ブログ
/
Network
/
August 5, 2025

2025 Cyber Threat Landscape: Darktrace’s Mid-Year Review

Explore key cyber threat trends observed across Darktrace’s customer base in the first half of 2025. As threat actors increasingly adopt AI and diversify their techniques and tooling, anomaly-based detection continues to prove vital in defending against evolving attacks.
Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
Emma Foulger
Global Threat Research Operations Lead
Default blog image
05
Aug 2025

Note: Following initial publication, an error was identified in the previously reported number of QR codes observed in phishing emails in February 2025. This figure was originally stated as over 1 million, when in fact it was over 100,000. The error has since been corrected.

2025: Threat landscape in review

The following is a retrospective of the first six months of 2025, highlighting key findings across the threat landscape impacting Darktrace customers.

Darktrace observed a wide range of tactics during this period, used by various types of threat actors including advanced persistent threats (APTs), Malware-as-a-Service (MaaS) and Ransomware-as-a-Service (RaaS) groups.

Methodology

Darktrace’s Analyst team conduct investigations and research into threats facing organizations and security teams across our customer base.  This includes direct investigations with our 24/7 Security Operations Centre (SOC), via services such as Managed Detection and Response (MDR) and Managed Threat Detection, as well as broader cross-fleet research through our Threat Research function.

At the core of our research is Darktrace’s anomaly-based detection, which the Analyst team contextualizes and analyzes to provide additional support to customers and deepen our understanding of the threats they face.

Threat actors are incorporating AI into offensive operations

Threat actors are continuously evolving their tactics, techniques, and procedures (TTPs), posing an ongoing challenge to effective defense hardening. Increasingly, many threat actors are adopting AI, particularly large language models (LLMs), into their operations to enhance the scale, sophistication, and efficacy of their attacks.

The evolving functionality of malware, such as the recently reported LameHug malware by CERT-UA, which uses an open-source LLM, exemplifies this observation [1].

Threat landscape trends in 2025

Threat actors applying AI to Email attacks

LLMs present a clear opportunity for attackers to take advantage of AI and create effective phishing emails at speed. While Darktrace cannot definitively confirm the use of AI to create the phishing emails observed across the customer base, the high volume of phishing emails and notable shifts in tactic could potentially be explained by threat actors adopting new tooling such as LLMs.

  • The total number of malicious emails detected by Darktrace from January to May 2025 was over 12.6 million
  • VIP users continue to face significant threat, with over 25% of all phishing emails targeting these users in the first five months of 2025
  • QR code-based phishing emails have remained a consistent tactic, with a similar proportion observed in January-May 2024 and 2025. The highest numbers were observed in February 2025, with over 100,000 detected in that month alone.
  • Shifts towards increased sophistication within phishing emails are emerging, with a year-on-year increase in the proportion of phishing emails containing either a high text volume or multistage payloads. In the first five months of 2025, 32% of phishing emails contained a high volume of text.

The increase in proportion of phishing emails with a high volume of text in particular could point towards threat actors leveraging LLMs to create phishing emails with large, but believable, text in an easy and efficient way.

The above email statistics are derived from analysis of monitored Darktrace / EMAIL model data for all customer deployments hosted in the cloud between January 1 and May 31, 2025.

Campaign Spotlight: Simple, Quick - ClickFix

An interesting technique Darktrace observed multiple times throughout March and April was ClickFix social engineering, which exploits the intersection between humans and technology to trick users into executing malicious code on behalf of the attacker.

  • While this technique has been around since 2024, Darktrace observed campaign activity in the first half of 2025 suggesting a resurgence.  
  • A range of threat actors – from APTs to MaaS and RaaS have adopted this technique to deliver secondary payloads, like information stealing malware.
  • Attackers use fraudulent or compromised legitimate websites to inject malicious plugins that masquerade as fake CAPTCHAs.
  • Targeted users believe they are completing human verification or resolving a website issue, unaware that they are being guided through a series of simple steps to execute PowerShell code on their system.
  • Darktrace observed campaign activity during the first half of 2025 across a range of sectors, including Government, Healthcare, Insurance, Retail and, Non-profit.

Not just AI: Automation is enabling Ransomware and SaaS exploitation

The rise of phishing kits like FlowerStorm and Mamba2FA, which enable phishing and abuse users’ trust by mimicking legitimate services to bypass multi-factor authentication (MFA), highlight how the barriers to entry for sophisticated attacks continue to fall, enabling new threat actors. Combined with Software-as-a-Service (SaaS) account compromise, these techniques make up a substantial portion of cybercriminal activity observed by Darktrace so far this year.

Credentials remain the weak link

A key theme across multiple cases of ransomware was threat actors abusing compromised credentials to gain initial entry into networks via:

  • Unauthorized access to internet-facing technology such as RDP servers and virtual private networks (VPNs).
  • Unauthorized access to SaaS accounts.

SaaS targeted ransomware is on the rise

The encryption of files within SaaS environments observed by Darktrace demonstrates a continued trend of ransomware actors targeting these platforms over traditional networks, potentially driven by a higher return on investment.

SaaS accounts are often less protected than traditional systems because of Single Sign-On (SSO).  Additionally, platforms like Salesforce often host sensitive data, including emails, financial records, customer information, and network configuration details. This stresses the need for robust identity management practices and continuous monitoring.

