
Jim Walter

2026
Agent vs. Agent: Inside an AI-Orchestrated Criminal Enterprise
AI-enabled hacking is often discussed as a future risk: autonomous malware, vulnerability exploitation at machine speed, or abuse of the next flagship model. This talk is about a different reality: an experienced criminal operation already using AI as an engineering workbench.
 In a joint investigation by Sophos and SentinelOne researchers, we tracked a financially motivated ransomware operation that integrated AI into its core workflows. The group used agentic coding tools and Model Context Protocol (MCP) to support payload generation, defensive-control research, infrastructure automation, and operator tooling.
We will show how those workflows changed the actor’s operating tempo: rapid prototyping, Active Directory lab automation, cloud infrastructure movement, and early experimentation with AI-agent mimicry for traffic masquerading. The same automation exposed the seams of the operation, including operational security failures, brittle agent behavior, token and context limitations, and automation-induced mistakes that created investigative visibility.Â
The defender side required its own shift in workflow. We used AI-assisted analysis to triage repositories and logs, built tooling to monitor adversary infrastructure, navigated collection risk, and coordinated across service providers, vendors, and public-sector partners. We will discuss the limits of our own AI-assisted workflows, including noisy outputs, over-aggregation, brittle assumptions, and the points where human judgment remains the difference between generated output and actionable intelligence.Â
Finally, we connect the development lifecycle to real victim impact. Over two months, the operation affected roughly 30 victims, involved seven-figure extortion demands, led to hundreds of gigabytes of stolen data, and supported rapid-fire ransomware deployments. We will discuss actor attribution, ecosystem overlaps, and what the investigation revealed about the pace of AI-enabled criminal operations.
Â
About Jim Walter
Jim Walter is a Senior Threat Researcher at SentinelOne focusing on evolving trends, actors, and tactics within the thriving ecosystem of cybercrime and crimeware. He specializes in the discovery and analysis of emerging cybercrime "services" and evolving communication channels leveraged by mid-level criminal organizations. Jim joined SentinelOne following ~4 years at a security start-up, also focused on malware research and organized crime.Â
Previously, he spent over 17 years at McAfee/Intel running their Threat Intelligence and Advanced Threat Research teams.
