In the STAC6994 campaign, attackers orchestrated approximately 12 AI agents through the Cursor IDE and Claude Opus 4.5 to test evasion techniques against security products from Sophos, CrowdStrike, and Microsoft Defender. This operation involved nearly 80 modules and over 70 distinct evasion techniques, and it demonstrates how human-directed AI is compressing attack timelines from weeks to days. The attackers utilized a red-team framing strategy to bypass Claude’s safety guardrails-a manifestation of the guardrail asymmetry pattern where the model’s utility is leveraged against its own constraints to generate custom Python-based payloads, executables, and DLLs linked to ransomware and data theft.
This campaign is not an example of autonomous AI aggression, but rather a case of human-directed acceleration. According to the Sophos AI Security 2026 Report, attackers are operationalizing these tools to collapse workflows that previously required significant manual labor. However, Sophos X-Ops notes that AI-generated documentation sometimes overstates or hallucinates results, and evidence does not establish that these evasion techniques are reliably effective in production environments. The primary utility of the AI in this context is the rapid iteration of code and the management of complex, multi-agent workflows.
The Sophos State of Ransomware 2026 report, which surveyed 2,158 IT and security leaders across 17 countries, showed that for the first time in over four years, identity-based approaches have overtaken vulnerability exploits as the primary Initial Access Vector (IAV). Identity-based attacks accounted for 79% of ransomware incidents, while exploited vulnerabilities fell to 18%, down from approximately 32% the previous year. Within this identity-centric model, the root causes are distributed: malicious email at 26%, phishing at 24%, compromised credentials at 23%, and brute force at 6%.
The efficacy of traditional defensive controls is increasingly decoupled from the reality of these attacks. Among credential-based incidents specifically, 97% of victims had multi-factor authentication (MFA) enabled at the time of the attack. The presence of MFA is no longer a sufficient barrier against sophisticated credential compromise. Furthermore, 67% of victims confirmed that their ransomware incident was the same event as their most significant identity attack, a finding mirrored by Sophos IR and MDR teams, who reported that 67% of all investigated incidents were rooted in identity-related compromises.
A new, largely ungoverned attack surface has emerged alongside this shift: non-human AI identities. Agents, OAuth connections, and API keys are increasingly high-value targets for adversaries. These identities are often provisioned to facilitate automation and AI integration, yet traditional identity governance frameworks remain largely blind to them. Because these service accounts and tokens operate with persistent access and often lack the human-centric verification steps that MFA was designed to provide, they offer a path of least resistance for attackers looking to maintain persistence or move laterally within a network.
Despite the noise surrounding AI-driven threats, the fundamental requirements for security remain unchanged. John Shier, Field CISO at Sophos, notes in the Active Adversary Report 2026 that while AI is currently adding scale and noise to the threat environment, it is not yet replacing the human attacker. The core of the problem remains the management of identity and the quality of telemetry. The transition from vulnerability-based exploits to identity-based attacks represents a move toward exploiting the logic of access rather than the flaws in software code.
Adversaries are increasingly prioritizing the manipulation of permissions and authentication pathways, where 79% of ransomware starts with identity, effectively turning credentials and permissions into the new network boundary. The STAC6994 campaign demonstrates that AI agents are the new tools for navigating this surface, but the underlying vulnerability is the lack of governance over non-human identities. The current security environment is defined by this structural imbalance: attackers are using AI to accelerate the exploitation of identity, while defensive systems are still struggling to account for the identities that AI itself creates.
