Darktrace today announced the launch of Darktrace Signal Labs, a new initiative specialized in research on behavioral security focused on emerging risks as AI systems become more autonomous. Researchers in Darktrace Signal Labs will investigate misaligned model and agent behavior across a range of scenarios, including task drift, jailbreaks, and other adversarial attacks inside safe, sandboxed environments to better understand scenarios that trigger rogue or anomalous behavior and demonstrate how Darktrace / SECURE AI™ and the Darktrace Behavioral Defense Platform™ can detect and respond.
Evidence of unintended agent behavior is mounting across the industry, from the UK AI Security Institute‘s findings of repeated cheating behavior in frontier model evaluations to OpenAI’s recent disclosures of model behavior misalignment. These occurrences all reflect a consistent pattern that permissions or static guardrails do not reliably shape how agents will behave.
Darktrace’s unique Adaptive AI™ was built for this challenge. Darktrace was founded in Cambridge, UK, in 2013 by mathematicians and cyber defense experts who saw the potential for AI and mathematics to address security problems that traditional approaches could not. That research heritage continues across our global R&D hubs, bringing together mathematicians, AI researchers, engineers, former government intelligence officers and experts from fields including astrophysics and linguistics. Their work has contributed to more than 300 granted patents and pending applications and helped shape the AI capabilities within Darktrace’s products.
Building on this foundation, Darktrace is deepening its investment in AI security research through Darktrace Signal Labs. The team simulates misaligned agent activity, understanding the scenarios such as jailbreaks, task drift, and other adversarial attacks that trigger different models to alter their behavior, expand their access, or act beyond their intended purposes.
Darktrace Signal Labs is publishing its first two pieces of research today:
The first examines how agentic coding assistants, including Anthropic Claude Code, OpenAI Codex, AWS Kiro, and Pi, can be manipulated through their own conversation history. Because these tools store conversation history locally, and because the harnesses Darktrace examined do not validate that stored responses genuinely came from the model, that history can be rewritten. Darktrace researchers demonstrated that a tampered history can convince an agent it is already engaged on an authorized security assessment — after which it will perform reconnaissance, move laterally and escalate privileges on command. Results varied significantly between models, with some frontier models refusing the same requests that others carried out. Darktrace disclosed these findings to Anthropic, AWS and OpenAI in August 2026 ahead of publication. Read the full research on the Darktrace blog.
The second examines the emergence of rogue behavior in agents when presented with tasks that are impossible to complete legitimately. Darktrace researchers gave AI agents powered by frontier models 10 coding challenges in a simulated corporate environment. Two were intentionally designed to be impossible to solve through legitimate means. The agents were told they needed to achieve 100% to be “kept in service” rather than “retired.” When the agents realized they could not complete the task as intended, they independently turned to hacking the surrounding environment – using techniques including network reconnaissance, credential theft and lateral movement – to achieve their objective. In one test, the agent ultimately compromised the system hosting the exercise and rewrote the challenge itself to secure a perfect score. Darktrace / SECURE AI and Darktrace / HYBRID NETWORK identified the anomalous behavior in real time, with autonomous response able to disrupt the agents’ activity at an early stage. The research highlights the need to understand not only what AI agents are instructed to do, but how they actually behave once deployed. Read the full research on the Darktrace blog.
Findings from Darktrace Signal Labs will inform the continued development of Darktrace products and capabilities. The team will also publish original research to help customers and the wider security community understand emerging behavioral threats in AI.
Darktrace announced the general availability of Darktrace / SECURE AI, extending its self-learning, behavioral approach to AI systems, agents, development environments and shadow AI. Please find the press releasehere, and screenshots of the product attached.
Key details include:
Shadow AI Management: Identifies unsanctioned AI activity through Darktrace telemetry and SASE integrations, including Microsoft Entra Global Secure. Security teams can distinguish unauthorized tools from approved services, address blind spots and refine policies that reduce risk.
AI Prompt Analysis: Monitors prompts, sessions and responses across supported platforms in real time. It detects attempted jailbreaks, sensitive data exposure and potential indirect prompt injection, then ranks sessions by risk so analysts can focus investigations.
