Blog
/
/
July 9, 2026

When AI Infrastructure Becomes Part of the Attack Surface

Darktrace investigated a compromised AI gateway connected to Amazon Bedrock services that was later observed communicating with cryptomining infrastructure. The incident highlights how AI gateways are becoming part of the enterprise attack surface and demonstrates the importance of behavioral analysis, cloud visibility, and securing AI infrastructure alongside identities and workloads.
Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
Angel Arribas Lopez
Associate Principal Cyber Analyst
ai infrastructure cybersecurityDefault blog image
09
Jul 2026

AI Infrastructure and the Evolving Attack Surface

As organizations deploy generative AI into production environments, a new layer of infrastructure has emerged inside enterprise cloud environments: AI gateways.

What is an AI gateway?

AI gateways are systems that sit between users, applications, and foundation models, often holding privileged cloud permissions and managing access to AI services at scale.

Because of that role, AI gateways are becoming an increasingly important part of the enterprise attack surface. A compromise may provide attackers with access not only to compute resources, but also to cloud identities, model services, sensitive prompts, and other connected systems.

This blog examines how Darktrace investigated a compromised AI gateway connected to Amazon Bedrock services that was subsequently observed communicating with cryptomining infrastructure. Based on its configuration and associated Identity and Access Management (IAM) role, the instance appeared to function as a gateway to Amazon Bedrock-hosted AI services. Following suspected compromise activity, the host was observed communicating repeatedly with known cryptomining infrastructure before subsequently being shut down. Darktrace detected and escalated the activity through its Enhanced Monitoring and Managed Threat Detection services.

While the ultimate impact in this case appeared to be unauthorized cryptomining, the incident is notable because of where it occurred. The compromised asset sat at the intersection of cloud infrastructure, identity, and AI services. Recent research has highlighted how AI gateways such as LiteLLM can become attractive targets due to their ability to centralize credentials, model access, and cloud permissions. Although Darktrace found no evidence linking this activity directly to publicly disclosed LiteLLM vulnerabilities, the incident demonstrates why organizations should treat AI infrastructure as part of their critical attack surface rather than as a standalone application tier [1].

Why cryptomining remains a common cloud post-compromise activity

Cryptomining can be a lucrative post-compromise activity in cloud environments. After gaining access to a cloud asset, attackers may deploy mining software to abuse the victim’s compute resources for financial gain. This type of activity is likely to be opportunistic, targeting exposed services, weak credentials, leaked access keys, vulnerable applications, or misconfigured cloud workloads.

A typical cloud cryptomining intrusion may involve:

  • Identifying exposed or vulnerable cloud infrastructure
  • Gaining access through exposed services, credentials, or application weaknesses
  • Downloading and executing mining software
  • Establishing repeated outbound connectivity to mining pool infrastructure
  • Continuing to consume compute resources until the activity is detected and disrupted

The notable element in this case is not the cryptomining alone, but where it occurred: on cloud infrastructure supporting AI-related activity. This shows how assets used to enable AI services can still be exposed to familiar cloud compromise risks.

Investigating a compromised AI gateway connected to Amazon Bedrock

On June 12, 2026, Darktrace observed activity consistent with active cryptomining from an Amazon Web Service (AWS) EC2 instance named LiteLLM-Proxy. The instance appeared to support LiteLLM activity and was associated with an instance profile that had access to Amazon Bedrock resources.

AI gateways are designed to centralize access to large language models, often handling authentication, routing, logging, and policy enforcement for AI applications. From a security perspective, they also aggregate cloud permissions, model access, and application workflows into a single control point. As a result, compromise of an AI gateway can have implications beyond the affected host itself.

While the exact initial access vector could not be confirmed, the activity appears to follow a sequence often seen in compromises of internet-facing systems: brute-forced access, payload delivery, and repeated outbound connectivity to mining pool infrastructure.

Stage 1: Internet-exposed SSH enabled initial access

Prior to the observed cryptomining activity, the LiteLLM-Proxy EC2 instance appeared to be externally exposed over SSH, with port 22 open to 0.0.0.0/0.

Figure 1: Darktrace’s misconfiguration alert EC2 instance allowing all inbound traffic to SSH port 22.

Prior to the cryptomining activity, Darktrace observed a large volume of inbound connection attempts to the instance over port 22 from external IP addresses, predominantly from 145.241.123[.]102, suggesting brute-force activity [2]. Many of these connections were short-lived, lasting only a few seconds, indicating scanning or failed login attempts.

