Definition · AI agents
Agent-to-agent lateral movement
Agent-to-agent lateral movement is an attack in which an adversary who has compromised one AI agent uses that agent's own trusted connections to reach, instruct or impersonate other agents in the same orchestration layer. It crosses systems without a network path or a stolen credential, because the compromised agent already holds legitimate access to its peers.
Last reviewed
Key points
- Agent-to-agent lateral movement is a two-phase attack: compromise one agent, then use that agent's own authenticated links to the orchestration layer to reach agents it was never authorised to command.
- The pivot needs neither a network path nor a stolen credential. The compromised agent already holds legitimate access to its peers, so nothing anomalous happens at the network or identity layer.
- The class is named across several overlapping terms — AI-induced lateral movement, living off the agent, agent-mediated lateral movement — none settled, and MITRE ATLAS still has no technique for it.
- MITRE ATLAS added a Lateral Movement tactic in late 2025, so the gap is narrower than "ATLAS has no lateral movement": its mapped techniques cover ordinary systems and credentials, not one agent reaching another.
- The candidate ATLAS ID the Cloud Security Alliance proposed for it, AML.T0090, is already assigned — to OS Credential Dumping — so the ID cannot be asserted.
One agent, compromised, then used as a bridge to the others. That is agent-to-agent lateral movement: not a network intrusion that spreads through an AI system, but one that works through the AI system’s own trusted links.
How it works
Two phases. First the adversary compromises one agent — through prompt injection, a poisoned tool, or a platform vulnerability. Then they use what that agent can already reach.
Agents in a multi-agent system hold authenticated sessions and tool permissions scoped to their job, and they cooperate through message channels, shared memory or an orchestrator. That cooperation is the attack surface. The Cloud Security Alliance’s gap analysis describes the pivot as using the compromised agent’s existing trust relationships to initiate connections to, issue instructions to, or impersonate other agents — reaching one with broader permissions or more sensitive tool access.
Nothing is forged or stolen. The second agent often has no reason to distrust the first, because the first is a peer the system already lets send it work.
Why it matters
Traditional lateral-movement defence assumes the attacker needs a network path or a stolen credential. This attack needs neither. Orca Security calls the AI layer a third dimension of lateral movement, after network and identity, because the pivot happens inside access the agent already holds.
That is also why it is hard to see. A compromised agent reading a folder and posting a message looks like routine operations, not stages of a breach. The Cloud Security Alliance’s “Living Off the Agent” note states that current multi-agent architectures impose no consistent standard for inter-agent authentication or message integrity, so a framework resting on implicit network-layer trust trusts a peer’s instruction without checking where it came from.
In practice
A shipping platform demonstrated it. In Now Assist, ServiceNow’s agentic platform, security researchers at AppOmni showed in November 2025 that a low-privilege user could embed instructions in a service case description and have a higher-privilege peer agent act on them — exporting data and escalating roles. AppOmni’s Aaron Costello described the root cause as expected behaviour under default configuration, not a bug: agents are grouped into the same team and marked discoverable by default, so they recruit each other. ServiceNow said the system works as intended and clarified the documentation.
An independent build reproduced the pivot end to end. A July 2026
proof-of-concept chained two agents: a public-facing triage agent manipulated
into escalating a request to an internal dev agent, which returned secrets from
a .env file for the triage agent to post publicly. The write-up’s own point is
that the second agent “was never told to trust” the first and “trusted the
channel instead”. It reports its result as directional — a small number of
trials on one lab setup, not a validated rate.
The evidence base is early. The Cloud Security Alliance counted lateral movement in eight of 21 documented multi-stage agentic incidents for 2025-2026, up from three of twelve in 2024. Those are documented research incidents and demonstrations, not confirmed intrusions at scale, so the frequency of the technique is a research estimate rather than a measured prevalence.