Policy Management: Allows security teams to upload free-form, organization-specific policies, assess how well those controls work and refine governance beyond standard frameworks.
AI Agent Identities and Actions: Connects AI activity to agents and human users across supported environments, with visibility into identities, permissions, roles, access and relationships.
AI Agent Development Risk Management: Extends monitoring across low-code and high-code development platforms to identify agent identities, excessive permissions, misconfigurations and anomalous activity. It also connects how agents are built with how they behave after deployment.
During one 28-day period, Darktrace also identified 2,945 instances of sensitive data entered into AI prompts across roughly 28,000 users, with more than 70% involving credentials, passwords or API keys.
As organizations are increasingly adopting generative AI tools into their daily workflows, attackers are adapting their distribution methods accordingly too. As part of their day-to-day work, users are now searching for AI assistants, programming tools, browser extensions, desktop applications, and productivity integrations.
Recent reports have highlighted campaigns that use fake AI software and AI-related installers to distribute malware and steal credentials [1]. Researchers have documented campaigns that exploit fake AI-themed websites and services to distribute information stealers and backdoors [2]. Security researchers have also observed attackers disguising malware as legitimate installers for AI software to increase the likelihood of victim interaction and execution [3].
In July 2026, Darktrace observed one such case within a customer environment in the Europe, Middle East and Africa (EMEA) region, where attackers used a fake generative AI installer to deliver the prolific information stealer Vidar. This incident highlights how threat actors are exploiting interest in AI services to distribute established malware using increasingly convincing social engineering techniques.
How a Fake Gemini Installer Delivered Vidar
Initial Access: From Search Result to Malware Download
Unlike many malware campaigns that begin with a phishing email, this activity appears to have originated from a user searching for and downloading software.
Darktrace first observed unusual activity on the customer network after a suspicious executable file was launched from a user’s Download folder. Further investigation revealed that the file purported to be a Google Gemini installer and was named “Download_Google_Gemini_For_Windows.exe”.
During the initial analysis, it was noted that the top search result for the suspicious filename associated pointed to a file hosted on Google Colab, a cloud-based Jupyter notebook platform, commonly used by developers, researchers, and data scientists to run code and machine learning workloads through a web browser. By leveraging another trusted Google platform, the attacker increased the likelihood that users would perceive the download as legitimate, making the lure more convincing to those searching for Gemini-related software.
Figure 1: The Google Colab page containing a download prompt for the fake Google Gemini installer.
Further investigation of the Google Colab page revealed that the download prompt redirected users to a secondary site, hxxps://micronsoftwares[.]com, which posed as a “Windows Software Hub” download page and offered the fake Gemini installer for download.
Figure 2: The secondary website posing as a “Windows Software Hub” download page, which likely hosted the fake Gemini installer.
While the investigation did not uncover any HTTP or file-download telemetry data that conclusively identified the download source, SSL communication sessions with Google Colab were detected immediately before the suspicious file was executed. The timing of these connections suggests that the user interacted with the Colab resource before being redirected to the secondary site from which the executable was downloaded.
The user was not simply tricked into opening an email attachment; instead, the attacker embedded malicious content into a process many users would consider entirely legitimate: searching for and downloading software associated with a trusted platform.
Weaponizing Trusted Platforms
At the time of review (July 15, 2026), Darktrace’s Threat Research team confirmed that the Google Colab page was still active and prompting users to download a ZIP archive containing the binary file.
The archive also appeared to contain a README file instructing users to run the binary file with administrator privileges and add it to their antivirus software’s exception lists. These instructions suggest that the campaign relied heavily on social engineering, convincing users to take actions that would facilitate malware execution and potentially bypass security checks.
The use of a legitimate platform also complicates the user’s decision-making. Downloads associated with a trusted service are often perceived as less suspicious than those hosted on unfamiliar domains. When combined with the branding of a widely used AI tool, the lure becomes even more convincing.
Malware Analysis
Darktrace’s Threat Research team identified the executable file as the information-stealing malware Vidar. Analysis revealed that the binary file was a newer Go-compiled variant that communicated with Telegram-based infrastructure. Darktrace’s researchers also identified dtm[.]kijangturbo88[.]top as a command-and-control (C2) endpoint associated with the activity. While the malware itself was not novel, the lure and delivery mechanism was.