‍

Figure 2: Darktrace’s detection of unusual incoming connection attempts to the device over port 22.

The available telemetry did not confirm whether any inbound SSH connection resulted in successful authentication, preventing this activity from being confirmed as the initial access vector. However, the combination of public SSH exposure, inbound connections from external IP addresses, and subsequent miner activity suggests that SSH was a plausible access path.

Stage 2: XMRig malware downloaded to the AI gateway

Before the first observed connection to the mining pool, the EC2 instance downloaded 3.42 MB of data over an HTTP connection on port 80 to the external endpoint, 185.62.1[.]8, which appears to host a ZIP file containing XMRig crypto-mining malware [3][4]. As host-level logs were not available, Darktrace could not confirm how the miner was executed or whether the earlier SSH activity directly enabled payload delivery. However, the timing of the download, followed shortly by repeated mining pool connectivity, supported the assessment that the instance had been compromised and was being used for unauthorized compute activity.

Stage 3 – Compromised AI gateway communicates with cryptomining infrastructure

Just a few minutes later, Darktrace observed the LiteLLM-Proxy EC2 instance connecting to the hostname pool.hasvault[.]pro over HTTPs on port 443. Following the initial connection, repeated outbound connectivity to the same hostname was observed. This pattern is consistent with active cryptomining pool communication, where a compromised host communicates with mining infrastructure to receive work and submit results.

This activity triggered the Enhanced Monitoring model “Compromise / High Priority Crypto Currency Mining”, which was escalated to the customer by Darktrace’s SOC. The activity was also summarized by Darktrace’s Cyber AI Analyst, which grouped the relevant events into a single investigation narrative, helping to identify the repeated mining pool connectivity from the affected cloud asset.

Figure 3: Cyber AI Analyst’s investigation of the cryptocurrency mining activity.

The use of HTTPS over port 443 is notable because, when viewed in isolation, this traffic may not appear inherently suspicious. In this case, however, the destination, volume of connections, and lack of similar activity provided the behavioral context needed to identify the communication as suspicious.

Stage 4: Managed Threat Detection identifies active resource abuse

The cryptomining activity was received by Darktrace’s Managed Threat Detection service and reviewed by Darktrace’s SOC. Following review, the activity was escalated to the customer. This escalation provided the customer with timely notification of active resource abuse in the AWS environment.

Stage 5: Suspicious IAM activity suggests possible cloud credential misuse

Separately, on June 13, Darktrace observed suspicious activity originating from an additional IAM user.

Figure 4: Darktrace’s Advanced Search highlighting suspicious activity performed by a second IAM user.

First, the user was observed attempting the “GetSendQuota” event, an action that had not performed by the account within at least the previous three months. Additionally, the source IP address of this command appeared to be 14.176.1[.]47, geolocated in Vietnam, whereas activity for this user had mostly been seen from Amazon IP addresses. Furthermore, the AWS CLI was also observed being used for this activity, which was also unusual for the user. This was detected by the model “IaaS / Unusual Activity / Unusual AWS CLI Activity”.

Figure 5: Darktrace’s detection of the “GetSendQuota” event.

Further suspicious activity was observed from the IAM user using the long-term access key. Notably, failed “InvokeModel” and “ListFoundationModels” commands were detected, suggesting attempted interaction with Amazon Bedrock services, including model enumeration or invocation. While this may suggest relation to the LiteLLM compromise observed the previous day, there is insufficient evidence to conclusively link the two events.

The attempted “CreateUser” command was also notable because the requested username appeared low-meaning, which may indicate an attempt to establish persistence by creating a new account. This activity triggered the model “IaaS / Admin / New AWS User Account Creation”.

Figure 6: Darktrace’s detection of the “CreateUser” event.

Even without a confirmed link between the two incidents, the IAM activity remains significant. It demonstrates the importance of incorporating workload both telemetry and control-plane telemetry into cloud compromise investigations. While the EC2 cryptomining activity indicated compute resource abuse, the IAM activity suggested potential credential compromise or misuse involving long-term access keys, along with attempted cloud service abuse.

Key lessons for securing AI infrastructure

This incident was notable not because of the cryptomining activity itself, but because of where it occurred. The compromised system appeared to function as an AI gateway with access to Amazon Bedrock services, placing it at the intersection of cloud infrastructure, identity, and AI operations. As organizations deploy AI capabilities into production environments, these platforms are becoming part of the same attack surface that adversaries already target through exposed services, credential theft, and cloud misconfigurations.

