Artificial intelligence has moved from a curiosity in the threat landscape to a working part of the intrusion, and agentic adversaries have infiltrated extortion campaigns, espionage operations and hacktivist activity alike. The speed of the tooling, more than any novel attack technique, is what leaves defenders far less time to respond.
That shift is measurable, not theoretical. Security teams that spent last year debating whether attackers would adopt AI are now watching them run entire operations with it, according to Adam Meyers (pictured), senior vice president of intelligence at CrowdStrike Holdings Inc.
“The stat that’s most interesting is we had something like 26 agentic adversaries that we were tracking in the last 30 days. That’s more than we were tracking in the year before that,” Meyers said. “REVENANT SPIDER is a group that we were tracking that was using an agent in the intrusion. AI agents are now part of ransomware operations.”
Meyers spoke with theCUBE’s Dave Vellante and Rebecca Knight at Fal.Con, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed agentic adversaries, intrusion speed and the Sality botnet takedown. (* Disclosure below.)
Agentic adversaries compress the intrusion timeline
Speed is the defining characteristic. CrowdStrike’s threat hunting research already found that exploitation windows are shrinking as AI works its way into adversary operations, and agent-driven intrusions are pushing that further still.
“In 58 minutes, VAULT PANDA had conducted 1,100 commands. It was an agent that was doing it, and we were watching it learn in real time,” Meyers said. “When I talk about breakout time from our global threat report, we were talking this year about 29 minutes on average, 27 seconds was the fastest. I’m talking about an entire intrusion operation conducted in minutes from start to finish.”
Defenders are pushing back with collective action. CrowdStrike worked with law enforcement on the Sality botnet disruption, an effort a decade in the making against a network that had run for 23 years, Meyers noted.
“Bluntly, we do need to bring the fight to the bad guys. I think we need to raise the cost of doing business for them,” Meyers said. “We need to do it in a responsible way”.
Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of Fal.Con:
(* Disclosure: TheCUBE is a paid media partner for the Fal.Con event. Neither CrowdStrike, the sponsor of theCUBE’s event coverage, nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)