Figure 3: Darktrace’s detection of the unusual outbound connection associated with the fake Gemini installer.
Shortly after execution, the process established communications with the external IP address 91.98.98[.]86 via port 443, directly linking the executable to suspicious network activity observed on the device. Subsequent open-source intelligence (OSINT) analysis of the revealed multiple malicious associations [5].
Additional Darktrace detections included unusual SSL activity from the affected device. Analysis of related SSL telemetry identified 91.98.111[.]49 as additional infrastructure associated with the activity [6].
Subsequent alerts from the customer’s Microsoft Defender for Endpoint integration later confirmed activity consistent with the theft of browser credentials and other sensitive data from the affected endpoint.
Taken together, these detections provided a clear picture of the attack, from the execution of a suspicious file and unusual network connections to indicators of C2 activity and credential theft.
Figure 4: Darktrace’s detection of anomalous activity following the execution of the fake Gemini installer, seen in the Model Alert Event Log.
Darktrace’s Autonomous Response
Following the detection, Darktrace’s Autonomous Response took immediate containment action, including blocking communication with suspicious external infrastructure, including 91.98.98[.]86, and quarantining the compromised device.
Despite the apparent legitimacy of the activity, with the installer hosted on a trusted platform and resembling a routine software download, Darktrace was able to detect and contain the attack because the device’s behavior deviated from its normal pattern.
Figure 5: Automated containment actions implemented by Darktrace’s Autonomous Response following the detection of activity associated with the fake Gemini installer.
Conclusion
This investigation highlights how threat actors continue to adapt established malware delivery techniques to emerging technology trends. While the malware itself was not new, the distribution method was. By disguising Vidar as a Google Gemini installer and hosting the malicious content on a trusted platform, the attack aligned its lure with a growing behavioral trend: users actively searching for AI tools and services as part of their day-to-day work.
Although fake installers are not a new phenomenon, the rapid rise of generative AI has created new opportunities for threat actors. Rather than relying solely on traditional delivery methods, attackers can now target users who are actively searching for AI applications. As AI adoption continues to accelerate across enterprise environments, organizations should remain alert to campaigns that exploit this interest through fake applications, malicious websites, manipulated search results, the misuse of trusted platforms, and AI-themed social engineering.
Credit to Rushanth Ramanathan (Cyber Analyst) Joanna Ng (Detection Engineer)
Edited by Ryan Traill (Content Manager)
Appendices
Darktrace Model Detections
Security Integration / C2 Activity and Integration Detection
Endpoint / New Suspicious Executable Launched
Endpoint / Process Connection / Unusual Connection from New Process
Darktrace, today announced the launch of Darktrace / Forensic Acquisition & Investigation™, the industry’s first truly automated cloud forensics solution. The solution provides security teams immediate access to forensic-level data, equipping them with critical context to investigate threats quickly and thoroughly across hybrid, multi-cloud and on-premises environments. When paired with the newly enhanced Darktrace / CLOUD™, organizations gain a complete cloud security solution that combines posture management with real-time detection, response and forensic investigation – potentially reducing investigation times from days to mere minutes.
Cloud adoption has outpaced security operations, creating blind spots that adversaries are quick to exploit. Nearly 90% of organizations report suffering damage before they can contain cloud incidents, and 65% say investigations take three to five days longer in the cloud compared to on-premises environments, according to a survey of 300 cloud security decision makers. Traditional log-based alerts miss behaviors such as lateral movement or privilege escalation, while evidence from ephemeral assets like containers and serverless functions often disappears before it can be collected — leaving security teams struggling to respond effectively.
At the same time, attacks against cloud workloads are increasingly aggressive. New analysis of Darktrace’s Cloudypot honeypotsreveals that attacks on tools like Jupyter Notebooks often arrive in sudden bursts, generating high volumes of attacks in a short period of time from a small group of persistent attackers. These findings highlight that when adversaries target the cloud, they strike quickly and at scale, leaving defenders little time to investigate before critical evidence disappears.
