Cybercriminals are moving beyond simple AI coding tools. Instead, they are building multi-agent systems that can automate large parts of an attack with little human supervision.
Google’s Threat Intelligence Group observed AI agents coordinating attacks, solving technical problems, and adapting their actions in real time. Some systems also scanned for vulnerabilities and collected thousands of stolen credentials.
AI agents automate entire attack workflows
Threat actors previously used large language models mainly to write scripts, create phishing messages, or troubleshoot malware. However, Google says attackers now integrate AI into several stages of the attack lifecycle.
These frameworks divide work between multiple AI agents. Each agent handles a specific task, such as scanning systems, managing stolen credentials, or changing network infrastructure.
As a result, attackers can react quickly when something fails. The agents can adjust their methods without waiting for detailed instructions from a human operator.
Traditional automation has supported cyberattacks for years. Yet these newer frameworks can make decisions, coordinate tasks, and respond to changing conditions.
Campaign launched in less than six hours
During one incident, a financially motivated attacker compromised an organization’s cloud infrastructure. The attacker then deployed an autonomous multi-agent framework inside the environment.
According to Google, the threat actor planned, created, and launched a mass credential-harvesting campaign in under six hours.
The attacker used an AI coding chatbot, a single prompt, and instructions written in Markdown. After deployment, the agents managed the campaign with limited human input.
They scanned for vulnerabilities, collected thousands of third-party credentials, and fixed operational problems as they appeared. Moreover, the agents rotated IP addresses to make detection more difficult.
The framework also routed malicious traffic through legitimate but compromised cloud environments. This helped the operation blend in with normal activity.
Consequently, defenders had less time to identify and stop the attack.
Recon framework managed thousands of secrets
Google researchers also discovered an exposed command-and-control server running an automated framework called Recon.
The server contained instructions for AI agents, knowledge files, and other components used to manage the operation. At the time of discovery, Recon handled more than 23,800 stolen secrets in real time.
These included API keys and other credentials that could provide access to online services and cloud environments.
The discovery shows how attackers can use AI credential theft systems to organize large volumes of stolen information. Furthermore, the frameworks can process and distribute the data much faster than a human operator.
State-backed hackers experiment with AI
Cyberespionage groups are also testing more advanced AI capabilities.
Google observed China-linked actors using AI-assisted development tools to create automated exploitation and post-exploitation pipelines. These systems could help attackers gain initial access and continue operating inside compromised networks.
Meanwhile, the Russia-based group UNC5792 reportedly integrated AI models into bots that monitor Telegram channels. The bots automatically search for information that may interest the Russian government.
State-backed groups continue to use AI for reconnaissance, phishing, malware development, exploitation, data analysis, and propaganda.
However, fully autonomous hacking has not yet become common. Google found no evidence that attackers widely use independent AI pipelines to discover zero-day vulnerabilities and exploit real-world networks.
Google disrupted several AI-enabled campaigns
Google said its Gemini AI model detected many abuse attempts at an early stage. Its safety systems responded automatically, which allowed the company to investigate further.
Google then disrupted several campaigns and banned the accounts connected to them.
Researchers have also observed AI abuse in supply-chain attacks and large-scale attempts to copy Gemini’s capabilities. In one operation, attackers reportedly used approximately 100 million prompts.
At the same time, criminals are creating a growing market for stolen AI accounts and API keys.
These developments suggest that AI will play a larger role in cybercrime. While fully autonomous attacks remain uncommon, multi-agent frameworks already allow hackers to operate faster and at a much greater scale.


0 responses to “Hackers Build AI Frameworks for Widescale Credential Theftg”