compromise typically associated with well-resourced threat groups.
The attack targeted an unnamed global enterprise operating within AWS and unfolded over approximately three days. According to Sygnia, the intrusion did not rely on a single security flaw but instead combined weaknesses across several components of the victim's cloud infrastructure.
"Conducted within an AWS environment, the intrusion did not exploit a single misconfiguration," Sygnia said. "Instead, it chained together weaknesses across application services, AWS resources, source code repositories, CI/CD pipelines, runtime components, and data stores. Simultaneously, the threat actor rapidly performed credential discovery, secrets harvesting, cloud enumeration, deployment pipeline abuse, runtime modification, database access, and operational disruption."
Researchers noted that although credential theft, cloud exploitation, and data exfiltration are common tactics in cloud-focused attacks, the speed and scale of this incident stood out. Activities that would normally take weeks were completed within just 72 hours, suggesting extensive use of AI-assisted automation.
Sygnia based its assessment on evidence including attacker-developed scripts, reporting artifacts, simultaneous activities, and the rapid execution of numerous cloud attack techniques. The company concluded that AI-assisted workflows enabled the attacker to accelerate reconnaissance, develop attack tools, structure commands, and continuously adapt to the target environment.
The attack reportedly began after the threat actor obtained an AWS access key through a vulnerability in an internet-facing application. Using that initial access, the attacker repeatedly executed multiple automated workflows to expand privileges, collect credentials, harvest secrets, and gain broader access across the cloud environment.
The campaign also involved systematic theft of sensitive information, creation of backdoors, and large-scale data exfiltration to strengthen the attacker's leverage during the extortion attempt.
"To increase pressure on the client, the threat actor performed mostly reversible impact actions as a demonstration of capability. These included denying access to S3 buckets, limiting ECS services or containers to a maximum capacity of zero, creating ACL rules to block network access, and purging SQS queues," the research stated. "While many of these actions were reversible, they served as a clear showcase of force: the actor was demonstrating that they had the ability to disrupt critical cloud services and could escalate to more destructive actions if needed."
Speaking to Dark Reading, Avi Dayan, Vice President of Incident Response at Sygnia, emphasized that while AI-generated commands may not significantly alter tactical defense strategies, they fundamentally change the pace at which defenders must respond.
"The mean time to detect (MTTD) and mean time to remediate (MTTR) must contract significantly [in cases where LLMs are involved in the attack execution process]. If an AI tool can execute a breakout or exfiltrate data in under a minute, a security team relying on human-in-the-loop triaging of SIEM alerts will always lose," he said. "Security operations must pivot toward automated, high-fidelity response playbooks [security orchestration, automation, and response, or SOAR] and AI-driven defense mechanisms just to match the adversary's tempo."
To counter increasingly automated threats, Sygnia recommends that organizations strengthen identity security, improve visibility across cloud assets, secure development environments, deploy layered security controls, and automate detection and incident response wherever possible.
The company also stressed the importance of having predefined containment procedures that can be executed immediately to prevent attackers from rapidly expanding access across interconnected cloud systems.
"Equally important is the establishment of predefined containment procedures that can be executed immediately when malicious activity is identified," the research stated. "In an environment where attackers can rapidly discover credentials, identify additional attack paths, and expand access across interconnected systems, delays in containment can have a disproportionate impact on the outcome of an incident. Organizations must therefore focus on reducing response friction and enabling rapid execution of containment actions at scale."