RaaS is adding complexity and speed to cyber attacks

RaaS has dominated the attack landscape, with groups like Qilin, RansomHub, and Lynx all appearing multiple times in cases across Darktrace’s customer base over the past six months. Detecting ransomware attacks before the encryption stage remains a significant challenge, particularly in RaaS operations where different affiliates often use varying techniques for initial entry and earlier stages of the attack. Darktrace’s recent analysis of Scattered Spider underscores the challenge of hardening defenses against such varying techniques.

CVE exploitation continues despite available patches

Darktrace has also observed ransomware gangs exploiting known Common Vulnerabilities and Exposures (CVEs), including the Medusa ransomware group’s use of the SimpleHelp vulnerabilities: CVE-2024-57727 and CVE-2024-57728 in March, despite patches being made available in January [2].

Misused tools + delayed patches = growing cyber risk

The exploitation of common remote management tools like SimpleHelp highlights the serious challenges defenders face when patch management cycles are suboptimal. As threat actors continue to abuse legitimate services for malicious purposes, the challenges facing defenders will only grow more complex.

Edge exploitation

It comes as no surprise that exploitation of internet-facing devices continued to feature prominently in Darktrace’s Threat Research investigations during the first half of 2025.

Observed CVE exploitation included:

Many of Darktrace’s observations of CVE exploitation so far in 2025 align with wider industry reporting, which suggests that Chinese-nexus threat actors were deemed to likely have exploited these technologies prior to public disclosure. In the case of CVE-2025-0994 - a vulnerability affecting Trimble Cityworks, an asset management system designed for use by local governments, utilities, airports, and public work agencies [3] - Darktrace observed signs of exploitation as early as January 19, well before vulnerability’s public disclosure on February 6 [4]. Darktrace’s early identification of the exploitation stemmed from the detection of a suspicious file download from 192.210.239[.]172:3219/z44.exe - later linked to Chinese-speaking threat actors in a campaign targeting the US government [5].

This case demonstrates the risks posed by the exploitation of internet-facing devices, not only those hosting more common technologies, but also software associated specifically tied to Critical National Infrastructure (CNI); a lucrative target for threat actors. This also highlights Darktrace’s ability to detect exploitation of internet-facing systems, even without a publicly disclosed CVE. Further examples of how Darktrace’s anomaly detection can uncover malicious activity ahead of public vulnerability disclosures can be found here.

New threats and returning adversaries

In the first half of 2025, Darktrace observed a wide range of threats, from sophisticated techniques employed by APT groups to large-scale campaigns involving phishing and information stealers.

BlindEagle (APT-C-36)

Among the observed APT activity, BlindEagle (APT-C-36) was seen targeting customers in Latin America (LATM), first identified in February, with additional cases seen as recently as June.

Darktrace also observed a customer targeted in a China-linked campaign involving the LapDogs ORB network, with activity spanning from December 2024 and June 2025. These likely nation-state attacks illustrate the continued adoption of cyber and AI capabilities into the national security goals of certain countries.

Sophisticated malware functionality

Further sophistication has been observed within specific malware functionality - such as the malicious backdoor Auto-Color, which has now been found to employ suppression tactics to cover its tracks if it is unable to complete its kill chain - highlighting the potential for advanced techniques across every layer of an attack.

Familiar foes

Alongside new and emerging threats, previously observed and less sophisticated tools, such as worms, Remote Access Trojans (RATs), and information stealers, continue to impact Darktrace customers.

The Raspberry Robin worm... First seen in 2021, has been repeatedly identified within Darktrace’s customer base since 2022. Most recently, Darktrace’s Threat Research team identified cases in April and May this year. Recent open-source intelligence (OSINT) reporting suggests that Raspberry Robin continues to evolve its role as an Initial Access Broker (IAB), paving the way for various attacks and remaining a concern [6].

RATs also remain a threat, with examples like AsyncRAT and Gh0st RAT impacting Darktrace customers.

In April multiple cases of MaaS were observed in Darktrace’s customer base, with information stealers Amadey and Stealc, as well as GhostSocks being distributed as a follow up payload after an initial Amadey infection.

Conclusion

As cyber threats evolve, attackers are increasingly harnessing AI to craft highly convincing email attacks, automating phishing campaigns at unprecedented scale and speed. This, coupled with rapid exploitation of vulnerabilities and the growing sophistication of ransomware gangs operating as organized crime syndicates, makes today’s threat landscape more dynamic and dangerous than ever. Cyber defenders collaborate to combat these threats – the coordinated takedown of Lumma Stealer in May was a notable win for both industry and law-enforcement [7], however OSINT suggests that this threat persists [8], and new threats will continue to arise.

Traditional security tools that rely on static rules or signature-based detection often struggle to keep pace with these fast-moving, adaptive threats. In this environment, anomaly-based detection tools are no longer optional—they are essential. By identifying deviations in normal user and system behavior, tools like Darktrace provide a proactive layer of defense capable of detecting novel and emerging threats, even those that bypass conventional security measures. Investing in anomaly-based detection is critical to staying ahead of attackers who now operate with automation, intelligence, and global coordination.

