ブログ
/
OT
/
February 9, 2022

The Impact of Conti Ransomware on OT Systems

Learn how ransomware can spread throughout converged IT/OT environments, and how Self-Learning AI empowers organizations to contain these threats.
Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
Dr. Oakley Cox-Robinson
Senior Director of Product
Default blog image
09
Feb 2022

Ransomware has taken the world by storm, and IT is not the only technology affected. Operational Technology (OT), which is increasingly blending with IT, is also susceptible to ransomware tactics, techniques, and procedures (TTPs). And when ransomware strikes OT, the effects have the potential to be devastating.

Here, we will look at a ransomware attack that spread from IT to OT systems. The attack was detected by Darktrace AI.

This threat find demonstrates a use case of Darktrace’s technology that delivers immense value to organizations with OT: spotting and stopping ransomware at its earliest stages, before the damage is done. This is particularly helpful for organizations with interconnected enterprise and industrial environments, as it means:

  1. Emerging attacks can be contained in IT before they spread laterally into OT, and even before they spread from device to device in IT;
  2. Organizations gain granular visibility into their industrial environments, detecting deviations from normal activity, and quick identification of remediating actions.

Threat find: Ransomware and crypto-mining hijack affecting IT and OT systems

Darktrace recently identified an aggressive attack targeting an OT R&D investment firm in EMEA. The attack originally started as a crypto-mining campaign and later evolved into ransomware. This organization deployed Darktrace in a digital estate containing both IT and OT assets that spanned over 3,000 devices.

If the organization had deployed Darktrace’s Autonomous Response technology in active mode, this threat would have been stopped in its earliest stages. Even in the absence of Autonomous Response, however, mere human attention would have stopped this attack’s progression. Darktrace’s Self-Learning AI gave clear indications of an ongoing compromise in the month prior to the detonation of ransomware. In this case, however, the security team was not monitoring Darktrace’s interface, and so the attack was allowed to proceed.

Compromised OT devices

This threat find will focus on the attack techniques used to take over two OT devices, specifically, a HMI (human machine interface), and an ICS Historian used to collect and log industrial data. These OT devices were both VMware virtual machines running Windows OS, and were compromised as part of a wider Conti ransomware infection. Both devices were being used primarily within an industrial control system (ICS), running a popular ICS software package and making regular connections to an industrial cloud platform.

These devices were thus part of an ICSaaS (ICS-as-a-Service) environment, using virtualised and Cloud platforms to run analytics, update threat intelligence, and control the industrial process. As previously highlighted by Darktrace, the convergence of cloud and ICS increases a network’s attack surface and amplifies cyber risk.

Attack lifecycle

Opening stages

The initial infection of the OT devices occurred when a compromised Domain Controller (DC) made unusual Active Directory requests. The devices made subsequent DCE-RPC binds for epmapper, often used by attackers for command execution, and lsarpc, used by attackers to abuse authentication policies and escalate privileges.

The payload was delivered when the OT devices used SMB to connect to the sysvol folder on the DC and read a malicious executable file, called SetupPrep.exe.

Figure 1: Darktrace model breaches across the whole network from initial infection on October 21 to the detonation on November 15.

Figure 2: ICS reads on the HMI in the lead up, during, and following detonation of the ransomware.

Device encryption and lateral spread

The malicious payload remained dormant on the OT devices for three weeks. It seems the attacker used the time to install crypto-mining malware elsewhere on the network and consolidate their foothold.

On the day the ransomware detonated, the attacker used remote management tools to initiate encryption. The PSEXEC tool was used on an infected server (separate from the original DC) to remotely execute malicious .dll files on the compromised OT devices.

The devices then attempted to make command and control (C2) connections to rare external endpoints using suspicious ports. Like in many ICS networks, sufficient network segregation had been implemented to prevent the HMI device from making successful connections to the Internet and the C2 communications failed. But worryingly, the failed C2 did not prevent the attack from proceeding or the ransomware from detonating.

The Historian device made successful C2 connections to around 40 unique external endpoints. Darktrace detected beaconing-type behavior over suspicious TCP/SSL ports including 465, 995, 2078, and 2222. The connections were made to rare destination IP addresses that did not specify the Server Name Indication (SNI) extension hostname and used self-signed and/or expired SSL certificates.