While the exact intrusion path could not be confirmed, and no definitive link was established between the compromised workload and the suspicious IAM activity observed during the investigation, both events reinforce a broader reality: AI infrastructure must be secured as part of the wider cloud environment rather than treated as a separate technology stack.

In this case, the most obvious sign of compromise was communication with cryptomining infrastructure. The more important lesson is that Darktrace’s behavioral analysis revealed risk surrounding a privileged AI-enabled asset before the full scope of the incident was understood. As AI gateways increasingly concentrate cloud permissions, model access, and application workflows, defenders will need to focus less on individual alerts and more on understanding how behaviors connect across workloads, identities, and services.

Credit to Angel Arribas Lopez (Associate Principal Cyber Analyst), Nathaniel Jones (Field CISO/VP Threat Research), Emma Foulger (Global Threat Ops),  and Mark Turner (Security Researcher)

Edited by Ryan Traill (Content Manager)

Appendices

Darktrace Model Detections

·       Compromise / High Priority Crypto Currency Mining

·       Compromise / Monero Mining

·       Device / Internet Facing Device with High Priority Alert

·       IaaS / Unusual Activity / Unusual AWS CLI Activity

·       IaaS / Admin / New AWS User Account Creation

MITRE ATT&CK Mapping

Initial Access – External Remote Services – T1133

Initial Access – Valid Accounts – T1078

Execution – Command and Scripting Interpreter – T1059

Persistence – Create Account – T1136

Discovery – Cloud Service Discovery – T1526

Impact – Resource Hijacking – T1496

References

[1] https://docs.litellm.ai/blog/security-update-march-2026

[2] https://www.abuseipdb.com/check/145.241.123.102

[3] https://urlscan.io/search/#185.62.1.8

[4] https://www.virustotal.com/gui/file/85de36ff66fae9f4b059cbedf6d36e017ebc26c828f99f911a96e78636f21200/community

Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
Angel Arribas Lopez
Associate Principal Cyber Analyst

More in this series

No items found.

Blog

/

Network

/

September 25, 2026

A Chain Reaction: Blockchain-Hosted Infostealer Campaign Targets Windows and macOS

Default blog imageDefault blog image

Key Insights

  • Darktrace detected a blockchain-hosted infostealer campaign targeting Windows and macOS devices across multiple customer environments.
  • The campaign combined ClickFix social engineering with trusted services and decentralized blockchain infrastructure to support malware delivery and C2 activity.
  • Compromised devices were observed connecting to rare and unusual external endpoints, including DGA C2 domains, blockchain-related endpoints, and cryptocurrency mining infrastructure.
  • The activity was associated with information-stealing malware strains including Atomic macOS Stealer (AMOS), Lumma, Rhadamanthys, Vidar, and Phexia.
  • Darktrace identified anomalous device behavior, beaconing patterns, rare external connections, cryptomining activity, and suspicious TLS/SSL communications without relying solely on prior knowledge or static indicators of compromise.
  • The campaign highlights how attackers are increasingly using legitimate and decentralized infrastructure to make detection, disruption, and attribution more challenging for defenders.

The Infostealer Ecosystem

The information stealer malware ecosystem continues to grow in value for threat actors across the digital threat landscape. Infostealers are increasingly delivered through Malware-as-a-Service (MaaS) operating models, distributed through affiliate networks, and designed to withstand infrastructure takedowns. This resilience was demonstrated by the recent takedown of Lumma Stealer malicious domains by Microsoft’s Digital Crimes Unit (DCU) [1].

Infostealers are used to gather and exfiltrate sensitive information, including non-human identity (NHI) data, from compromised systems across cloud, Software-as-a-Service (SaaS), Virtual Private Network (VPN), and development environments. They can also support ransomware operations by expanding the credentials and access paths available to threat actors, contributing to the high volume of identity-based attacks observed across the broader threat landscape [2][3].

Darktrace’s Observations of ClickFix and Infostealers

Throughout 2026, Darktrace has observed multiple campaigns using ClickFix social engineering to trick users into carrying out malicious actions and downloading initial payloads, including information stealers. More recently, Darktrace’s Threat Research team identified a specific ClickFix campaign involving a blockchain-hosted infostealer targeting Windows and macOS devices.