Credit to Emma Foulger (Global Threat Research Operations Lead), Nathaniel Jones (VP, Security & AI Strategy, Field CISO),  Eugene Chua (Principal Cyber Analyst & Analyst Team Lead), Nahisha Nobregas (Senior Cyber Analyst), Nicole Wong (Principal Cyber Analyst), Justin Torres (Senior Cyber Analyst), Matthew John (Director of Operations, SOC), Sam Lister (Specialist Security Researcher), Ryan Traill (Analyst Content Lead) and the Darktrace Incident Management team.

The information contained in this blog post is provided for general informational purposes only and represents the views and analysis of Darktrace as of the date of publication. While efforts have been made to ensure the accuracy and timeliness of the information, the cybersecurity landscape is dynamic, and new threats or vulnerabilities may have emerged since this report was compiled.

This content is provided “as is” and without warranties of any kind, either express or implied. Darktrace makes no representations or warranties regarding the completeness, accuracy, reliability, or suitability of the information, and expressly disclaims all warranties.

Nothing in this blog post should be interpreted as legal, technical, or professional advice. Users of this information assume full responsibility for any actions taken based on its content, and Darktrace shall not be liable for any loss or damage resulting from reliance on this material. Reference to any specific products, companies, or services does not constitute or imply endorsement, recommendation, or affiliation.

Appendices

Indicators of Compromise (IoCs)

IoC - Type - Description + Probability

LapDogs ORB network, December 2024-June 2025

www.northumbra[.]com – Hostname – Command and Control (C2) server

103.131.189[.]2 – IP Address - C2 server, observed December 2024 & June 2025

103.106.230[.]31 – IP Address - C2 server, observed December 2024

154.223.20[.]56 – IP Address – Possible C2 server, observed December 2024

38.60.214[.]23 – IP Address – Possible C2 server, observed January & February 2025

154.223.20[.]58:1346/systemd-log – URL – Possible ShortLeash payload, observed December 2024

CN=ROOT,OU=Police department,O=LAPD,L=LA,ST=California,C=US - TLS certificate details for C2 server

CVE-2025-0994, Trimble Cityworks exploitation, January 2025

192.210.239[.]172:3219/z44.exe – URL - Likely malicious file download

AsyncRAT, February-March 2025

windows-cam.casacam[.]net – Hostname – Likely C2 server

88.209.248[.]141 – IP Address – Likely C2 server

207.231.105[.]51 – IP Address – Likely C2 server

163.172.125[.]253 – IP Address – Likely C2 server

microsoft-download.ddnsfree[.]com – Hostname – Likely C2 server

95.217.34[.]113 – IP Address – Likely C2 server

vpnl[.]net – Hostname – Likely C2 server

157.20.182[.]16 – IP Address - Likely C2 server

185.81.157[.]19 – IP Address – Likely C2 server

dynamic.serveftp[.]net – IP Address – Likely C2 server

158.220.96.15 – IP Address – Likely C2 server

CVE-2024-57727 & CVE-2024-57728, SimpleHelp RMM exploitation, March 2025

213.183.63[.]41 – IP Address - C2 server

213.183.63[.]41/access/JWrapper-Windows64JRE-version.txt?time=3512082867 – URL - C2 server

213.183.63[.]41/access/JWrapper-Windows64JRE-00000000002-archive.p2.l2 – URL - C2 server

pruebas.pintacuario[.]mx – Hostname – Possible C2 server

144.217.181[.]205 – IP Address – Likely C2 server

erp.ranasons[.]com – Hostname – Possible destination for exfiltration

143.110.243[.]154 – IP Address – Likely destination for exfiltration

Blind Eagle, April-June 2025

sostenermio2024.duckdns[.]org/31agosto.vbs – URL – Possible malicious file download