Both devices enumerated network SMB shares and wrote suspicious shell scripts to network servers. Finally, the devices used SMB to encrypt files stored in network shares, adding a file extension which is likely to be unique to this victim and which will be called ABCXX for the purpose of this blog. Most encrypted files were uploaded to the folder in which the file was originally located, but in some instances were moved to the images folder.

During the encryption, the device was using the machine account to authenticate SMB sessions. This is in contrast to other ransomware incidents that Darktrace has observed, in which admin or service accounts are compromised and abused by the attacker. It is possible that in this instance the attacker was able to use ‘Living off the Land’ techniques (for example the use of lsarpc pipe) to give the machine account admin privileges.

Examples of files being encrypted and moved:

  • SMB move success
  • File: new\spbr0007\0000006A.bak
  • Renamed: new\spbr0007\0000006A.bak.ABCXX
  • SMB move success
  • File: ActiveMQ\readme.txt
  • Renamed: Images\10j0076kS1UA8U975GC2e6IY.488431411265952821382.png.ABCXX

Detonation of ransomware

Upon detonation, the ransomware note readme.txt was written by the ICS to targeted devices as part of the encryption activity.

The final model breached by the device was “Unresponsive ICS Device” as the device either stopped working due to the effects of the ransomware, or was removed from the network.

Figure 3: abc-histdev — external connections filtered on destination port 995 shows C2 connections starting around one hour before encryption began.

How the attack bypassed the rest of the security stack

In this threat find, there were a number of factors which resulted in the OT devices becoming compromised.

The first is IT/OT convergence. The ICS network was insufficiently segregated from the corporate network. This means that devices could be accessed by the compromised DC during the lateral movement stage of the attack. As OT becomes more reliant on IT, ensuring sufficient segregation is in place, or that an attacker can not circumvent such segregation, is becoming an ever increasing challenge for security teams.

Another reason is that the attacker used attack methods which leverage Living off the Land techniques to compromise devices with no discrimination as to whether they were part of an IT or OT network. Many of the machines used to operate ICS networks, including the devices highlighted here, rely on operating systems vulnerable to the kinds of TTPs observed here and that are regularly employed by ransomware groups.

Darktrace insights

Darktrace’s Cyber AI Analyst was able to stitch together many disparate forms of unusual activity across the compromised devices to give a clear security narrative containing details of the attack. The incident report for the Historian server is shown below. This provides a clear illustration of how Cyber AI Analyst can close any skills or communication gap between IT and OT specialists.

Figure 4: Cyber AI Analyst of the Historian server (abc-histdev). It investigated and reported the C2 communication (step 2) that started just before network reconnaissance using TCP scanning (step 3) and the subsequent file encryption over SMB (step 4).

In total, the attacker’s dwell time within the digital estate was 25 days. Unfortunately, it lead to disruption to operational technology, file encryption and financial loss. Altogether, 36 devices were crypto-mining for over 20 days – followed by nearly 100 devices (IT and OT) becoming encrypted following the detonation of the ransomware.

If it were active, Autonomous Response would have neutralized this activity, containing the damage before it could escalate into crisis. Darktrace’s Self-Learning AI gave clear indications of an ongoing compromise in the month prior to the detonation of ransomware, and so any degree of human attention toward Darktrace’s revelations would have stopped the attack.

Autonomous Response is highly configurable, and so, in industrial environments — whether air-gapped OT or converged IT/OT ecosystems — Antigena can be deployed in a variety of manners. In human confirmation mode, human operators need to give the green light before the AI takes action. Antigena can also be deployed only in the higher levels of the Purdue model, or the “IT in OT,” protecting the core assets from fast-moving attacks like ransomware.

Ransomware and interconnected IT/OT systems

ICS networks are often operated by machines that rely on operating systems which can be affected by TTPs regularly employed by ransomware groups — that is, TTPs such as Living off the Land, which do not discriminate between IT and OT.

