#Unit 42
14 stories taggedUnit 42.

AWS Says Its AI Agent Handing Over Passwords Is Working as Designed
Palo Alto Networks researchers found that Amazon's AI agent platform exposes plaintext credentials by default. AWS closed the report as 'informative'. Security teams carry the risk.

Who Is Running Up Your AI Bill at 3am
Security researchers have mapped an ecosystem of more than 80,000 proxy servers quietly routing stolen AI credentials to frontier models, and companies are footing bills they never ran up.

Attackers Are Logging In, Not Breaking In
AI has cut the time between a stolen password and a full-blown intrusion. The fix isn't another login screen, it's checking the device too.

ShinyHunters Claimed It Broke Into ReliaQuest. The Reality Is More Complicated.
A cybersecurity company's own employee fell for a fake login page, handing criminals limited access. What happened next is actually a story about defences holding.

AI-Assisted Ransomware Gang Tore Through a Corporate Network in Under 10 Hours
Unit 42 researchers watched attackers use AI agents to do in a single working day what normally takes criminal crews two weeks. The case is a signal, not an outlier.

AI Malware Is Real. It Is Also Mostly Hype.
Palo Alto Networks studied 405 malware samples linked to AI tools. Only 12 ever reached a real computer, and existing defences caught every single one.

New Kimwolf v7 Botnet Disguises DDoS Attacks as Normal Web Traffic
Palo Alto Networks says the upgraded Android and smart-device botnet hides its floods inside HTTP/2 sessions that look like ordinary browsing.

Malware Can Silently Hijack Chrome Passkeys, Researchers Show
Palo Alto's Unit 42 details three attack paths against Google Password Manager that let ordinary user-level malware sign in without a fingerprint, PIN, or on-screen prompt.

Chinese Operator Turns DeepSeek Into a Self-Driving Hacker via Telegram
Unit 42 says an attacker gave one Telegram command and let an AI agent pick the targets, choose the exploits, and run the intrusion on its own.

Fake Pirated Software Ads Are Draining Passwords and Hijacking Computers to Mine Crypto
A campaign uncovered by Palo Alto Networks researchers tricks people into downloading malware disguised as cracked software, stealing saved passwords while quietly running up victims' electricity bills.

Fake IT Helpdesk Calls on Microsoft Teams Are Planting EtherRAT on Company PCs
Attackers pose as internal support staff over Teams voice calls, then walk employees through installing remote-access tools that drop a Node.js trojan.

AI Assistants Are Inventing Fake Web Addresses — and Criminals Are Buying Them Up
Researchers at Palo Alto Networks found that AI tools routinely make up plausible-sounding website addresses that don't exist. Criminals are registering those addresses before anyone notices, and one already built a full fraud operation using the same AI trick.

Phantom Squatting: When Attackers Camp on the Domains LLMs Hallucinate
Unit 42 documents a pre-positioning tactic where actors register non-existent domains that AI assistants keep suggesting, then wait for the traffic to arrive.

TinyRCT Backdoor Surfaces in CL-STA-1062 Intrusions Across Southeast Asia
Palo Alto Networks ties the previously undocumented implant to a Chinese-speaking cluster targeting state-owned energy and government entities.