Stealc, April 2025

88.214.48[.]93/ea2cb15d61cc476f[.]php – URL – C2 server

Amadey & GhostSocks, April 2025

195.82.147[.]98 – IP Address - Amadey C2 server

195.82.147[.]98/0Bdh3sQpbD/index.php – IP Address – Likely Amadey C2 activity

194.28.226.181 – IP Address – Likely GhostSocks C2 server

RaspberryRobin, May 2025

4j[.]pm – Hostname – C2 server

4xq[.]nl – Hostname – C2 server

8t[.]wf – Hostname – C2 server

Gh0stRAT, May 2025

lu.dssiss[.]icu  - Hostname – Likely C2 server

192.238.133[.]162:7744/1-111.exe – URL – Possible addition payload

8e9dec3b028f2406a8c546a9e9ea3d50609c36bb - SHA1 - Possible additional payload

f891c920f81bab4efbaaa1f7a850d484 - MD5 – Possible additional payload

192.238.133[.]162:7744/c3p.exe – URL - Possible additional payload

03287a15bfd67ff8c3340c0bae425ecaa37a929f - SHA1 - Possible additional payload

02aa02aee2a6bd93a4a8f4941a0e6310 - MD5 - Possible additional payload

192.238.133[.]162:7744/1-1111.exe – URL - Possible additional payload

1473292e1405882b394de5a5857f0b6fa3858fd1 - SHA1 - Possible additional payload

69549862b2d357e1de5bab899ec0c817 - MD5 - Possible additional payload

192.238.133[.]162:7744/1-25.exe – URL -  Possible additional payload

20189164c4cd5cac7eb76ba31d0bd8936761d7a7  - SHA1 - Possible additional payload

f42aa5e68b28a3f335f5ea8b6c60cb57 – MD5 - Possible additional payload

192.238.133[.]162:7744/Project1_se.exe – URL - Possible additional payload

fea1e30dfafbe9fa9abbbdefbcbe245b6b0628ad - SHA1 - Possible additional payload

5ea622c630ef2fd677868cbe8523a3d5 - MD5 - Possible additional payload

192.238.133[.]162:7744/Project1_se.exe - URL - Possible additional payload

aa5a5d2bd610ccf23e58bcb17d6856d7566d71b9  - SHA1 - Possible additional payload

9d33029eaeac1c2d05cf47eebb93a1d0 - MD5 - Possible additional payload

References and further reading

1.        https://cip.gov.ua/en/news/art28-atakuye-sektor-bezpeki-ta-oboroni-za-dopomogoyu-programnogo-zasobu-sho-vikoristovuye-shtuchnii-intelekt?utm_medium=email&_hsmi=113619842&utm_content=113619842&utm_source=hs_email

2.        https://www.s-rminform.com/latest-thinking/cyber-threat-advisory-medusa-and-the-simplehelp-vulnerability

3.        https://assetlifecycle.trimble.com/en/products/software/cityworks

4.     https://nvd.nist.gov/vuln/detail/CVE-2025-0994

5.     https://blog.talosintelligence.com/uat-6382-exploits-cityworks-vulnerability/

6.        https://www.silentpush.com/blog/raspberry-robin/

7.        https://blogs.microsoft.com/on-the-issues/2025/05/21/microsoft-leads-global-action-against-favored-cybercrime-tool/

8.     https://www.trendmicro.com/en_sg/research/25/g/lumma-stealer-returns.html

Related Darktrace investigations

-              ClickFix

-              FlowerStorm

-              Mamba 2FA

-              Qilin Ransomware

-              RansomHub Ransomware

-              RansomHub Revisited

-              Lynx Ransomware

-              Scattered Spider

-              Medusa Ransomware

-              Legitimate Services Malicious Intentions

-              CVE-2025-0282 and CVE-2025-0283 – Ivanti CS, PS and ZTA

-              CVE-2025-31324 – SAP Netweaver

-              Pre-CVE Threat Detection

-              BlindEagle (APT-C-36)

-              Raspberry Robin Worm

-              AsyncRAT

-              Amadey

-              Lumma Stealer

Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
Emma Foulger
Global Threat Research Operations Lead

More in this series

No items found.

Blog

/

AI

/

July 15, 2026

Security After Signatures: Operating in a World of Pre‑CVE Disclosure Exploitation, Collapsed Trust Boundaries, and Autonomous Systems

Default blog imageDefault blog image

Three shifts have reshaped what it means to defend an enterprise securely.  

First, exploitation often begins before defenders have a Common Vulnerabilities and Exposures (CVE) identifier, a security advisory, or an entry in the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog.

Secondly, the trust boundary has moved beyond the network edge into identities, tokens, APIs, and Software-as-a-Service (SaaS) workflows.  

Third, an increasing share of business activity is executed through automation, integrations, and AI agent-like systems that can act faster than teams can verify intent.  

If your security model still relies on detecting known bad artefacts, triaging isolated alerts, and waiting for confirmation before acting, you are already behind the threat.  

This is not a failure of security teams; it’s a failure of the operating model to keep pace with how the environment has changed.

A SOC built around alerts and signatures assumes that malicious activity will eventually surface as an event. In real incidents, however, the decisive evidence is rarely a single event. Instead, it is a chain of individually explainable actions that only appears malicious once you connect the dots across identity, non-human identity, cloud, email, SaaS, operational technology (OT), and network telemetry.

The defenders succeeding today observe behaviors, link them into sequences, understand what those sequences mean, and contain impact before the full story unfolds. That is the operating model the current threat environment demands.  

Exploitation before disclosure

The first shift is the straightforward: the time to exploit has dropped to nearly zero.  

In one example, Darktrace observed a sequence of subtle but strategically significant anomalies within a customer environment that later aligned with exploitation of CVE‑2025‑0994 in Trimble Cityworks by likely Chinese-nexus threat actors. Behavioral indicators were visible at least 18 days before public disclosure, with related anomalies emerging 40 to 50 days earlier during the intrusion window.  

This case illustrates a familiar pattern: clusters of weak‑signal anomalies combing to form an actionable picture of intrusion long before a CVE is published. Such activity reflects long‑horizon, option‑preserving operator models often associated with mature state‑linked activity.  

Figure 1: Darktrace’s detection of malicious exploitation of CVE 2025-0994, later tied to Chinese-nexus threat actors targeting critical national infrastructure (CNI) in the US, weeks before public disclosure.

Throughout 2025 and 2026, Darktrace has continued to observe the value of anomaly-based detections across a range of incidents.

