Hackers Backed by China, Russia, Iran Deploy AI Agents in Attacks
Google researchers document nation-state threat actors moving from basic chatbots to autonomous AI systems that execute complex cyberattacks without human oversight.

Nation-state hackers are rapidly advancing their use of artificial intelligence, shifting from simple chatbot queries to deploying autonomous AI agents capable of executing sophisticated cyberattacks with minimal human intervention, according to a new report from Google's threat intelligence division.
The Google Threat Intelligence Group documented multiple cases where adversaries linked to China, Russia, and Iran have integrated AI capabilities across entire attack lifecycles. Rather than relying on basic prompt-based interactions with language models, these threat actors are now building highly autonomous systems that can reason through complex tasks and make dynamic decisions independently.
Advanced tactics from state-backed groups
One particularly concerning operation involves a group designated UNC6508, which Google researchers first identified earlier this year. This group has been targeting American academic, medical, and military research institutions in ways that align with Chinese government interests.
According to the report published Tuesday, UNC6508 has been observed deploying open-source AI models within compromised cloud environments. This approach allows the attackers to steal computing resources while avoiding the digital fingerprints that commercial AI services would leave behind. The group continues researching how to operate AI tools locally and is actively investigating vulnerabilities within AI models themselves.
In another documented case, Iranian threat actors used Google's Gemini model to generate photorealistic deepfakes for social engineering campaigns. Rather than manually refining images through repeated prompts, these attackers configured the AI to autonomously define technical parameters including camera angles, studio lighting, and facial textures to produce convincing fake imagery.
Model distillation becomes geopolitical flashpoint
Google's researchers also reported observing coordinated campaigns aimed at distilling its proprietary AI systems—a practice the company considers a terms-of-service violation that could warrant legal action. Distillation involves using outputs from one AI model to train another, typically smaller model.
While distillation has long been standard practice within the AI industry for developing new models, it has recently emerged as a contentious issue in U.S.-China technology competition. American AI developers including OpenAI and Anthropic have accused Chinese competitors of conducting industrial-scale distillation of their frontier models. The White House has pledged to address what it describes as deliberate campaigns to replicate U.S. AI systems.
Why it matters
The same AI capabilities that companies promote for productivity and automation are proving equally valuable to adversaries conducting espionage and cyberattacks. As AI systems become more autonomous and capable of handling complex tasks without constant human direction, they lower the technical barriers for sophisticated attacks while making attribution and defense more challenging. This development underscores a fundamental tension in AI development: features designed to make systems more useful also make them more exploitable by hostile actors.
The findings were first reported by the Google Threat Intelligence Group in a report released Tuesday morning.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call
