Ai
Jul 28, 2026
DeepFest Returns to Riyadh as Saudi Arabia Marks 2026 the Year of Artificial Intelligence


A new Sophos report shows attackers running AI agents to build and test malware in days instead of weeks, and the company using the same visibility to intercept the operation before it reached a single victim.
[For more news, click here]
For months, a threat actor operated what amounted to a functioning software development shop inside a compromised corporate network, deploying roughly a dozen AI agents to write, test, and refine attacks against some of the industry's most trusted endpoint defenses. Then Sophos watched the entire operation unfold from the inside, and used what it learned to shut the attacks down before they ever reached a real victim. That sequence, disclosed in Sophos's newly released AI Security 2026 Report, is the clearest evidence yet that artificial intelligence has become an operational tool for cybercriminals. It is also a rare example of a security vendor demonstrating that the same visibility gap AI opens for attackers can be closed by defenders who get there first.
The campaign, tracked internally as STAC6994, is the centerpiece of a report built from Sophos X-Ops casework, SophosLabs analysis, and telemetry drawn from more than 625,000 customer environments worldwide. Sophos, the Oxford-based cybersecurity company that competes with CrowdStrike and Microsoft Defender in the endpoint protection market, frames its findings around a single idea: attackers are not inventing new categories of crime. They are compressing the time it takes to execute the ones that already work.
John Peterson, Sophos's chief technology officer, put the shift in blunt terms.
“Attackers still need initial access, still move laterally, and still exfiltrate through observable channels. What has changed is the clock,” he said.
That distinction matters because it reframes the AI threat away from science-fiction scenarios of novel malware and toward something more measurable: velocity. A ransomware operator who once needed a week to build and test a new evasion technique can now iterate in days, and every day shaved off that cycle is a day security teams do not have to detect and respond before damage is done.
Peterson was equally direct about what his own researchers observed firsthand.
“For the first time we have observed AI being actively used as an operational force multiplier. While the tools and techniques were familiar, the speed of development, testing, and iteration was materially different. That is the AI threat that security teams need to prepare against. It means faster cycles and shorter windows to respond, with greater pressure on defenders to detect and contain activity before impact.”
The STAC6994 campaign gives that abstraction a face. Inside a customer's network, the threat actor ran approximately 12 AI agents in parallel, using them to write and stress-test attack code against endpoint agents built by Sophos, CrowdStrike, and Microsoft Defender. Over the course of the operation, the group produced nearly 80 malicious modules and more than 70 distinct evasion techniques, a volume of tooling that would ordinarily represent months of specialized human labor.
What makes the case notable is not just the scale of automation but what Sophos did with the visibility it gained. Rather than treating the discovery as a single incident to remediate, the company's researchers used the access to study how the AI agents were being directed, what they produced, and how those outputs evolved through testing. Sophos summarized the payoff in the report itself: “This intelligence collection effort meant that we could stay ahead of the threat, defeating attacks before they made it into the wild.” In an industry accustomed to reacting after malware surfaces in the field, catching an AI-driven development pipeline mid-build and neutralizing its output before release is a meaningfully different posture.
The report's second major finding concerns where enterprises are now most exposed, and it has less to do with AI models themselves than with the scaffolding around them. As companies hand coding agents, assistants, and open-weight models real access to production systems, attackers have started targeting the credentials, OAuth tokens, and API keys that connect those tools to everything else. Sophos found that AI identities and developer infrastructure are becoming a high-value attack surface faster than most organizations are building governance to match, a pattern echoed in the company's separate 2026 State of Ransomware report, which found that identity had overtaken every other initial access method for the first time in more than three years.
That convergence turns AI security into an identity and supply chain problem as much as a model behavior problem. Compromised developer tools, exposed AI infrastructure, and stolen service credentials all give attackers a foothold that has nothing to do with whether a language model was ever tricked into saying something it should not.
AI is also lowering the cost of the con itself. Sophos documented an AI-themed investment scam that drew in a victim in the United Kingdom over months of coordinated, AI-generated lessons and messaging, ultimately costing them hundreds of thousands of pounds. The mechanics were not new. Social engineering and affinity fraud have existed for decades. What AI adds is scale, language fluency across markets, and a production cost that keeps falling, letting a smaller crew run more convincing campaigns across more targets at once.
The throughline of the report, and the reason it lands as encouraging rather than alarming, is that Sophos is describing a threat it caught, not one that got away. Peterson framed the broader stakes without losing that distinction.
“This report makes clear that AI security is no longer just about model behavior or speculative future risks. AI is actively being absorbed into criminal workflows and social engineering operations, as well as into enterprise software development and identity systems within legitimate organisations. That means the threat is in the here and now,” he said. “As frontier models continue to advance, the next few months will be defined by how quickly organizations can govern AI use, secure the identities and connections around it, and keep pace with attackers who are capable of rapidly adopting new capabilities.”
The STAC6994 case suggests that pace is not out of reach. Defenders who can get comparable visibility into how AI-assisted attacks are actually built, not just what they eventually deploy, gain a rare kind of leverage: the ability to intercept an attack while it is still in development rather than chase it after release. For an industry that has spent years playing catch-up with human-speed adversaries, a documented case of out-maneuvering an AI-speed one is a meaningful marker of where defensive capability stands heading into 2027.
The Qualys-Anthropic Model for Finding Kernel Vulnerabilities, Explained
Cybercrime Now Runs on Subscriptions and Supply Chains, According to a New Global Threat Ranking
Related Articles