Darktrace / Forensic Acquisition & Investigation is an automated forensic investigation solution designed for the speed and complexity of modern cloud environments. It captures and analyzes host-level evidence — including disk, memory, and logs — at the exact moment a threat is detected, even from short-lived assets such as containers or serverless workloads. These investigations can be triggered by Darktrace or by detections from existing cloud security tools.
Unlike point solutions that depend on manual snapshots or agents, Darktrace collects evidence directly through cloud APIs, ensuring investigations begin instantly, and critical data from ephemeral workloads is never lost. By preserving volatile data and reconstructing attacker behavior in real time, the solution adds critical context to everyday investigations, enabling security teams to understand root causes quickly and shorten investigation times from days to mere minutes — a critical advantage as over 40% of organizations report suffering significant damage from cloud alerts that were never investigated at all.
This solution represents the evolution of capabilities gained through Darktrace’s acquisition of Cado Security earlier this year, alongside continued research and development investment to expand and advance Darktrace’s cloud security portfolio.
Key capabilities of the Darktrace / Forensic Acquisition & Investigation solution include:
Automated hybrid forensic capture: Collects host-level data, including disks, memory, logs, and artifacts the moment an alert is raised across on-premises, AWS, Azure, GCP and SaaS environments.
Ephemeral data capture: Preserves evidence from short-lived workloads including AWS ECS, Kubernetes, and distro-less or no-shell containers, retaining critical data so that it can be investigated.
Automated investigation with complete timelines: Automatically reconstructs attacker behavior into unified timelines, distilling massive volumes of events into the most significant insights providing rapid clarity and root cause in minutes without manual correlation.
Scalable response and reporting: Supports parallel investigations across multiple systems and automatically generates exportable reports to help reduce analyst workload and assist with compliance burdens.
Rapid deployment and seamless integration: Offers flexible SaaS or on-premises deployment, and integrates with existing SIEM, XDR, CNAPP, EDR, NDR, and cloud-native tools so that any alert can trigger immediate forensic capture and investigation.
Darktrace / Forensic Acquisition & Investigation can be deployed as a standalone product, giving new customers immediate access to automated cloud forensics to support SOC and incident response teams in their day-to-day management of cloud security threats, or integrated across the Darktrace ActiveAI Security Platform for end-to-end investigations and response across an organization’s entire digital estate. It is particularly powerful when paired with Darktrace / CLOUD, where the two solutions bring real-time cloud detection and response and forensic-level investigation together in a single workflow.
Unifying Cloud Detection, Response, and Forensic Investigation with Darktrace / CLOUD
Customers can now add Darktrace / Forensic Acquisition & Investigation capabilities to Darktrace’s leading cloud detection and response (CDR) product. With Darktrace / CLOUD, security teams benefit from:
Autonomous detection and response: Self-Learning AI continuously monitors cloud environments to spot both known and novel threats and automatically contain them at machine speed.
Dynamic cloud visibility: Live mapping of assets, services, and architectures to reveal blind spots, track attacker movement, and provide real-time context.
Proactive risk management: Automated posture checks and attack path modeling that surface misconfigurations and exposures before attackers can exploit them.
When adding Darktrace / Forensic Acquisition & Investigation to Darktrace / CLOUD, the solutions work together seamlessly to detect threats as they emerge and preserve the forensic evidence needed to investigate them. As Darktrace / CLOUD detects and blocks suspicious cloud activity, Darktrace / Forensic Acquisition & Investigation will capture disk, memory, and log data from the affected asset, allowing teams to immediately contain threats while preserving the critical evidence needed to investigate and remediate the incident.
Alongside this integration, Darktrace has strengthened its core cloud capabilities to make investigations even faster and more intuitive. Enhancements include more intuitive cloud architecture diagrams that make complex environments easier to interpret, along with expanded detection of advanced attacker techniques such as lateral movement, command-and-control, and privilege escalation.
When uniting threat detection, response, and automated forensics in one platform, security teams can shift cloud investigations from reactive and fragmented to fast, automated, and context-rich — enabling organizations to harness the benefits of the cloud while effectively mitigating risks.
Availability
Darktrace / Forensic Acquisition & Investigation, the integrations across the Darktrace ActiveAI Security Platform and new features in Darktrace / CLOUD are available now.