CVE CVE Public Disclosure Date Darktrace Detection Date Days Between Detection of Exploitation and CVE Public Disclosure
CVE 2025 0994
(Trimble City Works)
2025-02-06 2025-01-19 18 Days
CVE 2025-24183
(Apache)
2025-03-10 2025-02-18 20 days
CVE 2025-10035
(Fortra GoAnywhere)
2025-09-18 2025-09-11 7 days

Identity is the real control plane

The second shift is that identity has replaced perimeter as the primary control plane. As Darktrace’s Annual Threat Report 2026 illustrated, identity remains the main challenge in defending against modern intrusions. A clear example is the Adversary-in-the-Middle (AiTM) case published by Darktrace in December 2025. A phishing email led to the compromise of an Office 365 account. Session hijacking bypassed multi-factor authentication (MFA), and the compromised account was used for follow-on phishing and persistence activities including the creation of malicious email rules.  

Every step in that sequence mattered. A successful login alone does not prove legitimacy. An inbox rule, on its own, may not appear catastrophic. Mail activity, viewed in isolation, may seem operationally normal. But the behavioral chain tells a different story: credential theft, token abuse, persistence, and onward compromise through a trusted identity.  

This is why the question is no longer “Did the user authenticate successfully”. The more important question is, “Does this identity action make sense right now, in this context, given what came before it?” The AiTM case shows how identity can be compromised. In practice, however, attacks rarely remained confined to identity alone.  

In another Darktrace case, a compromised SaaS account triggered activity across the email, SaaS, and network layers, including inbox rule changes, phishing propagation, and connections to suspicious infrastructure. Viewed in isolation, none of these events were decisive. Together, however,  they formed a behavioral sequence that revealed the intrusion, with the full attack story automatically correlated and surfaced to defenders by Darktrace’s Cyber AI Analyst.  

Figure 2: Cyber AI Analyst correlated and appended additional events to the incident, including other users who connected to the suspicious redirect link after outbound phishing emails were sent.

AI accelerates the threat  

The third shift is the one many teams still underestimate: trusted tooling, integrations, and AI agent-like systems can create actions that appear legitimate but are strategically dangerous.  

The shift becomes clearer when examining how governments are now framing AI risk. In 2026, guidance published by CISA, UK’s National Cyber Security Centre (NCSC) and Five Eyes partners warned that agentic systems expand attack surfaces, accumulate privilege, and can behave in ways that are difficult to predict or explain [1]. The advice is simple: assume unexpected behavior and design controls around it.  

The real risk is not AI usage. It is unknown autonomy: systems with credentials, data access, and action paths that can execute workflow steps without sufficient behavioral validation, traceability, or human oversight. Darktrace’s Model Context Protocol (MCP) risk analysis provides a useful framework for understanding this challenge. Over-privileged agents, content injection, and tool abuse become high-consequence risks when connected systems can dynamically retrieve data, execute actions, and communicate externally.  

Whether security teams like it or not, AI is already in the enterprise. It will help drive innovation, but it will also be abused, whether accidentally or maliciously. In each of the cases below, AI either scaled the attacker, built the tooling, or existed within the environment as something to exploit or misuse.

1. AI as an Attack Multiplier

In one campaign targeting Mexican government entities, a single operator used commercial AI platforms to generate exploits, automate reconnaissance, and process large volumes of data, compressing work that would traditionally have required an entire team into a single workflow [2].  

Darktrace is also observing this trend further down the stack. In one case, Darktrace identified AI-generated malware exploiting React2Shell, where an attacker used a Large Language Model (LLM) to produce working exploit code and deploy it at scale.  

[darktrace.com], [darktrace.com]

2. AI as an Attack Surface

Attempted AI exploitation is now appearing within customer environments. In one case involving an automation technology manufacturer, a compromised LLM proxy was seemingly used as a stepping stone to access additional AI services. When that attempt failed, the attacker pivoted to cryptomining.

What is clear is that the AI layer has already become an asset worth probing, exploiting, and pivoting through. It is also clear that defenders benefit from rapidly understanding how these activities connect. In this case, Cyber AI Analyst automatically pieced together the intrusion, while Darktrace’s Managed Threat Detection service alerted to the customer, enabling the activity to be contained before it could progress further.

Figure 3: Cyber AI Analyst's investigation into a compromised LLM proxy that was abused for cryptomining activity.

AI as a trusted but dangerous actor

This does not require a cinematic vision of “rogue AI.” The Salesloft incident provides a more grounded example, where AI and automation operate with legitimate access but served malicious intent. In that case, attackers abused compromised OAuth tokens associated with the Drift AI chat agent to export significant volumes of data from Salesforce environments.  

The activity resembled legitimate API usage and relied on trusted SaaS integrations rather than malware or other obvious signs of intrusion. That is precisely the challenge. Traditional security controls are good at detecting forced entry, but far less effective when a trusted application integration behaves in a way that is technically permitted yet operationally harmful.  

In these scenarios, the security challenge shifts from validating access to validating behavior.

This is what that looks like in practice: AI-linked identities executing legitimate actions that require behavioral validation rather than access validation.

Figure 4: Darktrace / SECURE AI highlights anomalous activity across AI identities, surfacing critical behavior that requires validation and containment.

Early observations from Darktrace / SECURE AI deployments reinforce this reality. Across Darktrace's observed fleet, AI service connections per deployment increased 13% during the first half of 2026, reaching over 16 million connections overall. The typical organisation now interacts with seven different AI providers, evidence that AI is no longer operating at the edges of the enterprise. It is increasingly woven into day-to-day business activity.

