How Threat Hunting can help detect and contain attacks carried out using AI agents

A proactive Threat Hunting service can detect and contain attacks carried out using AI agents even when they manage to avoid triggering alerts, thereby preventing an attack from escalating into a security incident
On September 14, 2026, the Spanish Data Protection Agency (AEPD) announced that it had received the first notification of a data breach caused by an attack executed using an AI agent. According to the agency itself, this incident shows that attacks carried out using AI agents «are no longer a theoretical risk and are beginning to materialize as incidents».
The news also comes at a time of growing concern about the impact AI may have on the security of organizations.
In recent weeks, several security incidents involving AI systems from OpenAI and Anthropic during security testing have been disclosed, involving the exploitation of vulnerabilities and configuration weaknesses, respectively.
However, the real focus is on attacks carried out using AI agents by malicious actors.
For months, cybersecurity experts have observed attacks against organizations in which AI systems are used to identify vulnerabilities at unprecedented speed, successfully exploit them, execute malware capable of evolving in real time, and adapt to the defensive measures deployed by the targeted companies or institutions.
Against this dangerous threat landscape, it is essential for organizations to prepare to contain attacks carried out using AI agents and highly automated attacks.
How can they do this? Proactive Threat Hunting services can play a key role in detecting and containing attacks carried out using AI agents, particularly when these attacks manage to evade security alerts, since Threat Hunters work by formulating and investigating Compromise Hypotheses, rather than relying on an alert to initiate an investigation.
Below, we examine the key characteristics of attacks carried out using AI agents and explain why proactive Threat Hunting is crucial to preventing them from escalating into significant security incidents within organizations.
Table of Contents
Attacks carried out using AI agents are set to become one of the major security threats of this era
The security incident reported to the AEPD, in which personal data and even important documents such as invoices were exposed, is not an isolated case.
Cybersecurity experts have observed the use of AI as an accelerator of malicious actors’ offensive capabilities. Why?
First, attacks carried out using AI agents can be launched by malicious actors who lack substantial financial resources or advanced technical expertise. AI systems can compensate for these limitations throughout all stages of an attack, from searching for exploitable vulnerabilities in a company’s infrastructure to the execution phase, in which AI can orchestrate actions designed to evade an organization’s security controls.
Second, just as AI enables companies to automate multiple legitimate tasks and processes in their day-to-day operations, it also enables malicious actors to automate actions and reduce the time and resources required to design and manage attacks. This is particularly relevant to social engineering techniques and to vulnerability discovery and effective exploitation.
In fact, attacks carried out using AI agents differ from manually executed attacks in one key respect: AI can simultaneously analyze multiple assets in search of vulnerabilities.
All of this shows that attacks carried out using AI agents may become increasingly numerous, automated, fast, adaptive, and difficult to detect and contain.
The use of AI accelerates vulnerability discovery and exploitation
As noted above, and as demonstrated by the security incident reported to the AEPD, the malicious use of AI agents can play a crucial role in vulnerability discovery and exploitation. They enable malicious actors to:
- Expand the scope of vulnerability discovery, identifying weaknesses in technology infrastructure that may have remained undetected for years.
- Accelerate the vulnerability discovery process.
- Chain the exploitation of multiple vulnerabilities. As a result, vulnerabilities initially classified as low risk can, when exploited in combination with other weaknesses, ultimately lead to extremely serious security incidents.
- Significantly reduce the time between the discovery of zero-day vulnerabilities and their exploitation. A process that once took weeks can now potentially be completed in hours.
This shows that attacks carried out using AI agents already pose a major challenge for vulnerability management, both in terms of detection and remediation.
From malware developed with AI to AI-powered malware
Another key factor to consider regarding attacks carried out using AI agents is the extremely rapid transition from malware developed using AI systems to the emergence of AI-powered malware.
What is the difference? In the first case, malicious actors use AI systems to develop malicious code more quickly and effectively. In addition, actors with limited technical expertise can develop their own malware.
In the second case, however, we are dealing with malware that uses AI to adapt and evolve during execution, enabling it to evade detection systems, remain undetected, and persist for longer periods, thereby significantly increasing its potential impact. Cases already documented by security researchers confirm this evolution.
In November 2025, Google Threat Intelligence Group identified PROMPTFLUX, VBScript malware that periodically queries the Gemini API to rewrite and obfuscate its own code, even regenerating its entire source code every hour with the explicit aim of evading antivirus software.
The same report documents PROMPTSTEAL, used by the Russia-linked APT28 group in real-world operations, which dynamically generates the reconnaissance and exfiltration commands it uses at runtime rather than having them statically embedded in its code.
Months earlier, in August 2025, ESET had discovered PromptLock, the first known AI-powered ransomware, capable of dynamically generating malicious scripts tailored to each victim’s system. SentinelOne, meanwhile, revealed the existence of MalTerminal, malware that incorporates a GPT-4 model to generate ransomware code or a reverse shell in real time depending on the circumstances of each execution.