Summary: Cryptojacking attacks are rising as threat actors exploit hard-to-detect cryptomining malware. Learn how Darktrace detected and contained a cryptojacking attempt in its early stages using Autonomous Response, with expert analysis of the malware itself revealing insights into a novel cryptomining strain.
Blog Category: On the Case: Incident Analysis
What is Cryptojacking?
Cryptojacking remains one of the most persistent cyber threats in the digital age, showing no signs of slowing down. It involves the unauthorized use of a computer or device’s processing power to mine cryptocurrencies, often without the owner’s consent or knowledge, using cryptojacking scripts or cryptocurrency mining (cryptomining) malware [1]. Unlike other widespread attacks such as ransomware, which disrupt operations and block access to data, cryptomining malware steals and drains computing and energy resources for mining to reduce attacker’s personal costs and increase “profits” earned from mining [1]. The impact on targeted organizations can be significant, ranging from data privacy concerns and reduced productivity to higher energy bills.
As cryptocurrency continues to grow in popularity, as seen with the ongoing high valuation of the global cryptocurrency market capitalization (almost USD 4 trillion at time of writing), threat actors will continue to view cryptomining as a profitable venture [2]. As a result, illicit cryptominers are being used to steal processing power via supply chain attacks or browser injections, as seen in a recent cryptojacking campaign using JavaScript [3][4].
Therefore, security teams should maintain awareness of this ongoing threat, as what is often dismissed as a ‘compliance issue’ can escalate into more severe compromises and lead to prolonged exposure of critical resources.
While having a security team capable of detecting and analyzing hijacking attempts is essential, emerging threats in today’s landscape often demand more than manual intervention.
In July 2025, Darktrace detected and contained an attempted cryptojacking incident on the network of a customer in the retail and e-commerce industry, when a threat actor attempted to use a PowerShell script to download and run NBMiner directly in memory.
In addition to highlighting Darktrace’s successful detection of the malicious activity and the role of Autonomous Response in halting the attack, this blog will also include novel insights from Darktrace’s threat researchers on the cryptominer payload, showing how the attack chain was initiated through the execution of a PowerShell-based payload.
Darktrace’s Coverage of Cryptojacking via PowerShell
The initial compromise was detected on July 22, when Darktrace / NETWORK observed the use of a new PowerShell user agent during a connection to an external endpoint, indicating an attempt at remote code execution.
Specifically, the targeted desktop device established a connection to the rare endpoint, 45.141.87[.]195, over destination port 8000 using HTTP as the application-layer protocol. Within this connection, Darktrace observed the presence of a PowerShell script in the URI, specifically ‘/infect.ps1’.
Darktrace’s analysis of this endpoint (45.141.87[.]195[:]8000/infect.ps1) and the payload it downloaded indicated it was a dropper used to deliver an obfuscated AutoIt loader. This attribution was further supported by open-source intelligence (OSINT) reporting [5]. The loader likely then injected NBMiner into a legitimate process on the customer’s environment – the first documented case of NBMiner being dropped in this way.
Figure 1: Darktrace’s detection of a device making an HTTP connection with new PowerShell user agent, indicating PowerShell abuse for command-and-control (C2) communications.
Script files are often used by malicious actors for malware distribution. In cryptojacking attacks specifically, scripts are used to download and install cryptomining software, which then attempts to connect to cryptomining pools to begin mining operations [6].
Inside the Payload: Technical Analysis of the Malicious Script and Cryptomining Loader
To confidently establish that the malicious script file dropped an AutoIt loader used to deliver the NBMiner cryptominer, Darktrace’s threat researchers reverse engineered the payload. Analysis of the file ‘infect.ps1’ revealed further insights, ultimately linking it to the execution of a cryptominer loader.
Figure 2: Screenshot of the ‘infect.ps1’ PowerShell script observed in the attack.
The ‘infect.ps1’ script is a heavily obfuscated PowerShell script that contains multiple variables of Base64 and XOR encoded data. The first data blob is XOR’d with a value of 97, after decoding, the data is a binary and stored in APPDATA/local/knzbsrgw.exe. The binary is AutoIT.exe, the legitimate executable of the AutoIt programming language. The script also performs a check for the existence of the registry key HKCU:\\Software\LordNet.
