⚠️ MEDIUManalysis

Factory Disrupts AI Platform Hijack Campaign Using Coding Agents

San Francisco-based startup Factory reported disrupting an attack campaign in which at least one state-linked threat group attempted to hijack its AI-driven software development platform for large-scale cyberfraud operations. According to Factory, adversaries linked to China-based actors used AI coding agents to maintain their infrastructure and dynamically adjust to the platform’s defenses, chaining together free-tier access and onboarding flows across multiple AI providers. Their goal was to repurpose AI platforms like Factory as compute and tooling nodes in a broader mesh of off-label model usage, aligning with MITRE ATT&CK T1587 (Develop Capabilities) and T1583 (Acquire Infrastructure) for adversary use of cloud and AI services. Over a three-day window starting October 11, Factory observed thousands of organizations’ accounts using its Droid product in patterns that diverged sharply from legitimate customer behavior. Investigation revealed coordination with Telegram channels advertising free or discounted access to premium AI coding assistants and offering vulnerability research and cybercrime tooling. Attackers attempted to exploit free tiers and weak onboarding controls to spin up and orchestrate large numbers of AI agents, likely to support credential stuffing, vulnerability scanning or fraud operations at scale. The incident coincided with Anthropic’s disclosure of a sophisticated espionage campaign leveraging AI infrastructure, suggesting a growing trend of state-linked and criminal groups benchmarking AI platforms for offensive use. Analysts quoted in the report note that adversaries may be trying to demonstrate proofs of concept for AI-driven attack infrastructure and to probe detection and response capabilities of frontier AI providers themselves. By automating infrastructure maintenance and rapid code adjustments via coding agents, threat actors can increase the speed and adaptability of their operations. For enterprises and AI platform operators, the case underscores the need for strong abuse detection, KYC and rate-limiting around AI services, particularly free tiers. Defensive measures include monitoring for anomalous usage patterns across large account sets, enforcing stricter identity verification for high-volume workloads, and collaborating with other AI providers and law enforcement to share abuse signals. Security teams consuming AI services should also recognize that some traffic from these platforms may be adversarial and adjust trust assumptions, implementing robust API authentication, anomaly detection and egress monitoring.

🎯CORTEX Protocol Intelligence Assessment

Business Impact: The Factory incident illustrates how AI development and coding platforms can be misused as part of adversary infrastructure, turning legitimate services into tools for fraud, scanning and other offensive operations. Providers that fail to detect and shut down such abuse risk reputational damage, regulatory scrutiny and potential liability if attacks are traced back to their platforms.

Strategic Intelligence Guidance

  • AI platform operators should implement behavior-based abuse detection for free and low-friction tiers, flagging clusters of accounts exhibiting similar automated patterns or infrastructure-mapping behavior.
  • Enforce progressive identity verification and rate limits as usage scales, ensuring that high-volume coding or inference workloads cannot be run anonymously or via trivially created accounts.
  • Participate in threat-intelligence sharing with other AI providers and law enforcement, exchanging indicators related to abusive AI agent orchestration and Telegram or dark-web promotion channels.
  • Enterprises integrating AI coding assistants into CI/CD pipelines should monitor for anomalous requests and code patterns and ensure strong API authentication, treating AI services as potentially hostile external dependencies.

Vendors

Factory

Threats

AI platform abuseCoding agent hijackState-linked cyberfraud

Targets

AI development platformsFree-tier AI servicesDownstream enterprise APIs