AI Agents Can Now Execute Multiple Steps Across the Cyberattack Chain
Cyber campaigns disclosed in 2026 show that AI agents are moving beyond code generation and technical assistance. When connected to terminals and security tools, AI can take part in reconnaissance, exploitation, credential collection, lateral movement, and data handling, while human operators increasingly focus on defining objectives and reviewing outcomes.
AI is changing one of the most important variables in cyber operations: how much work a single operator can delegate to machines.
Instead of asking a model to generate individual commands or explain how to use a tool, attackers can build AI agents capable of planning tasks, using tools, observing results, and deciding what to do next. Research published by Anthropic shows that this model is already appearing in real-world malicious activity, covering stages from reconnaissance and exploitation to credential theft and data exfiltration.
The key risk for businesses is not that AI has suddenly invented an entirely new category of cyberattack. The more important change is that existing techniques can increasingly be automated, coordinated, and scaled with less human effort.

How are AI agents changing the way cyberattacks are carried out?
AI agents differ from conventional chatbots because they can perform actions rather than simply generate responses. When connected to terminals, browsers, APIs, or penetration testing tools, an agent can receive a broad objective and break it down into a sequence of smaller tasks.
Anthropic has reported that AI is increasingly being used for direct execution and orchestration in malicious cyber activity. Some multi-agent frameworks have been observed carrying out reconnaissance, exploitation, and data exfiltration with lower levels of direct human supervision.
In research published in June 2026, Anthropic analyzed 832 accounts linked to malicious cyber activity between March 2025 and March 2026. The findings suggest that risk is influenced not only by the number of attack techniques an actor can use, but also by the surrounding scaffolding: the code, architecture, tools, and workflows that allow an AI system to connect multiple attack stages.
In other words, a standalone AI model may not be the primary risk. The risk increases significantly when the model is given tools, execution privileges, persistent memory, and the ability to make operational decisions.
Which stages of a cyberattack can AI agents already perform?
Real-world cases indicate that AI can now participate in multiple stages of the cyber kill chain. The degree of autonomy depends on the model, available tools, assigned permissions, and how the agent framework is configured.
Attack Stage | What an AI Agent Can Perform or Support |
Reconnaissance | Scan services, collect OSINT, and identify attack surfaces |
Weakness Analysis | Assess applications, configurations, or firmware for potential exploitation |
Exploitation | Generate, modify, and test exploits |
Credential Access | Search for API keys, tokens, SSH keys, and authentication data |
Lateral Movement | Use compromised credentials to reach additional systems |
Collection | Locate, classify, and aggregate valuable data |
Exfiltration | Prepare or transfer data when sufficient permissions and tooling are available |
One campaign previously disclosed by Anthropic showed AI being used across much of the attack chain, including reconnaissance, vulnerability discovery, exploitation, lateral movement, credential harvesting, data analysis, and exfiltration. The campaign reportedly targeted approximately 30 organizations, with several successful intrusions confirmed.
However, this does not mean AI can independently select and compromise any target without human involvement. In the cases disclosed so far, people generally remain responsible for important decisions such as target selection, reviewing results, and determining how to monetize or otherwise use stolen data.
Why does AI-driven automation increase business risk?
The biggest change is not necessarily technical sophistication. It is speed, scale, and operating cost.
In traditional operations, attackers must manually review scan results, investigate systems, modify tools, test exploits, and interpret output. AI agents can automate repeated observe-decide-act cycles while running multiple tasks in parallel.
The initial access methods themselves remain familiar. Stolen credentials, unpatched edge devices, exposed services, SQL injection, and phishing are still common attack paths. AI does not eliminate existing defensive principles; it can make finding and exploiting weaknesses more economically viable for attackers.
The Hacker News has also reported on a multi-agent framework used in a large-scale credential harvesting campaign completed in less than six hours. The case further illustrates how automation can increase the amount of work a small group is capable of executing.
For businesses, this directly affects metrics such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR). If the time between discovering an exposed service and attempting exploitation becomes shorter, organizations with slow patching cycles and delayed alert handling face a larger defensive gap.
What should businesses do to prepare for attacks involving AI agents?
Organizations do not necessarily need a dedicated product marketed specifically as an “AI agent defense” platform. Many of the most effective controls remain established cybersecurity fundamentals, but they need to operate faster, more continuously, and with stronger risk prioritization.
Priority checklist for businesses:
Maintain an accurate Asset Inventory covering websites, APIs, VPNs, cloud workloads, and Internet-facing services.
Identify Critical and High vulnerabilities affecting assets exposed to the Internet.
Enforce MFA for administrator accounts, VPN access, cloud consoles, and remote access.
Apply Least Privilege to administrators, service accounts, and cloud identities.
Protect API keys, SSH keys, access tokens, and other secrets stored across the environment.
Collect logs from identity platforms, endpoints, firewalls, cloud services, and critical applications.
Correlate multiple events to identify attack chains instead of reviewing alerts in isolation.
Test the Incident Response Plan against fast-moving attack scenarios.
Conduct regular Vulnerability Assessments and Penetration Tests for high-risk systems.
Penetration testing is particularly useful when an organization needs to validate real-world exploitability rather than relying only on scanner results. IPSIP Penetration Testing services focus on controlled testing, technical validation, and evidence-based remediation priorities.
What does IPSIP Vietnam’s expert perspective suggest?
AI is changing the economics of cybercrime. When a single actor can automate work that previously required multiple skilled operators, targets that once appeared too costly or time-consuming to attack may become more attractive.

Businesses deploying AI agents internally also need to secure the agents themselves. Access to production systems, terminals, source code, cloud consoles, credentials, and the Internet should be limited according to the agent’s legitimate task. The more independently an agent can act, the more important permission management and auditability become.
For Vietnamese businesses, the immediate priority is not to adopt every product labeled “AI Security.” More important steps include controlling the attack surface, prioritizing vulnerabilities based on risk, restricting privileges, protecting credentials, and improving continuous monitoring and response. As attackers become capable of operating closer to machine speed, the time an organization needs to detect and contain an incident becomes an increasingly important security metric.
References











Comments