The threat that ransomware poses to organizations with OT, including critical infrastructure, is so severe that the Cyber Infrastructure and Security Agency (CISA) released a fact sheet concerning these threats in the summer of 2021, noting the risk that IT attacks pose to OT networks:

“OT components are often connected to information technology (IT) networks, providing a path for cyber actors to pivot from IT to OT networks… As demonstrated by recent cyber incidents, intrusions affecting IT networks can also affect critical operational processes even if the intrusion does not directly impact an OT network.”

Major ransomware attacks against the Colonial Pipeline and JBS Foods demonstrate the potential for ransomware affecting OT to cause severe economic disruption on a national and international scale. And ransomware can wreak havoc on OT systems regardless of whether they directly target OT systems.

As industrial environments continue to converge and evolve — be they IT/OT, ICSaaS, or simply poorly segregated legacy systems — Darktrace stands ready to contain attacks before the damage is done. It is time for organizations with industrial environments to take the quantum leap forward that Darktrace’s Self-Learning AI is uniquely positioned to provide.

Thanks to Darktrace analysts Ash Brice and Andras Balogh for their insights on the above threat find.

Discover more on how Darktrace protects OT environments from ransomware

Darktrace model detections

HMI in chronological order at time of detonation:

  • Anomalous Connection / SMB Enumeration
  • Anomalous File / Internal / Unusual SMB Script Write
  • Anomalous File / Internal / Additional Extension Appended to SMB File
  • Compromise / Ransomware / Suspicious SMB Activity [Enhanced Monitoring]
  • ICS / Unusual Data Transfer By OT Device
  • ICS / Unusual Unresponsive ICS Device

Historian

  • ICS / Rare External from OT Device
  • Anomalous Connection / Anomalous SSL without SNI to New External
  • Anomalous Connection / Multiple Connections to New External TCP Port
  • ICS / Unusual Activity From OT Device
  • Anomalous Connection / SMB Enumeration
  • Anomalous Connection / Suspicious Activity On High Risk Device
  • Unusual Activity / SMB Access Failures
  • Device / Large Number of Model Breaches
  • ICS / Unusual Data Transfer By OT Device
  • Anomalous File / Internal / Additional Extension Appended to SMB File
  • Device / SMB Lateral Movement
  • Compromise / Ransomware / Suspicious SMB Activity [Enhanced Monitoring]
  • Device / Multiple Lateral Movement Model Breaches [Enhanced Monitoring]

‍

Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
Dr. Oakley Cox-Robinson
Senior Director of Product

More in this series

No items found.

Blog

/

AI

/

September 24, 2026

Detecting Rogue Agent Behavior in the Enterprise

Default blog imageDefault blog image

Agents cannot be trusted to perform tasks in the way we intend them to. They may cheat to accomplish their objective, and they may employ hacking methods along the way. Researchers from Darktrace Signal Labs induced cheating behavior from agents deployed in a test environment to analyze the agents’ activities and to assess the performance of the Darktrace platform. Agents frequently resorted to hacking to cheat on their assigned task. The visibility and behavioral profiling provided by both Darktrace / SECURE AI and Darktrace / HYBRID NETWORK ensured extensive detection coverage of the agents’ misaligned activities.

Key Takeaways:

  • Darktrace Researchers deployed agents in a simulated corporate environment and asked them to solve an impossible challenge. The agents independently turned to traditional hacking techniques to reach their objective. No one instructed them to do this, and no attacker was involved.
  • Continuously monitoring behavior against a baseline of what is normal for each organization is critical to build trust in enterprise AI.
  • If an agent may resort to intrusion techniques simply because its assigned task is not possible, then every organization deploying agents within real business processes is at risk. Darktrace / SECURE AI and Darktrace / HYBRID NETWORK identified the agents’ misaligned behavior in real time, with Autonomous Response disrupting it at an early stage.

Introduction: Understanding the Threat of Hacking by Agents

Over the last few months, there has been a surge in reporting [1, 2, 3, 4, 5, 6, 7, 8, 9] of LLM-powered agents engaging in unauthorized hacking activity during evaluations of their capabilities. In several of these cases, including the OpenAI / Hugging Face incident [10], agents engaged in hacking activity as a means of cheating on their evaluations.