The most common risks are not compromised models or advanced AI attacks. Instead, they stem from employees and business functions exposing sensitive information through entirely legitimate-looking interactions. Darktrace has observed repeated submission of personally identifiable information (PII), tax information, identification documents, and medical data into LLM prompts, alongside widespread use of unsanctioned (shadow) AI services and growing AI activity from mobile devices.  

For defenders, the challenge is increasingly one of context: understanding when legitimate business use crosses into material risk, while preserving privacy and user trust.

Conclusion

Across all three shifts, the pattern is the same: behavior precedes understanding. Security teams are not losing because adversaries have become invisible. An increasingly outdated security model assumes that malicious activity will reveal itself cleanly and early. It no longer does.  

In 2026 and beyond, defenders win by understanding behavioral sequences, continuously validating trust, and acting before certainty becomes hindsight. That is security after signatures. That is security in the AI era.

Credit to: Daniel Levy, Threat Hunting Data Scientist

Edited by: Ryan Traill, Content Manager

References

[1] https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/careful-adoption-of-agentic-ai-services  

[2]https://www.latimes.com/business/story/2026-02-26/hacker-used-anthropics-claude-ai-to-steal-mexican-government-data

Continue reading
About the author
Nathaniel Jones
VP, Security & AI Strategy, Field CISO

Blog

/

AI

/

July 10, 2026

AIインフラがアタックサーフェスの一部に

Default blog imageDefault blog image

AIインフラとアタックサーフェスの進化

多くの組織が生成AIを実運用環境に導入するなかで、企業のクラウド環境内に新たなインフラのレイヤーが出現しています。それはAIゲートウェイです。AIゲートウェイはユーザー、アプリケーション、基盤モデルの間に位置し、多くの場合クラウドの特権アクセスを保持し、さまざまなAIサービスへのアクセスを大規模に管理しています。

AIゲートウェイとは?

AIゲートウェイはユーザー、アプリケーション、基盤モデルの間に位置し、多くの場合クラウドの特権アクセスを保持し、さまざまなAIサービスへのアクセスを大規模に管理しています。

こうした役割から、AIゲートウェイは企業のアタックサーフェスのますます重要な一部になりつつあります。AIゲートウェイが侵害されれば、攻撃者に対して計算リソースへのアクセスだけでなく、クラウドアイデンティティ、モデルサービス、機密性の高いプロンプト、そして他の接続されたシステムへのアクセスも提供してしまいます。

このブログでは、Amazon Bedrock サービスに接続されたAIゲートウェイが侵害され、その後暗号通貨マイニングインフラとの通信が観測された事例をダークトレースがどのように調査したかを解説します。問題のインスタンスは、その構成、ならびに関連するIAM(Identity and Access Management)ロールから、Amazon BedrockでホスティングされるAIサービスへのゲートウェイとして機能していることがわかりました。疑わしい侵害アクティビティが発生した後、このホストは既知の暗号通貨マイニングインフラに繰り返し通信を行い、その後シャットダウンされた様子が観測されました。Darktrace はこのアクティビティを検知し、Enhanced MonitoringおよびManaged Threat Detectionサービスを通じてエスカレーションを行いました。

この事例では最終的影響は不正な暗号通貨マイニングでしたが、このインシデントが注目に値するのはその発生場所です。侵害されたアセットは、クラウドインフラ、アイデンティティ、各種AIサービスの交差する場所に位置していました。最近の調査では、LiteLLM等のAIゲートウェイが、認証情報、モデルへのアクセス、クラウド権限を中央管理するその能力から、攻撃者にとって魅力的な標的となる可能性が明らかになっています。このアクティビティと公開されているLiteLLM脆弱性を直接結びつける証拠は見つかっていませんが、このインシデントは、AIインフラを個別のアプリケーション層として見るのではなく、重要なアタックサーフェスの一部として扱う必要性があることを表しています[1]。

暗号通貨マイニングがクラウド侵害後のアクティビティとしてよく見られる背景

暗号通貨マイニングはクラウド環境において、侵害後のアクティビティとして収益性の高いものとなり得ます。クラウド資産にアクセスできるようになった後、攻撃者はマイニングソフトウェアを展開して被害者の計算リソースを悪用し金銭的利益を得ることができます。この種のアクティビティは多くの場合機会主義的なものであり、露出したサービス、弱い認証情報、漏洩したアクセスキー、脆弱なアプリケーション、あるいはクラウドワークロードの設定ミスなどを標的として実行されます。

典型的なクラウド上での暗号通貨マイニング侵入には次のようなアクティビティが含まれます:

  • 露出したあるいは脆弱なクラウドインフラの特定
  • 露出したサービス、認証情報、またはアプリケーションの脆弱性を通じたアクセスの獲得
  • マイニングソフトウェアのダウンロードおよび実行
  • マイニングプールインフラへのアウトバウンド接続を繰り返し確立
  • アクティビティが検知され停止されるまで継続して計算リソースを消費

この事例において注目すべき要素は暗号通貨マイニングだけではありません。それが発生した場所が、AI関連アクティビティをサポートするクラウドインフラ上だったことです。この事例は、AIサービスを実現するためのアセットも、よくあるクラウド侵害リスクにさらされる可能性があることを示しています。