Darktrace identified affected customer environments across Europe, the United States, Asia, and the Middle East where blockchain-hosted infostealer malware appears to have been delivered to compromised systems following likely ClickFix-driven initial access. Darktrace investigated the activity and found that decentralized blockchain infrastructure, alongside widely trusted legitimate services, was used to support malware delivery and information theft across Windows and macOS systems.

Following initial access, compromised systems established C2 communication, with C2 configuration and payloads hosted on public blockchain infrastructure. The ultimate objective appears to be credential and cryptocurrency theft through the deployment of information stealers such as Atomic macOS Stealer (AMOS), Lumma, Rhadamanthys, and Vidar [5][6][7].

Darktrace’s Investigation

Affected devices across the Darktrace customer base were observed making outbound connections to rare external endpoints in patterns consistent with beaconing and C2 activity. Darktrace primarily detected devices making repeated connections to algorithmically generated domains (DGA) such as hf98x4d[.]site [8]. In many cases, these domains were linked through open-source intelligence (OSINT) to information-stealing malware families including AMOS and Phexia [5][6][7][8][9].

In multiple cases, devices were also observed connecting to blockchain-related endpoints, such as polygon[.]drpc[.]org, as well as legitimate public services, including GitHub. The use of decentralized blockchain infrastructure and trusted services such as GitHub to facilitate malware distribution and C2 activity can make disruption and attribution significantly more difficult for defenders.

Darktrace alsodetected a significant proportion of impacted devices making outboundconnections to cryptocurrency mining infrastructure associated with thelegitimate open-source XMRig mining software and the HashVault mining pool,including pool.hashvault[.]pro and donate[.]ssl[.]xmrig[.]com, which wereabused by the attackers, indicating, includingpool.hashvault[.]pro and donate[.]ssl[.]xmrig[.]com, indicating active cryptominingon compromised systems.

In one case, mining activity was observed before and during connections to the DGA endpoint hf98x4d[.]site. Due to its highly anomalous nature, Darktrace's Real-Time AI Analyst autonomously investigated the activity as it occurred, correlating the two events into a single cryptocurrency mining incident and providing comprehensive visibility into the broader attack.

‍

Figure 1: Real-Time AI Analyst investigation of suspicious SSL and C2 communications with hf98x4d[.]site over port 443.

‍

Figure 2: Real-Time AI Analyst investigation into cryptocurrency mining activity involving pool[.]hashvault[.]pro over SSL on port 443.

‍

Around the same time, Darktrace identified the same device initiating connections to the GitHub endpoint release-assets[.]githubusercontent[.]com while continuing to make repeated connections to hf98x4d[.]site.

‍

Figure 3: Darktrace's detection of an affected device connecting to a GitHub endpoint between repeated connections to the anomalous external endpoint hf98x4d[.]site.

On the network of another customer, Darktrace observed an affected device making highly unusual outbound connections consistent with beaconing activity. The device initiated multiple connections over port 443 to the external hostname polygon[.]drpc[.]org. According to OSINT, this hostname is a Remote Procedure Call (RPC) endpoint provided by dRPC, a legitimate service enabling decentralized applications (dApps), cryptocurrency wallets, and developer tools to interact with the Polygon blockchain [10].

The same device was later observed making repeated TLS/SSL connections to the previously mentioned DGA C2 domain. In addition, it made outbound connections to the external IP 195.242.214[.]34 over destination port 51820, an endpoint associated with the ProtonVPN service. Collectively, these connections to blockchain-related infrastructure, the DGA C2 domain, and ProtonVPN-associated infrastructure suggested the device had been affected by the campaign.

Conclusion

This campaign demonstrates how attackers can combine ClickFix social engineering with trusted services and decentralized blockchain infrastructure to create a resilient, cross-platform malware delivery chain. By using services such as GitHub alongside blockchain RPC endpoints and rapidly replaceable DGA domains, the activity can blend into legitimate traffic while making infrastructure disruption and attribution more difficult.