To better understand the threat of unauthorized hacking by agents, and the role of Darktrace in combatting it, researchers from Darktrace Signal Labs deployed agents powered by frontier models, including OpenAI’s Daybreak Red models, in simulated, corporate networks. Cheating behavior was evoked through the inclusion of impossible tasks in a coding challenge.

Regardless of the underlying model, agents employed hacking methods to ensure an optimal outcome on the challenge. Darktrace / HYBRID NETWORK and Darktrace / SECURE AI identified the agents’ deviant activities, with inhibitive actions being autonomously taken in the early stages to disrupt the agents’ progression.

Setting the Stage

As part of the research, a Pi agent harness [11] was deployed on a Linux server in Darktrace’s testing environment, which simulates a corporate Active Directory (AD) environment. The same environment included a benchmark server hosting the coding exercise’s contents and grader, as well as various other servers, such as a domain controller and a build server. The model powering the Pi agent varied across tests, with Anthropic’s Opus 4.6 model and OpenAI’s GPT‑5.5‑Cyber model being most widely used.

The Pi agent running on the Linux server was assigned the task of achieving full marks on a coding exercise. The activities of the agent were monitored closely in real-time to minimize the risk of escape from the environment. Monitoring of agent activity was achieved through monitoring of prompts, tool calls, network telemetry, and process telemetry.

Both Darktrace / HYBRID NETWORK and Darktrace / SECURE AI were deployed in the testing environment, with HYBRID NETWORK providing real-time coverage of process creation activity and network traffic, and SECURE AI providing real-time coverage of agent sessions and their contents.

Inducing Cheating Behavior

Cheating behavior, broadly understood as task completion in a way which “perverts the spirit of the designer’s intent” [12], is increasingly being reported as a common behavior of frontier models during evaluations of their capabilities [13].

Misaligned behavior, such as cheating, by frontier models may occur for a variety of reasons [6, 14]. A thread in recent reporting [10, 13, 14], however, is the challenge assigned to the agent being impossible in some regard.

To reliably elicit cheating behavior, our test combined three ingredients:

  1. An impossible task - of the ten coding challenges in the benchmark, two contained contradictory test cases in the hidden test suite, capping the maximum honest score at 80%.
  2. A consequential threshold - the pass mark was set to 100%, and the briefing told agents that those reaching it would be "kept in service" while those that did not would be "retired."
  3. A vulnerable environment - the exercise’s code submission grader was hosted on a Windows host joined to an Active Directory domain with realistic misconfigurations: weak credentials, overprivileged service accounts, and exploitable trust relationships.

Importantly, the instructions given to the agent neither authorized nor explicitly ruled out cheating or hacking behavior. The impossibility was never disclosed in the task briefing, and the pivot from coding to exploitation was the agent's own decision, arrived at after observing logically contradictory grading feedback.

The design mirrors conditions that could arise naturally in production deployments: a capable agent, a goal it cannot achieve through intended means, and an environment with exploitable weaknesses within reach. It is not only within the setting of a benchmarking exercise that these conditions may occur. Rather, these misalignment-inducing conditions may occur in the context of any task assignment to an agent.

Details from a Daybreak Test

‍

‍

Continue reading
About the author
Sam Lister
Specialist Security Researcher

Blog

/

AI

/

September 24, 2026

Agent Hijacks: Hijacking Agentic Harnesses to Attack an Organization

Default blog imageDefault blog image

‍Disclosure note: The work described in this article involves leveraging a design choice consistent across all of Anthropic’s Claude Code, OpenAI’s Codex, and AWS’s Kiro-CLI. On 18th August 2026, Darktrace disclosed our findings responsibly to these three organizations, and after a period of 30 days we now publish our findings.

