Attackers Deploy AI Agents to Steal Thousands of Credentials in Six Hours
Google's threat intelligence team reports criminals are using autonomous AI frameworks to compress attack timelines, leaving defenders with minimal response windows.

Autonomous AI frameworks accelerate credential theft
Threat actors have successfully deployed a multi-agent artificial intelligence framework to compromise thousands of credentials in less than six hours, according to a report released today by Google's Threat Intelligence Group. The attack represents a significant escalation in how criminals are leveraging AI to compress attack timelines and reduce human involvement in cyberattacks.
Mandiant investigators attribute the campaign to a financially motivated actor who initially breached an organization's cloud infrastructure. The attacker then constructed an autonomous framework combining an AI coding chatbot, custom prompts, and agent instructions. Preconfigured markdown playbooks automated the subsequent scanning and credential harvesting operations.
The framework handled troubleshooting and IP rotation without operator intervention. Because traffic originated from the victim's own network addresses, it appeared legitimate as it exited the environment—a technique that bypasses many standard detection mechanisms.
From human-driven to autonomous attacks
The findings appear in Google Threat Intelligence Group's report "From Prompting to Autonomy: The Evolution of Adversarial AI," which tracks activity from the second quarter. The research follows a May report that documented the first confirmed instance of criminals using AI to develop a working zero-day exploit.
What has changed in the intervening months is the degree of autonomy, according to GTIG. Adversaries are now delegating multistep decision-making to AI models, which dramatically shrinks the window defenders have to detect and respond to intrusions.
While GTIG has not yet observed fully autonomous attack pipelines deployed against targets in production environments, adversary intent is clear. An alleged China-linked espionage group used Google's Gemini to design an automated penetration testing framework intended to conduct port scanning, service parsing, and other reconnaissance work independently. Google disabled the assets before the group progressed beyond the development phase.
Supply chain poisoning targets AI tooling
The report focuses substantial attention on UNC6780, a criminal group Google also tracks as TeamPCP. This actor poisoned the LiteLLM gateway in March and has since conducted large-scale compromises across PyPI, npm, and Docker Hub. The group publishes trojanized versions of Model Context Protocol servers and injects malicious code into GitHub repositories that AI coding assistants automatically clone.
Their DUSTMAKER credential stealer drops files into hidden project directories such as .claude and .cursor, locations where AI development tools read them as routine developer artifacts. Some malware samples included prompt injections written as extreme requests about biological and nuclear weapons—text apparently designed to trigger large language model security scanners to refuse the file and skip scanning the malicious JavaScript embedded within.
AI assets become direct targets
Mandiant worked several data theft extortion cases last quarter where attackers specifically targeted AI assets. Threat actors stole proprietary models, source code, and prompts from technology, healthcare, and media companies across North America and Europe. In one healthcare incident, attackers exfiltrated drug research data and a proprietary model, threatening to publish both unless the victim paid a ransom.
Compute resources are also being stolen. UNC6508, an alleged China-linked group with a multiyear campaign against academic, medical, and military research institutions, has been observed deploying open-weight models inside compromised cloud environments to keep their prompting activity away from commercial API monitoring. In another case, an exposed GitHub access token allowed an attacker to provision high-performance GPU instances in April at the victim's expense.
Why it matters
The six-hour credential theft campaign demonstrates that AI is fundamentally changing the economics of cyberattacks. When criminals can automate complex, multistep intrusions that previously required skilled operators and extended timelines, they gain a structural advantage over defenders who still rely on human-speed detection and response. Organizations must now assume that threat actors are using AI capabilities and adjust their security architectures accordingly—particularly around cloud infrastructure, supply chain dependencies, and AI development tooling that may introduce new attack surfaces.
John Hultquist, chief analyst at Google Threat Intelligence Group, said the working assumption is now that every threat actor is using AI in some capacity and deriving benefit from it. Speed is the primary concern. "Criminals, like the ones who conducted a mass exploitation campaign in just six hours, will gravitate to attacks that are faster than we can respond to," he stated. Groups like TeamPCP represent a newer threat category, targeting AI systems as they become embedded in enterprise infrastructure rather than simply using AI as a tool.
These findings were first reported by Google Threat Intelligence Group in their quarterly adversarial AI report.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call