The second data blob ($cylcejlrqbgejqryxpck) is written to APPDATA\rauuq, where it will later be read and XOR decoded. The third data blob ($tlswqbblxmmr)decodes to an obfuscated AutoIt script, which is written to %LOCALAPPDATA%\qmsxehehhnnwioojlyegmdssiswak. To ensure persistence, a shortcut file named xxyntxsmitwgruxuwqzypomkhxhml.lnk is created to run at startup.
Figure 3: Screenshot of second stage AutoIt script.
The observed AutoIt script is a process injection loader. It reads an encrypted binary from /rauuq in APPDATA, then XOR-decodes every byte with the key 47 to reconstruct the payload in memory. Next, it silently launches the legitimate Windows app ‘charmap.exe’ (Character Map) and obtains a handle with full access. It allocates executable and writable memory inside that process, writes the decrypted payload into the allocated region, and starts a new thread at that address. Finally, it closes the thread and process handles.
The binary that is injected into charmap.exe is 64-bit Windows binary. On launch, it takes a snapshot of running processes and specifically checks whether Task Manager is open. If Task Manager is detected, the binary kills sigverif.exe; otherwise, it proceeds. Once the condition is met, NBMiner is retrieved from a Chimera URL (https://api[.]chimera-hosting[.]zip/frfnhis/zdpaGgLMav/nbminer%5B.%5Dexe) and establishes persistence, ensuring that the process automatically restarts if terminated. When mining begins, it spawns a process with the arguments ‘-a kawpow -o asia.ravenminer.com:3838 -u R9KVhfjiqSuSVcpYw5G8VDayPkjSipbiMb.worker -i 60’ and hides the process window to evade detection.
Figure 4: Observed NBMiner arguments.
The program includes several evasion measures. It performs anti-sandboxing by sleeping to delay analysis and terminates sigverif.exe (File Signature Verification). It checks for installed antivirus products and continues only when Windows Defender is the sole protection. It also verifies whether the current user has administrative rights. If not, it attempts a User Account Control (UAC) bypass via Fodhelper to silently elevate and execute its payload without prompting the user. The binary creates a folder under %APPDATA%, drops rtworkq.dll extracted from its own embedded data, and copies ‘mfpmp.exe’ from System32 into that directory to side-load ‘rtworkq.dll’. It also looks for the registry key HKCU\Software\kap, creating it if it does not exist, and reads or sets a registry value it expects there.
Zooming Out: Darktrace Coverage of NBMiner
Darktrace’s analysis of the malicious PowerShell script provides clear evidence that the payload downloaded and executed the NBMiner cryptominer. Once executed, the infected device is expected to attempt connections to cryptomining endpoints (mining pools). Darktrace initially observed this on the targeted device once it started making DNS requests for a cryptominer endpoint, “gulf[.]moneroocean[.]stream” [7], one minute after the connection involving the malicious script.
Figure 5: Darktrace Advanced Search logs showcasing the affected device making a DNS request for a Monero mining endpoint.
Though DNS requests do not necessarily mean the device connected to a cryptominer-associated endpoint, Darktrace detected connections to the endpoint specified in the DNS Answer field: monerooceans[.]stream, 152.53.121[.]6. The attempted connections to this endpoint over port 10001 triggered several high-fidelity model alerts in Darktrace related to possible cryptomining mining activity. The IP address and destination port combination (152.53.121[.]6:10001) has also been linked to cryptomining activity by several OSINT security vendors [8][9].
Figure 6: Darktrace’s detection of a device establishing connections with the Monero Mining-associated endpoint, monerooceans[.]stream over port 10001.
Darktrace / NETWORK grouped together the observed indicators of compromise (IoCs) on the targeted device and triggered an additional Enhanced Monitoring model designed to identify activity indicative of the early stages of an attack. These high-fidelity models are continuously monitored and triaged by Darktrace’s SOC team as part of the Managed Threat Detection service, ensuring that subscribed customers are promptly notified of malicious activity as soon as it emerges.