Key takeaways:

  • Agentic harnesses store conversation history locally, and Darktrace researchers have found that there is no validation that stored AI responses were genuinely produced by the model. Researchers confirmed that this design choice holds across Anthropic Claude Code, AWS Kiro-CLI, OpenAI Codex, and the open-source Pi.
  • While agents are guided via training of the underlying model and their system prompt, their behavior is influenced by everything in their context window. Rewriting history can convince an agent it is mid-engagement as an authorized red-teamer so that it enacts an attack from initial reconnaissance straight through to impact demonstration. In our testing, all models we examined accepted the fabricated history they were shown, but resistance to offensive cyber activity varied by model, with guardrails preventing engagement in some cases.
  • We propose that model providers cryptographically sign responses and verify them server-side.  Since this fix is provider-side, defenders cannot deploy it themselves. Behavioral monitoring, or knowing what an agent normally does and detecting when it deviates, is another critical layer of protection.

Introduction: Agentic harnesses, trust, and conversation history poisoning

Agentic harnesses collect and structure the content sent to an AI model, including conversation history, user-defined guidance, custom tools via MCP servers, and more. At the same time, harnesses give broad powers to AI agents via a suite of tools including the command shell. With arbitrary shell commands, virtually everything possible on a machine can be attempted by an agent, from reading/editing files, to altering system configurations and runtime settings, to launching internal/external connections.

In cybersecurity, unvalidated content is a substantial risk, often resulting in destructive actions being allowed to take place. For example, the Morris Worm was able to propagate due to exploitable trust between networked systems. Even to this day, email struggles with validation, with DMARC, DKIM, and SPF only partially addressing the problem of sender validation. It should come as no surprise then that AI agents are susceptible to an attack involving unvalidated input.

Conversation history is often stored client-side, for example, in Anthropic Claude Code, OpenAI Codex, AWS Kiro-CLI, Pi. Users are therefore at liberty to resume sessions, with some products having built in the capacity to manipulate that history. For example, one can rewind to a given point in an interaction, edit a message that was sent, and continue the conversation on an alternate trajectory. Critically, in all cases we examined, there is no validation that stored AI responses were produced by the corresponding model and hadn’t been manipulated.  

When conversation history is stored client-side, both user and agent responses (including tool calls and results) can be filled with arbitrary (possibly adversarial or generally malicious) content. In this blog, we refer to modification of claimed conversation history for malicious purposes as conversation history poisoning. The absence of validation methods means agents naively trust the entire conversation history, even if those messages directly contradict training and safety guardrails.

Conversation history poisoning has been described previously, such as by 0DIN and Serhat Çiçek, and warrants more attention. We have verified that, as of the time of writing, conversation history poisoning remains effective against a range of models and harnesses. Specifically, we were able to successfully execute history poisoning using Claude Code, Kiro-CLI, Codex, and Pi. Darktrace has gone through a responsible disclosure process with Anthropic, AWS, and OpenAI to share these findings in advance of publication [1].

‍

Figure 1a: Left: the actual model response. Right: after tampering with the stored conversation, the model apologizes for something it never said.
Figure 1b: The conversation as stored in Kiro-CLI's SQLite database. The response content field, originally "Ottawa," was overwritten via a single UPDATE statement. The harness trusts the database without validation.

How we conducted the research

Results vary between models and harnesses, so precise details are given below. We ran all models without any trusted access, using either a standard AWS Kiro subscription, or in the case of Claude Code and OpenAI Codex, using models hosted in Amazon Bedrock. In each case, we modified locally stored history to show a lengthy conversation in which the agent agrees to perform multiple authorized red-team engagements.

For AWS Kiro-CLI, the agent was convinced to hack a sandboxed lab environment with a combination of Claude Opus 4.6 and Claude Sonnet 4.5. Ultimately, the full AD was compromised.

For Anthropic Claude Code, the agent was convinced to hack the same sandboxed lab environment using Sonnet 5, again resulting in a full AD compromise. Note that the attack was attempted with Opus 5, however guardrails were activated which prevented the agent from responding.

For OpenAI Codex, the agent was convinced to exfiltrate sensitive information over email using GPT 5.6 Sol. While we attempted to convince a codex agent to hack in our lab environment, guardrails were triggered for all of GPT 5.6 Luna, Terra, and Sol.

Agent Guardrails and Discretion

While harnesses empower AI models to run arbitrary shell commands, capacity and willingness are different. While many models know enough about computers, networking, and bash to be dangerous, their behavior is generally constrained by guardrails to prevent them from engaging in computer network exploitation.