Although several of these samples are still experimental or proof-of-concept, they all point in the same direction: malware that no longer executes a fixed routine, but instead makes decisions and modifies its behavior on the fly, making signature-based detection more difficult and extending its dwell time in compromised systems.

Attacks carried out using AI agents can automate stages across the entire Cyber Kill Chain
The developments discussed above point to a highly concerning reality: the use of offensive AI agents is already being observed throughout the Cyber Kill Chain.
In fact, in the incident disclosed by the AEPD, «a third party appears to have used an AI agent as a tool to successfully chain together different stages of the attack».
What does it mean that malicious actors are already using AI throughout the Cyber Kill Chain? As noted above, this enables malicious actors to automate a significant proportion of the attacks they carry out against companies and public-sector organizations, increasing the speed at which attacks are executed, their ability to adapt in real time to security controls, and their likelihood of success.
The use of AI in certain stages of the Cyber Kill Chain has been observed for years, but we are now facing a much more complex scenario. In attacks carried out using AI agents, the ability to scale attacks and the speed of exploitation can exponentially increase their success rate.
This is why proactivity is essential when defending an organization against attacks carried out using AI agents. A proactive Threat Hunting service makes it possible to investigate potential compromise scenarios that have not triggered alerts and to identify malicious activity at an early stage of an intrusion. This can significantly accelerate an organization’s response to an attack that may unfold extremely quickly, as discussed above. The use of AI by malicious actors will require companies to adopt a proactive approach to their cybersecurity strategies.
Recommendations for defending against attacks carried out using AI agents
In response to the threat posed by attacks carried out using AI agents, Spain’s National Cryptologic Centre (CCN) published a best-practices guide for addressing offensive AI models.
The CCN, which is part of Spain’s National Intelligence Centre (CNI), recommends that companies and public-sector organizations adapt their cybersecurity strategies around four fundamental pillars:
- Strengthen fundamental security controls to prevent unauthorized access to organizational systems. For example, by optimizing identity management policies and network segmentation and access control mechanisms.
- Embed security by design into IT and OT processes to prevent vulnerabilities that offensive AI agents could identify and exploit.
- Build resilient and secure systems under an assume-compromise approach, with the aim of preventing attacks and reducing incident response times in order to limit their impact.
- Use AI for defensive security purposes to accelerate vulnerability management and improve software supply chain security.
Threat Hunting services can help organizations implement the CCN’s recommendations, particularly because they operate on the basis of Compromise Hypotheses. Unlike a reactive approach, Threat Hunters investigate under the assumption that malicious activity may have occurred without being detected by defensive security technologies.
This enables them to detect previously unknown and targeted attacks that unfold over very short periods of time, such as attacks carried out using AI agents.
Threat Hunting: proactivity is key to containing attacks carried out using AI agents
Given everything discussed throughout this article, it is clear that, in order to address attacks carried out using AI agents, companies and public-sector organizations need to take a proactive approach to security. Waiting for a security event to be detected may simply be too late.
Why? If multiple stages of an attack can be automated, executed faster, and allowed to evolve while the attack is underway, it can also become more effective at evading detection. A reactive approach may therefore be insufficient to contain the attack and prevent significant operational and financial damage to an organization.
This is why proactive Threat Hunting services are set to play a critical role in defending companies technology infrastructure in the coming years. This type of cybersecurity service can:
- Use EDR/XDR solutions that have undergone internal assessment to ensure they provide the capabilities required to deliver a high-quality Threat Hunting service.
- Continuously and proactively hunt for threats 24/7.
- Detect malicious operations carried out using AI agents, potentially even before defensive security technologies do.
- Identify previously unknown threat actors through an investigative process based on Compromise Hypotheses.
- Query available telemetry to identify previously unknown threats.
- Understand how malicious actors operate, how they use AI, which emerging techniques they employ, and how they may evade an organization’s detection and response mechanisms.
- Respond immediately to any identified malicious activity and provide incident response teams with high-quality intelligence and context to limit the impact of security incidents and safeguard business continuity.
Ultimately, attacks carried out using AI agents represent a growing threat to companies and public-sector organizations.
The fact that the AEPD has received notification of an attack in which AI was used to automate and successfully chain together several stages demonstrates that this is no longer a theoretical risk, but a real-world threat.
Organizations must therefore strengthen their vulnerability identification and management capabilities, as well as their incident detection and response mechanisms. attacks carried out using AI agents can operate faster and adapt more effectively—and in real time—to the defensive measures deployed by security teams.
A proactive Threat Hunting service can make a decisive contribution to improving the detection of sophisticated threats and defending against attacks that may unfold within an extraordinarily short timeframe.