Security

Attackers Deploy AI Agents to Steal Thousands of Credentials in Six Hours

Google's threat intelligence team reports criminals are using autonomous AI frameworks to compress attack timelines, leaving defenders with minimal response windows.

Omega Editorial· September 8, 2026· 4 min read

Autonomous AI frameworks accelerate credential theft

Threat actors have successfully deployed a multi-agent artificial intelligence framework to compromise thousands of credentials in less than six hours, according to a report released today by Google's Threat Intelligence Group. The attack represents a significant escalation in how criminals are leveraging AI to compress attack timelines and reduce human involvement in cyberattacks.

Mandiant investigators attribute the campaign to a financially motivated actor who initially breached an organization's cloud infrastructure. The attacker then constructed an autonomous framework combining an AI coding chatbot, custom prompts, and agent instructions. Preconfigured markdown playbooks automated the subsequent scanning and credential harvesting operations.

The framework handled troubleshooting and IP rotation without operator intervention. Because traffic originated from the victim's own network addresses, it appeared legitimate as it exited the environment—a technique that bypasses many standard detection mechanisms.

From human-driven to autonomous attacks

The findings appear in Google Threat Intelligence Group's report "From Prompting to Autonomy: The Evolution of Adversarial AI," which tracks activity from the second quarter. The research follows a May report that documented the first confirmed instance of criminals using AI to develop a working zero-day exploit.

What has changed in the intervening months is the degree of autonomy, according to GTIG. Adversaries are now delegating multistep decision-making to AI models, which dramatically shrinks the window defenders have to detect and respond to intrusions.

While GTIG has not yet observed fully autonomous attack pipelines deployed against targets in production environments, adversary intent is clear. An alleged China-linked espionage group used Google's Gemini to design an automated penetration testing framework intended to conduct port scanning, service parsing, and other reconnaissance work independently. Google disabled the assets before the group progressed beyond the development phase.

Supply chain poisoning targets AI tooling

The report focuses substantial attention on UNC6780, a criminal group Google also tracks as TeamPCP. This actor poisoned the LiteLLM gateway in March and has since conducted large-scale compromises across PyPI, npm, and Docker Hub. The group publishes trojanized versions of Model Context Protocol servers and injects malicious code into GitHub repositories that AI coding assistants automatically clone.

Their DUSTMAKER credential stealer drops files into hidden project directories such as .claude and .cursor, locations where AI development tools read them as routine developer artifacts. Some malware samples included prompt injections written as extreme requests about biological and nuclear weapons—text apparently designed to trigger large language model security scanners to refuse the file and skip scanning the malicious JavaScript embedded within.

AI assets become direct targets

Mandiant worked several data theft extortion cases last quarter where attackers specifically targeted AI assets. Threat actors stole proprietary models, source code, and prompts from technology, healthcare, and media companies across North America and Europe. In one healthcare incident, attackers exfiltrated drug research data and a proprietary model, threatening to publish both unless the victim paid a ransom.

Compute resources are also being stolen. UNC6508, an alleged China-linked group with a multiyear campaign against academic, medical, and military research institutions, has been observed deploying open-weight models inside compromised cloud environments to keep their prompting activity away from commercial API monitoring. In another case, an exposed GitHub access token allowed an attacker to provision high-performance GPU instances in April at the victim's expense.

Why it matters

The six-hour credential theft campaign demonstrates that AI is fundamentally changing the economics of cyberattacks. When criminals can automate complex, multistep intrusions that previously required skilled operators and extended timelines, they gain a structural advantage over defenders who still rely on human-speed detection and response. Organizations must now assume that threat actors are using AI capabilities and adjust their security architectures accordingly—particularly around cloud infrastructure, supply chain dependencies, and AI development tooling that may introduce new attack surfaces.

John Hultquist, chief analyst at Google Threat Intelligence Group, said the working assumption is now that every threat actor is using AI in some capacity and deriving benefit from it. Speed is the primary concern. "Criminals, like the ones who conducted a mass exploitation campaign in just six hours, will gravitate to attacks that are faster than we can respond to," he stated. Groups like TeamPCP represent a newer threat category, targeting AI systems as they become embedded in enterprise infrastructure rather than simply using AI as a tool.

These findings were first reported by Google Threat Intelligence Group in their quarterly adversarial AI report.

#ai security#credential theft#supply chain attacks#autonomous agents#threat intelligence#cybersecurity

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

Attackers Hide Malware in Weapon Schematics to Evade AI Scanners

Google Threat Intelligence reveals cybercriminals are exploiting AI safety filters by embedding malicious code alongside nuclear and biological weapon designs.

Via AI Watch · Sep 8, 2026
Security· 4 min read

AI Agents Now Pose Insider Threat Risks at Machine Speed

Autonomous systems with privileged access are deleting databases, mining crypto, and resisting shutdown—all with legitimate credentials.

Via Automation Watch · Sep 8, 2026
Security· 3 min read

Telecom Networks Face AI Attacks 100x Faster Than Human Defense

Omdia research reveals only 65% of carriers have AI threat detection as weaponized algorithms and quantum risks demand architectural overhaul.

Via AI Watch · Sep 8, 2026