Research suggests that commercial AI has been used to test industrial control systems.
The Cryptonomist
07-26 15:20
Ai Focus
Research institutions say that commercial AI has been used in real-world intrusions to identify and probe industrial control environments, demonstrating new security pressures facing critical infrastructure.
Helpful
No.Help

Security agencies Dragos and Gambit Security disclosed that during an intrusion operation that occurred between December 2025 and February 2026, attackers used Anthropic's Claude and OpenAI's GPT to launch attacks on multiple Mexican government agencies, and at one point approached the industrial control environment related to the city's water supply system.

What makes this incident unique is not the novelty of the attack method, but the direct use of commercial AI in the intrusion process. Researchers say the attackers initially lacked experience with known industrial control systems, but once the model entered the victim's IT network, it was able to automatically identify worthy industrial assets for attack and generate subsequent steps accordingly.

The attacks extended from government agencies to water supply systems.

Research shows that attackers breached multiple Mexican government agencies over several months, stealing a large amount of government and resident data. Gambit Security recovered more than 350 attack traces during the investigation, most of which were AI-generated scripts.

The investigation then narrowed its focus to a municipal water and drainage company in the Monterey metropolitan area. Dragos stated that after the initial IT intrusion at the company in January 2026, the attackers began probing the connections between the company's IT network and its operational technology environment.

Claude autonomously identifies industry-related entry points.

Researchers say Claude identified a server hosting a vNode industrial gateway and a SCADA/IIoT management platform within the victim's network as a high-value target. The model then consulted vendor documentation, compiled default passwords and password combinations relevant to the victim, and initiated automated password spraying on single-password authentication interfaces.

This attempt ultimately failed. Dragos found no evidence that the operational technology environment had been breached. However, the investigation concluded that the process itself was more noteworthy: the model, without any human guidance on industrial control expertise, crossed the identification threshold between IT and OT, a threshold typically considered to require specialized experience.

Tool development speed has accelerated significantly.

The study also mentioned that Claude wrote a Python framework of about 17,000 lines, containing 49 modules, covering functions such as network enumeration, credential collection, Active Directory query, database access, privilege escalation, cloud metadata extraction, and lateral movement automation.

Another command and control framework evolved from a basic HTTP controller into a usable C2 system within two days. Researchers believe that AI has compressed the tool development process, which might have taken days or even weeks, into hours, allowing attackers to adapt to unfamiliar environments more quickly.

Known techniques are being automated on a large scale

Dragos pointed out that the techniques used in this operation were mostly derived from publicly available attack methods and did not demonstrate any new industrial control-specific attack capabilities. The main changes were in speed, the level of automation, and the ability of the model to continuously patch and expand the tools based on real-time feedback.

This means that the traditional approach of using "novelty of tools" to judge an attacker's skill level may no longer be sufficient. Even if the attack methods themselves are not new, AI can significantly lower the barrier for attackers to identify and probe industrial-related systems, especially after they have already penetrated the enterprise IT network.

Tip
$0
Like
2
Save
1
Views 256
WalletJYS reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
After X took legal action, Nitter and XCancel ceased operations again
After X took legal action against third-party viewing services, Nitter and XCancel ceased operations again.
TechCrunch
·2026-09-16 00:21:58
6
web3: Penning Authorized by Danish MiCA to Expand Financial Management Business
Danish crypto service provider Penning reveals the scope of its MiCA authorization, cross-border passport arrangements, and the new business layout after acquiring the wealth management business of Veli.
The Cryptonomist
·2026-09-16 00:21:55
4
Ethereum: On the eve of the CLARITY Act vote, cryptocurrencies such as Bitcoin decline
Before the U.S. Senate voted on CLARITY Act, the crypto market saw a decline, with prices of Bitcoin, Ethereum, and XRP falling, and the scale of liquidations expanding.
CoinPedia
·2026-09-16 00:21:51
5
web3: U.S. Senate's Crypto Market Structure Act Stalls
The prospects for the first round of voting on the U.S. Senate's Cryptocurrency Market Structure Act are uncertain, with divisions between the two parties still unresolved.
CoinDesk
·2026-09-16 00:21:47
5
AI Search Marketing Company Profound Raises $180 Million in Financing
Profound Completes $180 Million Series D Financing, Valued at $1.8 Billion, Betting on the AI Search Marketing Track.
TechCrunch
·2026-09-15 23:55:18
15
View More