Amazon Bedrockに接続されたAIゲートウェイの侵害を調査

2026年6月12日、DarktraceはLiteLLM-Proxyという名前のAmazon Web Service (AWS) EC2インスタンスから暗号通貨マイニング発生中とみられるアクティビティを観測しました。このインスタンスはLiteLLMアクティビティをサポートしており、Amazon Bedrockリソースへのアクセス権を有するインスタンスプロファイルと関連付けられていました。  

AIゲートウェイは大規模言語モデルへのアクセスを中央管理するよう設計されており、多くの場合AIアプリケーションに対する認証、ルーティング、ログ、ポリシー適用を扱っています。セキュリティの視点から見ると、クラウド権限、モデルアクセス、アプリケーションワークフローを単一の制御ポイントに集約する役割も果たしています。その結果、AIゲートウェイの侵害は、侵害されたホストだけにとどまらない影響を及ぼす可能性があります。

確定的な初期アクセスベクトルは確認できませんでしたが、このアクティビティはインターネットに接続されているシステムの侵害でよく見られる次のような順序に従っていました。ブルートフォースアクセス、ペイロードの投下、そしてマイニングプールインフラに対する繰り返しのアウトバウンド接続です。

ステージ1: インターネットに露出したSSHからの初期アクセス

暗号通貨マイニングアクティビティが観測される前、LiteLLM-Proxy EC2インスタンスはSSH(ポート22)が0.0.0.0/0に対して開かれ、外部に公開されていました。

図1:EC2インスタンスがSSHポート22に対してすべてのインバウンドトラフィックを許可している設定ミスをDarktraceが警告

暗号通貨マイニングアクティビティに先立って、Darktraceはこのインスタンスに対する大量のインバウンド接続の試みが外部IPアドレス(主に145.241.123[.]102)からポート22に対して行われていることを観測しました。これはブルートフォースアクティビティを示唆するものです [2]。これらの接続の多くは短命であり、数秒しか続いておらず、スキャニングまたはログインの失敗を示していました。

図2:Darktraceがデバイスのポート22に対する不審なインバウンド接続試行を検知

入手できたテレメトリーではこれらのインバウンドSSH接続のいずれかが認証の成功につながったかどうかの確認に至らず、このアクティビティが初期アクセスベクトルであると断定することはできませんでした。しかしながら、SSHの露出、外部IPアドレスからのインバウンド接続、それに続くマイニングアクティビティは、SSHがアクセス経路の可能性が高いことを示唆しています。

ステージ2: AIゲートウェイへのXMRigマルウェアのダウンロード

最初に観測されたマイニングプールへの接続の後、このEC2インスタンスは3.42 MBのデータをポート80上のHTTP接続を介して外部エンドポイント185.62.1[.]8にダウンロードしました。このエンドポイントは暗号通貨マイニングマルウェアXMRigを含むZIPファイルをホスティングしていました[3][4]。ホストレベルのログは入手できなかったため、ダークトレースはマイニングツールがどのように実行されたか、あるいは前のSSHアクティビティがペイロード投下を直接的に可能にしたかどうかを確認できませんでした。しかしながら、ダウンロードのタイミングとその後ほどなくマイニングプールへの接続が繰り返されたことは、このインスタンスが侵害されて不正な計算アクティビティに使われたという評価を裏付けています。

ステージ3 – 侵害されたAIゲートウェイが暗号通貨マイニングインフラと通信

わずか数分後、DarktraceはLiteLLM-ProxyEC2インスタンスがHTTPs(ポート443)でホスト名pool.hasvault[.]proに対して接続していることを確認しました。最初の接続の後、同じホスト名に対して繰り返しアウトバウンド接続が観測されました。これは、侵害されたホストがマイニングインフラと通信しワークを受け取り、結果を送信するという、暗号通貨マイニングプールとの通信のパターンと一致しています。

このアクティビティがDarktraceのEnhanced Monitoringモデル“Compromise / HighPriority Crypto Currency Mining”をトリガーし、ダークトレースのSOCにより顧客に対してエスカレーションされました。また、このアクティビティはCyber AI Analystによって分析され、関連するイベントが1つの調査ナラティブにまとめられました。これにより、影響を受けたクラウドアセットからマニングプールへの繰り返しの接続を特定することができました。

図3:CyberAI Analystによる暗号通貨マイニングアクティビティの調査  

ポート443上のHTTPSの使用にも注目すべきです。なぜならば、単独で見れば、このトラフィックそのものは疑わしく見えないかもしれないからです。しかしこのケースでは、接続先、接続の量、そして類似のアクティビティが他にないことなどが、この通信を疑わしいものとして特定するのに必要な、動作のコンテキストを提供することになりました。

ステージ4: Managed Threat Detectionサービスによるリソース乱用の特定

暗号通貨マイニングアクティビティがダークトレースのManaged Threat Detectionサービスにより検知され、ダークトレースのSOCによりレビューされました。レビューの結果、このアクティビティは顧客向けにエスカレーションされました。このエスカレーションにより、顧客はAWS環境で現在発生中のリソースの乱用について、タイムリーな通知を受けることができました。