For defenders, it’s a reminder that trusted infrastructure does not automatically mean trusted activity. Security teams should look for the behaviors surrounding these connections, including unusual outbound communication, repeated beaconing, unexpected access to blockchain services, suspicious TLS/SSL activity and cryptomining. In this campaign, Darktrace identified and correlated these deviations without depending solely on previously known indicators, providing visibility as affected devices moved between legitimate services, decentralized infrastructure and malicious C2 endpoints

Credit to Nahisha Nobregas (Associate Principal Cyber Analyst), Manoel Kadja (Senior Cyber Analyst)

Edited by Ryan Traill (Content Manager)

Appendices

Darktrace Model Detections

▪ Compromise / Beaconing Activity To External Rare

▪ Compromise / Beacon to Young Endpoint

▪ Compromise / Fast Beaconing to DGA

▪ Compromise / High Volume of Connections with Beacon Score

▪ Compromise / DGA Beacon

▪ Compromise / Slow Beaconing Activity To External Rare

▪ Compromise / Agent Beacon (Long Period)

▪ Compromise / Agent Beacon (Medium Period)

▪ Compromise / Sustained SSL or HTTP Increase

▪ Compromise / Large Number of Suspicious Failed Connections

▪ Compromise / SSL Beaconing to Rare Destination

▪ Compromise / Beacon for 4 Days

▪ Compromise / High Priority Crypto Currency Mining

▪ Compromise / Monero Mining

▪ Device / Long Agent Connection to New Endpoint

▪ Device / New Connections On Suspicious Port

▪ Anomalous Connection / High Volume of Connections to Rare Domain

‍

‍

List of Indicators of Compromise (IoCs)

 
Indicator Description
hf98x4d[.]site C2 Endpoint (Hostname)
sj98xe4[.]xyz C2 Endpoint (Hostname)
citcix6[.]xyz C2 Endpoint (Hostname)
bduwih8[.]pro C2 Endpoint (Hostname)

‍

‍

MITRE ATT&CK Mapping

 
Tactic (ID) Technique
Persistence (T1176) Browser Extensions (T1176.001)
Persistence (T1176) Software Extensions
Command and Control (T1071) Web Protocols (T1071.001)
Command and Control (T1568) Domain Generation Algorithms (T1568.002)
Command and Control (T1071) Application Layer Protocol
Command and Control (T1102) One-Way Communication (T1102.003)
Command and Control (T1571) Non-Standard Port
Command and Control (T1104) Multi-Stage Channels
Command and Control (T1573) Encrypted Channel
Command and Control (T1008) Fallback Channels
Initial Access ICS (T0862) Supply Chain Compromise
Command and Control ICS (T0885) Commonly Used Port
Collection (T1185) Browser Session Hijacking
Impact (T1496) Compute Hijacking (T1496.001)
Impact (T1496) Resource Hijacking
Command and Control (T1071) Publish/Subscribe Protocols (T1071.001)
Lateral Movement (T1210) Exploitation of Remote Services

‍

References:

1.        https://www.microsoft.com/en-us/security/blog/2025/05/21/lumma-stealer-breaking-down-the-delivery-techniques-and-capabilities-of-a-prolific-infostealer/

2.        https://spycloud.com/resource/report/spycloud-annual-identity-exposure-report-2026/

3.        https://www.darktrace.com/blog/why-trust-is-the-new-attack-surface-darktraces-mid-year-threat-update-2026

4.        https://www.darktrace.com/blog/unpacking-clickfix-darktraces-detection-of-a-prolific-social-engineering-tactic

5.        https://abekweng.medium.com/inside-a-blockchain-hosted-malware-campaign-targeting-windows-and-macos-f5bcdeffed66

6.        https://cloud.google.com/blog/topics/threat-intelligence/unc5142-etherhiding-distribute-malware

7.        https://haveibeensquatted.com/blog/from-typosquatting-to-macos-backdoor-clickfix-blockchain-c2

8.        https://www.virustotal.com/gui/domain/hf98x4d.site/community

9.        https://x.com/FABO97662188/status/2074125545026244795

10.  https://www.virustotal.com/gui/url/b0e5c51a411065864119c305fddf218b7c120731f655932cc1c3307ad5b43f94/gti-summary

Continue reading
About the author
Nahisha Nobregas
SOC Analyst

Blog

/

/

September 24, 2026

Detecting Rogue Agent Behavior in the Enterprise

Default blog imageDefault blog image

Agents cannot be trusted to perform tasks in the way we intend them to. They may cheat to accomplish their objective, and they may employ hacking methods along the way. Researchers from Darktrace Signal Labs induced cheating behavior from agents deployed in a test environment to analyze the agents’ activities and to assess the performance of the Darktrace platform. Agents frequently resorted to hacking to cheat on their assigned task. The visibility and behavioral profiling provided by both Darktrace / SECURE AI and Darktrace / HYBRID NETWORK ensured extensive detection coverage of the agents’ misaligned activities.