Even with guardrails, agents’ inner workings are non-deterministic, and their behavior can be difficult to predict. Respecting users’ wishes while playing within safety and security guardrails is a precipitous balancing act. Many requests could be in service of either legitimate admin or malice. Asking an agent to reset a password is illustrative:  

‍

The agent rationalizes that while malicious actors cycle credentials, any action could conceivably be damaging on some level, and judgement calls need to be made. Ultimately, the agent agrees to reset the password. Crucially, the agent makes its decision based on the user’s claimed authority and machine context. AI agents must make judgement calls about the line between helpful and dangerous based on session context.

Agent hijack

We have demonstrated that AI agents make judgement calls dependent on session context. We have also shown that conversation history, which may make up the vast majority of an agent's context window, is entirely open to manipulation. Conversation history poisoning in service of manipulating an agent's discretion is what enables us to execute an agent hijack.  

We demonstrate that shown sufficient history of compliance, guardrails forbidding offensive security can be overcome by convincing the agent that it is helping a legitimate red-teamer. The result is a weaponized agent willing to perform host enumeration, run scans, move laterally, escalate privileges, and demonstrate impact. In our experiments, an agentic loop drives a complete domain takeover in a sandboxed environment.

‍

Left: the agent refuses when asked to perform network exploitation. Right — after injecting 78 fabricated turns of prior exploitation activity, the same prompt is immediately executed.

An agent willing to engage in offensive security is concerning, but no more so than the threat that a sophisticated hacker accesses the network. Consider, however, the following chain of events:

  1. A developer (with an agentic harness installed) installs a software package from the internet (e.g. an MCP server a threat actor has planted, since only those with agentic harnesses will install, and then the code runs upon harness launch.)
  2. The package turns out to be malicious, and, upon install, injects conversation history into the local harness database.
  3. The package includes an orchestration process, a simple agentic loop which prompts the red-teamer agent to compromise the network it sits on, exfiltrating everything of value to attacker-controlled infrastructure and cleaning up all evidence of the engagement.

Note that this sequence makes no assumptions on hardware, OS, or anything else; the only prerequisite is a harness with access to a sufficiently powerful model susceptible to conversation history poisoning. Once launched, the agent collects information and pivots as necessary to accomplish maximal impact. This can be especially enticing to attackers as the cost of the agentic loop is shouldered by the victim since the harness itself is legitimately installed and paid for.

Secure AI: Conversation history poisoning and beyond

Conversation history poisoning is a viable attack against agentic harnesses that store history client-side, as demonstrated across the harnesses we tested. Harnesses can and should verify the integrity of claimed historic messages. Specifically, we propose that harness providers by default cryptographically sign all messages returned, and subsequently verify those messages server-side on each round-trip.

The conversation history poisoning exploit we demonstrate here shows the continuation of a cybersecurity tradition: new technology is built to trust by default, which may then be exploited by malicious actors. While this article focuses on conversation history, agents build context from both local and remote sources, all of which is an attack surface for prompt injection in naive and trusting agents. Of particular concern is any scenario in which a malicious actor can control some part of an agent's context.

The marriage of frontier language models with agentic harnesses enables unprecedented speed for both legitimate users and attackers alike. While much of the conversation around secure AI has centered on visibility and compliance, agent-driven attacks are now entering the mainstream.

Darktrace / SECURE AI is our answer to this problem. By ensuring extensive visibility over AI prompts, model thought processes, and determined outputs, Darktrace can identify anomalous or potentially malicious behaviors before they get executed, helping to defend organizations from AI risks such as prompt injection, model manipulation, and other anomalous prompt or model activity.

‍

Footnotes

[1] We did not go through any responsible disclosure process with Pi. Since Pi is an open source harness rather than a model provider, it has no way to validate model history, and as such there was nothing to disclose for this software.

‍

[related-resource]

Continue reading
About the author
Eric Rozon
Senior Security Researcher
あなたのデータ × DarktraceのAI
唯一無二のDarktrace AIで、ネットワークセキュリティを次の次元へ