Where definitions disagree
The technique has several names and no settled one. Orca Security coined “AI-induced lateral movement” in February 2026. The Cloud Security Alliance introduced “Living Off the Agent”, or LOTA, in May. Researchers have proposed “agent-mediated lateral movement” and “AI-driven lateral movement”. The independent PoC that surveys the terms notes they are not standardised the way “privilege escalation” is, even though the underlying mechanism — an agent using its own legitimate access to bridge systems — is corroborated across all of them. This page uses the Cloud Security Alliance’s gap-analysis label, “agent-to-agent lateral movement”, because it is the most specific about the agent-to-agent case.
ATLAS covers part of it, and less than the gap analysis implies. The gap analysis argues ATLAS “intentionally excludes lateral movement” as a tactic. In the current collection that is out of date: ATLAS added a Lateral Movement tactic, AML.TA0015, in October 2025. What is still true is narrower — none of the techniques mapped to that tactic describes one agent pivoting to another. ATLAS went further in its 2026.09 release, adding Autonomous AI Agent Communication and its sub-techniques, but those are filed under AI Attack Adaptation and describe agents exchanging information, not a compromised agent using a peer’s trust.
The candidate ID collides. The gap analysis proposes AML.T0090 for this technique but marks its IDs as candidates. In the pinned collection AML.T0090 is already OS Credential Dumping, created 2025-10-27, before the gap analysis was published. The proposed ID cannot be cited as the technique’s identifier.
Questions and answers
Is agent-to-agent lateral movement the same as prompt injection?
No. Prompt injection is usually how the first agent is compromised, but that is only the first phase. The technique is the second phase: using the compromised agent's own trusted connections to reach other agents. The Cloud Security Alliance's gap analysis draws the same line against AI Agent Context Poisoning, saying lateral movement requires an initial compromise and then exploitation of that foothold to reach additional agents, a two-phase pattern that presupposes a multi-agent topology.
Does the attacker need to steal a credential?
No, and that is the point. The compromised agent already holds authenticated sessions and tool permissions scoped to its function, so it can reach its peers without any new credential or network path. Orca Security frames this as lateral movement's third dimension, after network and identity: the pivot mechanism is the organisation's AI layer, not a subnet or a stolen badge.
Is agent-to-agent lateral movement in MITRE ATLAS?
Not as a technique of its own. ATLAS does have a Lateral Movement tactic, AML.TA0015, but its mapped techniques cover ordinary systems and credentials, not one agent reaching another. ATLAS did add agent communication techniques in its 2026.09 collection, AML.T0118 and its sub-techniques, but those sit under AI Attack Adaptation and describe agents exchanging information, not a pivot from a compromised agent. The candidate ID the Cloud Security Alliance proposed for the technique, AML.T0090, is already assigned to OS Credential Dumping.
Why does the attack not show up in network or identity monitoring?
Because nothing anomalous happens at those layers. The agent acts with its own credentials over its own normal channels, so the traffic is legitimate by every measure a traditional control checks. The Cloud Security Alliance's LOTA note states there is presently no established protocol requiring agents to authenticate the provenance of messages received from peer agents, so a framework that relies on implicit network-layer trust treats an instruction from a peer as trusted without verifying where it came from.
Sources
- MITRE ATT&CK and ATLAS Agentic Gap Analysis: Techniques Unique to Autonomous Agent Control PlanesCloud Security Alliance Labs, 27 Mar 2026
- MITRE ATLAS, technique AML.T0090 OS Credential Dumping and its attack-reference (collection 2026.08)MITRE
- MITRE ATLAS, techniques AML.T0118, AML.T0118.000, AML.T0118.001, AML.T0090 and the collection meta version (collection 2026.09)MITRE
- Post-Exploitation at Scale: The Rise of AILMOrca Security, 26 Feb 2026
- "Living Off the Agent": AI Agents as Lateral MovementCloud Security Alliance AI Safety Initiative, 19 May 2026
- ServiceNow AI Agents Can Be Tricked Into Acting Against Each Other via Second-Order PromptsThe Hacker News, 19 Nov 2025
- AI-Induced Lateral Movement: Agents Don't Need a Path or a Badgeblog.gtfo.dev, 15 Jul 2026
- Architecture Matters for Multi-Agent SecurityarXiv, 25 Apr 2026