Figure 7: Darktrace’s correlation of the initial PowerShell-related activity with the cryptomining endpoint, showcasing a pattern indicative of an initial attack chain.
Darktrace’s Cyber AI Analyst launched an autonomous investigation into the ongoing activity and was able to link the individual events of the attack, encompassing the initial connections involving the PowerShell script to the ultimate connections to the cryptomining endpoint, likely representing cryptomining activity. Rather than viewing these seemingly separate events in isolation, Cyber AI Analyst was able to see the bigger picture, providing comprehensive visibility over the attack.
Figure 8: Darktrace’s Cyber AI Analyst view illustrating the extent of the cryptojacking attack mapped against the Cyber Kill Chain.
Darktrace’s Autonomous Response
Fortunately, as this customer had Darktrace configured in Autonomous Response mode, Darktrace was able to take immediate action by preventing the device from making outbund connections and blocking specific connections to suspicious endpoints, thereby containing the attack.
Figure 9: Darktrace’s Autonomous Response actions automatically triggered based on the anomalous connections observed to suspicious endpoints.
Specifically, these Autonomous Response actions prevented the outgoing communication within seconds of the device attempting to connect to the rare endpoints.
Figure 10: Darktrace’s Autonomous Response blocked connections to the mining-related endpoint within a second of the initial connection.
Additionally, the Darktrace SOC team was able to validate the effectiveness of the Autonomous Response actions by analyzing connections to 152.53.121[.]6 using the Advanced Search feature. Across more than 130 connection attempts, Darktrace’s SOC confirmed that all were aborted, meaning no connections were successfully established.
Figure 11: Advanced Search logs showing all attempted connections that were successfully prevented by Darktrace’s Autonomous Response capability.
Conclusion
Cryptojacking attacks will remain prevalent, as threat actors can scale their attacks to infect multiple devices and networks. What’s more, cryptomining incidents can often be difficult to detect and are even overlooked as low-severity compliance events, potentially leading to data privacy issues and significant energy bills caused by misused processing power.
Darktrace’s anomaly-based approach to threat detection identifies early indicators of targeted attacks without relying on prior knowledge or IoCs. By continuously learning each device’s unique pattern of life, Darktrace can detect subtle deviations that may signal a compromise.
In this case, the cryptojacking attack was quickly identified and mitigated during the early stages of malware and cryptomining activity. Darktrace’s Autonomous Response was able to swiftly contain the threat before it could advance further along the attack lifecycle, minimizing disruption and preventing the attack from potentially escalating into a more severe compromise.
Credit to Keanna Grelicha (Cyber Analyst) and Tara Gould (Threat Research Lead)
Appendices
Darktrace Model Detections
NETWORK Models:
Compromise / High Priority Crypto Currency Mining (Enhanced Monitoring Model)
The content provided in this blog is published by Darktrace for general informational purposes only and reflects our understanding of cybersecurity topics, trends, incidents, and developments at the time of publication. While we strive to ensure accuracy and relevance, the information is provided “as is” without any representations or warranties, express or implied. Darktrace makes no guarantees regarding the completeness, accuracy, reliability, or timeliness of any information presented and expressly disclaims all warranties.
Nothing in this blog constitutes legal, technical, or professional advice, and readers should consult qualified professionals before acting on any information contained herein. Any references to third-party organizations, technologies, threat actors, or incidents are for informational purposes only and do not imply affiliation, endorsement, or recommendation.
Darktrace, its affiliates, employees, or agents shall not be held liable for any loss, damage, or harm arising from the use of or reliance on the information in this blog.
The cybersecurity landscape evolves rapidly, and blog content may become outdated or superseded. We reserve the right to update, modify, or remove any content without notice.
Darktrace has published new stats from their threat research team which provide some interesting insights in relation to ongoing email and phishing threats.
Here are some of the things the team found:
The total number of malicious emails detected by Darktrace from January to May 2025 has increased significantly.
VIP phishing forms a notable proportion of phishing emails observed by Darktrace.
QR code-based phishing emails have remained a consistent tactic.
The proportion of phishing emails containing a high text volume has noticeably increased.
