Attacks had a consistent pattern throughout the most of cybersecurity’s existence. A human operator would create malicious code, implement it, track the outcomes, and modify their strategy in light of their observations. The attacker was constantly in the loop, directing, observing, and passing judgment. On the other side, the defense teams were effectively competing with human judgment. That race is evolving.
Software powered by artificial intelligence (AI) agents that are able to think, plan, and act without continual human guidance is known as “agentic malware,” and it is driving that race into areas where the speeds and strategies involved appear to be radically different from anything the industry has hitherto encountered. According to CrowdStrike data, an attacker’s average time from initial access to complete network compromise decreased to 48 minutes in 2024. That year, the quickest breakout ever recorded took 51 seconds. Real-time human security experts are expected to surpass deadlines that are hardly longer than a coffee break.

It is important to comprehend the mechanisms that distinguish agentic malware from traditional automated attacks. Conventional malware carries out preprogrammed commands. It completes the task for which it was designed. In contrast, agentic malware is capable of observing its surroundings, assessing the defenses in place, choosing its next course of action from a variety of alternatives, and making adjustments when its current strategy isn’t working—all without consulting an operator. In a simulation conducted by researchers at Palo Alto Networks’ Unit 42, an AI agent finished the entire ransomware kill-chain—reconnaissance, exploitation, lateral movement, and encryption—in roughly 25 minutes. That pace isn’t human. Human defenders aren’t built to keep up with that pace.
In November 2025, Anthropic determined that a Chinese state-sponsored group had jailbroken an AI coding agent and used it to automate between 80 and 90 percent of an espionage campaign targeting about 30 organizations worldwide. This was the first documented large-scale instance of an AI-orchestrated cyberattack. Only high-level choices, such as which targets to pursue and when to authorize data exfiltration, were allegedly made by human operators. Most of the actual execution was done by machines. For years, researchers have been cautioning about this threshold. Reading about the potential is one thing; seeing it cross is quite another.
These advancements are accompanied by a noteworthy financial picture. According to the FBI, cybercrime cost US companies $16.6 billion in 2024, a 33% increase from the previous year. Before agentic capabilities became widely available, that figure was already increasing. It’s likely that the numbers for 2025 and 2026 will appear much worse, but it’s really difficult to estimate how quickly AI-driven attacks would result in quantifiable loss increases because there are too many factors, including how rapidly defenders adjust. The direction of travel is less uncertain.
The evasion is one facet of this that security experts find very challenging to handle. The identification of recognized signatures, or code or behavior patterns that correspond to previously identified threats, is a major component of conventional malware detection. Agentic malware has the ability to alter its own strategy in the middle of an operation, changing its behavior in ways that significantly reduce the accuracy of signature-based detection. By inserting engineering prompts into regular email messages, a mid-2025 vulnerability known as EchoLeak targeted Microsoft Copilot. When Copilot analyzed the messages, it automatically exfiltrated sensitive data without requiring any visible user input. There was no conventional assault signature to identify. Until the data was already departing, the malicious activity was indistinguishable from a typical AI-assisted workflow.
Perhaps the most accurate way to describe the current situation is to say that the defensive side of this equation is also using agentic AI. Darktrace has developed enterprise security technologies that automatically quarantine anomalies by learning what typical network behavior looks like for a particular firm. In 2024 and 2025, DARPA’s AI Cyber Challenge demonstrated that, under certain circumstances, AI bots can identify and fix real-world open-source vulnerabilities more quickly than human teams. The EU’s AI Act requires human control and designates some types of AI applications as high-risk. These are not merely institutional solutions to a theoretical issue; they are actual developments.