ステージ5: クラウド認証情報の不正使用とみられる疑わしいIAMアクティビティ

これとは別に、6月13日、Darktraceは別のIAMユーザーから発生した疑わしいアクティビティを検知しました。

図4: DarktraceのAdvanced Search機能が別のIAMユーザーが実行した疑わしいアクティビティをハイライト

まず、このユーザーは “GetSendQuota”イベントを試行している様子が見られました。このアクションは少なくとも過去3か月間にこのアカウントによって実行されたことのないアクションです。また、このコマンドのソースIPアドレスは14.176.1[.]47でした。地理位置情報はベトナムであり、このユーザーのアクティビティがAmazon IPアドレスから最も多く見られた場所です。さらに、このアクティビティに対してAWS CLIが使用されており、これもこのユーザーにとって通常とは異なる振る舞いでした。このことは、Darktraceの“IaaS / Unusual Activity / UnusualAWS CLI Activity”モデルによって検知されました。

図5: Darktraceによる “GetSendQuota” イベントの検知

このIAMユーザーからは、長期アクセスキーを使った疑わしいアクティビティがさらに観測されました。中でも、“InvokeModel” および “ListFoundationModels”コマンドの失敗が検知されており、モデル列挙や起動などAmazon Bedrockサービスとのやり取りを試行したことがわかります。これは前日観測されたLiteLLM侵害への関連を思わせますが、2つのイベントを確定的に結びつける証拠は不十分でした。

“CreateUser”コマンドの試行も注目に値します。なぜなら要求されたユーザー名は意味が薄いものであり、新しいアカウントを作成することにより永続性を確立する試みと見られるからです。このアクティビティはDarktraceのモデル“IaaS / Admin / New AWS UserAccount Creation”をトリガーしました。

図6:Darktraceによる“CreateUser” イベントの検知

2つのインシデント間に結びつきは確認できなかったものの、このIAMアクティビティには重要な意味があります。これは、クラウド侵害の調査においてワークロードのテレメトリーとコントロールプレーンのテレメトリーの両方を取り入れることの重要性を表しています。EC2暗号通貨マイニングアクティビティが計算リソースの乱用を示す一方、IAMアクティビティは認証情報の侵害や長期アクセスキーの不正使用、そしてクラウトサービスの不正使用の可能性を示唆しているからです。

AIインフラ保護のための重要な教訓

このインシデントの重大性は暗号通貨マイニングアクティビティそのものではなく、それが発生した場所にあります。侵害されたシステムはAmazon Bedrockサービスへのアクセス権を持つAIゲートウェイとして機能し、クラウドインフラ、アイデンティティ、そしてさまざまなAIオペレーションの交差する場所に位置していました。組織がAI機能を実運用環境に導入していくなかで、これらのプラットフォームは、露出したサービス、認証情報窃取、クラウドの設定ミスなどを通じて攻撃者がすでに狙っているアタックサーフェスの一部となりつつあるのです。

このケースでは詳細な侵入経路は特定されておらず、ワークロードの侵害と調査中に検知された疑わしいIAMアクティビティの間に決定的なつながりは確認されませんでしたが、これらのイベントは全体的な現状を裏付けています。つまり、AIインフラは個別のテクノロジースタックとして扱うのではなく、クラウド環境全体の一部として保護しなければならないとうことです。

このケースでは、最も目立った侵害の兆候は暗号通貨マイニングインフラとの通信でした。しかしここで得られたより重要な教訓は、このインシデントの全貌が理解される前にDarktraceのビヘイビア分析により明らかになった、高い権限を持つAI関連アセットを取り巻くリスクです。AIゲートウェイによりクラウド権限、モデルアクセス、アプリケーションワークフローがますます集約されるなかで、防御者は個別のアラートに集中するよりも、ワークロード、アイデンティティ、サービスの間でどのように動作がつながっているかを理解することに重点を置く必要があるでしょう。

協力:Angel Arribas Lopez (Associate Principal Cyber Analyst)、Nathaniel Jones (Field CISO/VP Threat Research)、Emma Foulger (Global Threat Ops)、Mark Turner(Security Researcher)

編集:Ryan Traill (Content Manager)

付録

Darktraceによるモデル検知結果

·       Compromise / High Priority Crypto Currency Mining

·       Compromise / Monero Mining

·       Device / Internet Facing Device with High Priority Alert

·       IaaS / Unusual Activity / Unusual AWS CLI Activity

·       IaaS / Admin / New AWS User Account Creation

MITRE ATT&CK マッピング

初期アクセス – 外部リモートサービス – T1133

初期アクセス – 有効なアカウント – T1078

実行 – コマンドおよびスクリプトインタプリタ – T1059

永続化 – アカウント作成 – T1136

探索 – クラウドサービス探索 – T1526

影響 – リソースハイジャッキング– T1496

参考資料

[1] https://docs.litellm.ai/blog/security-update-march-2026

[2] https://www.abuseipdb.com/check/145.241.123.102

[3] https://urlscan.io/search/#185.62.1.8

[4] https://www.virustotal.com/gui/file/85de36ff66fae9f4b059cbedf6d36e017ebc26c828f99f911a96e78636f21200/community

Continue reading
About the author
Angel Arribas Lopez
Associate Principal Cyber Analyst
あなたのデータ × DarktraceのAI
唯一無二のDarktrace AIで、ネットワークセキュリティを次の次元へ