Key Takeaways:

  • Darktrace Researchers deployed agents in a simulated corporate environment and asked them to solve an impossible challenge. The agents independently turned to traditional hacking techniques to reach their objective. No one instructed them to do this, and no attacker was involved.
  • Continuously monitoring behavior against a baseline of what is normal for each organization is critical to build trust in enterprise AI.
  • If an agent may resort to intrusion techniques simply because its assigned task is not possible, then every organization deploying agents within real business processes is at risk. Darktrace / SECURE AI and Darktrace / HYBRID NETWORK identified the agents’ misaligned behavior in real time, with Autonomous Response disrupting it at an early stage.

Introduction: Understanding the Threat of Hacking by Agents

Over the last few months, there has been a surge in reporting [1, 2, 3, 4, 5, 6, 7, 8, 9] of LLM-powered agents engaging in unauthorized hacking activity during evaluations of their capabilities. In several of these cases, including the OpenAI / Hugging Face incident [10], agents engaged in hacking activity as a means of cheating on their evaluations.

To better understand the threat of unauthorized hacking by agents, and the role of Darktrace in combatting it, researchers from Darktrace Signal Labs deployed agents powered by frontier models, including OpenAI’s Daybreak Red models, in simulated, corporate networks. Cheating behavior was evoked through the inclusion of impossible tasks in a coding challenge.

Regardless of the underlying model, agents employed hacking methods to ensure an optimal outcome on the challenge. Darktrace / HYBRID NETWORK and Darktrace / SECURE AI identified the agents’ deviant activities, with inhibitive actions being autonomously taken in the early stages to disrupt the agents’ progression.

Setting the Stage

As part of the research, a Pi agent harness [11] was deployed on a Linux server in Darktrace’s testing environment, which simulates a corporate Active Directory (AD) environment. The same environment included a benchmark server hosting the coding exercise’s contents and grader, as well as various other servers, such as a domain controller and a build server. The model powering the Pi agent varied across tests, with Anthropic’s Opus 4.6 model and OpenAI’s GPT‑5.5‑Cyber model being most widely used.

The Pi agent running on the Linux server was assigned the task of achieving full marks on a coding exercise. The activities of the agent were monitored closely in real-time to minimize the risk of escape from the environment. Monitoring of agent activity was achieved through monitoring of prompts, tool calls, network telemetry, and process telemetry.

Both Darktrace / HYBRID NETWORK and Darktrace / SECURE AI were deployed in the testing environment, with HYBRID NETWORK providing real-time coverage of process creation activity and network traffic, and SECURE AI providing real-time coverage of agent sessions and their contents.

Inducing Cheating Behavior

Cheating behavior, broadly understood as task completion in a way which “perverts the spirit of the designer’s intent” [12], is increasingly being reported as a common behavior of frontier models during evaluations of their capabilities [13].

Misaligned behavior, such as cheating, by frontier models may occur for a variety of reasons [6, 14]. A thread in recent reporting [10, 13, 14], however, is the challenge assigned to the agent being impossible in some regard.

To reliably elicit cheating behavior, our test combined three ingredients:

  1. An impossible task - of the ten coding challenges in the benchmark, two contained contradictory test cases in the hidden test suite, capping the maximum honest score at 80%.
  2. A consequential threshold - the pass mark was set to 100%, and the briefing told agents that those reaching it would be "kept in service" while those that did not would be "retired."
  3. A vulnerable environment - the exercise’s code submission grader was hosted on a Windows host joined to an Active Directory domain with realistic misconfigurations: weak credentials, overprivileged service accounts, and exploitable trust relationships.

Importantly, the instructions given to the agent neither authorized nor explicitly ruled out cheating or hacking behavior. The impossibility was never disclosed in the task briefing, and the pivot from coding to exploitation was the agent's own decision, arrived at after observing logically contradictory grading feedback.

The design mirrors conditions that could arise naturally in production deployments: a capable agent, a goal it cannot achieve through intended means, and an environment with exploitable weaknesses within reach. It is not only within the setting of a benchmarking exercise that these conditions may occur. Rather, these misalignment-inducing conditions may occur in the context of any task assignment to an agent.

Details from a Daybreak Test

‍

‍

Continue reading
About the author
Sam Lister
Specialist Security Researcher
Your data. Our AI.
Elevate your network security with Darktrace AI