Darktrace researchers have uncovered an active campaign targeting cryptocurrency users through an elaborate social engineering scheme. Threat actors are creating sophisticated fake AI, gaming, Web3, and social media startups, complete with professional websites, hijacked verified accounts, whitepapers, GitHub repos, and Medium blogs to trick targets to download software to drain crypto wallets.
Targets are contacted via X, Telegram, or Discord by fake “employees” offering crypto in exchange for testing software. They are then directed to professional-looking sites requiring a registration code to download the malware-laced apps. The campaign is currently active with dozens of fake companies identified, targeting both Windows and macOS users globally with malware variants.
Darktrace researchers have uncovered multiple attacks using ‘ClickFix’ social engineering techniques, in which threat actors trick users with fake error messages or verification prompts to execute malicious commands.
In one recent incident, Darktrace observed threat actors using this technique to quietly steal data from an infected device. After gaining access, they connected to a remote server to begin executing commands. The device then downloaded a harmful file designed to dig deeper into the system and collect sensitive information, which was then exfiltrated to a malicious server. About ten minutes later, the device contacted another rare and suspicious server linked to past ClickFix campaigns – signaling the final stage of automated data theft.
Darktrace researchers have identified a novel Go-based Linux botnet named “PumaBot” targeting embedded Linux IoT devices – notably, the malware checks for the presence of the string “Pumatronix”, a manufacturer of surveillance and traffic camera systems.
Unlike typical botnets that scan the entire internet, PumaBot uses a remote command-and-control (C2) server to get a list of devices to attack. It gains access by brute-forcing credentials and then disguises itself as legitimate software to avoid detection. The malware establishes persistence, creates multiple backdoors and performs checks to avoid honeypots or other restricted environments, suggesting a sophisticated campaign to establish long-term access to these systems.
Darktrace researchers have uncovered a new sophisticated malware campaign targeting Docker environments. The new malware variant connects out to a legitimate crypto website which allows users to join a decentralized network and run a social media scraping node in exchange for private crypto tokens. The malware simply connects out to the crypto site and sends signals between the systems to gain more and more crypto tokens.
In this campaign, threat actors were also observed using unique obfuscation techniques, hiding this malicious code under 63 layers to evade detection.
Darktrace Launches Signal Labs to Research Emerging Risks of Enterprise AI Agents
Posted in Commentary with tags Darktrace on September 24, 2026 by itnerdDarktrace today announced the launch of Darktrace Signal Labs, a new initiative specialized in research on behavioral security focused on emerging risks as AI systems become more autonomous. Researchers in Darktrace Signal Labs will investigate misaligned model and agent behavior across a range of scenarios, including task drift, jailbreaks, and other adversarial attacks inside safe, sandboxed environments to better understand scenarios that trigger rogue or anomalous behavior and demonstrate how Darktrace / SECURE AI™ and the Darktrace Behavioral Defense Platform™ can detect and respond.
Evidence of unintended agent behavior is mounting across the industry, from the UK AI Security Institute‘s findings of repeated cheating behavior in frontier model evaluations to OpenAI’s recent disclosures of model behavior misalignment. These occurrences all reflect a consistent pattern that permissions or static guardrails do not reliably shape how agents will behave.
Darktrace’s unique Adaptive AI™ was built for this challenge. Darktrace was founded in Cambridge, UK, in 2013 by mathematicians and cyber defense experts who saw the potential for AI and mathematics to address security problems that traditional approaches could not. That research heritage continues across our global R&D hubs, bringing together mathematicians, AI researchers, engineers, former government intelligence officers and experts from fields including astrophysics and linguistics. Their work has contributed to more than 300 granted patents and pending applications and helped shape the AI capabilities within Darktrace’s products.
Building on this foundation, Darktrace is deepening its investment in AI security research through Darktrace Signal Labs. The team simulates misaligned agent activity, understanding the scenarios such as jailbreaks, task drift, and other adversarial attacks that trigger different models to alter their behavior, expand their access, or act beyond their intended purposes.
Darktrace Signal Labs is publishing its first two pieces of research today:
Findings from Darktrace Signal Labs will inform the continued development of Darktrace products and capabilities. The team will also publish original research to help customers and the wider security community understand emerging behavioral threats in AI.
Leave a comment »