Hackers Deploy Autonomous AI Agents for Six-Hour Attack Blitz
Google researchers document financially motivated group using multi-agent framework to harvest thousands of credentials at machine speed.

Autonomous AI systems accelerate credential theft
Threat actors have crossed a significant threshold in offensive automation, according to new research from Google Threat Intelligence Group. The company documented a financially motivated attacker who deployed an autonomous, multi-agent AI framework to execute a mass credential harvesting operation in under six hours—compromising thousands of third-party credentials without continuous human oversight.
The attacker compromised cloud infrastructure and used an AI coding chatbot with preconfigured instruction sets as operational playbooks. The system autonomously managed vulnerability scanning, conducted real-time troubleshooting, and executed IP rotation logic to evade detection. This represents a fundamental shift from AI-assisted attacks to fully autonomous offensive operations running at machine speed.
"At this point, we can assume that all threat actors are using AI in some capacity and their operations have benefited," John Hultquist, chief analyst at GTIG, told The Hacker News. "Criminals, like the ones who conducted a mass exploitation campaign in just six hours, will gravitate to attacks that are faster than we can respond to."
Supply chain compromises target AI development tools
Google identified TeamPCP (also tracked as Altered Spider and UNC6780) as a financially motivated actor conducting large-scale software supply chain attacks against PyPI, npm, and Docker Hub. The group deploys credential stealers including SANDCLOCK and DUSTMAKER specifically designed to target AI coding assistants and developer credentials.
DUSTMAKER, the successor to SANDCLOCK, is a cross-platform JavaScript payload optimized for CI/CD pipelines. Unlike its predecessor, DUSTMAKER incorporates AI-specific attack techniques including poisoning of AI assistant workspaces and prompt injection for defense evasion. Stolen credentials are monetized through direct sale or partnerships with ransomware and data extortion groups.
Nation-state actors adopt AI for espionage operations
Google documented widespread AI adoption across nation-state threat groups. China-nexus actors including Basin Castle (Mustang Panda) and Ravine Castle (APT24) use large language models for intelligence gathering, exploit development, and troubleshooting errors during active intrusions. Russia's Sandworm group employs Gemini for intelligence collection and social engineering in operations targeting Ukraine.
One China-aligned espionage group is developing an agentic penetration testing framework using Gemini, designed to observe target state, reason through actions, and execute tasks autonomously in unpredictable environments. The planned agent would perform discovery tasks including port scanning and service parsing without human intervention.
Another China-nexus actor, UNC6508, compromised cloud environments to deploy local LLM infrastructure using open-weight models rather than commercial services, evading monitoring by AI providers.
Why it matters
The shift from AI-assisted to fully autonomous attack frameworks fundamentally changes the defender's calculus. When attackers can execute complex operations in six hours that previously required days or weeks, traditional detection and response timelines become inadequate. Organizations must assume adversaries are already operating AI systems that work continuously, troubleshoot independently, and adapt faster than human security teams can respond. This creates an asymmetric advantage that will only widen as open-weight models improve and agentic frameworks mature.
Open-weight models create monitoring gaps
Google noted that while commercial AI providers can monitor API usage for misuse, open-weight models enable local, unmonitored deployments without safety guardrails. "Abliterated" or uncensored model variants circulating underground eliminate content restrictions entirely.
"Open-weight models present an increasing risk by democratizing access and enabling local, unmonitored deployments that lack safety guardrails," GTIG told The Hacker News. The company called for enforceable industry-wide safety baselines for open-source AI and coordinated platform policies to restrict uncensored model checkpoints.
Google also documented threat actors stealing AI credentials via information stealer malware including Lumma Stealer, Vidar, and ACR Stealer, which have expanded capabilities to target AI developer configurations. Attackers are purchasing bulk LLM API access using hijacked accounts and exfiltrating proprietary AI models, training data, and research from healthcare, government, and media organizations.
These findings were first reported by The Hacker News based on research from Google Threat Intelligence Group.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call