‘We can assume that all threat actors are using AI in some capacity’: Google cyber researchers warn hackers are ramping up automated attacks
Google Threat Intelligence Group has issued a warning over the increased threats posed by hackers using agentic AI tools
Attackers used AI agents to compromise a cloud resource and then plan, build, and carry out a mass credential harvesting campaign earlier this year – and all in less than six hours.
That’s according to new research from Google Threat Intelligence Group (GTIG), with recent analysis showing threat actors are flocking to agentic AI and automation to conduct sophisticated attacks.
“At this point, we can assume that all threat actors are using AI in some capacity and their operations have benefited," said John Hultquist, chief analyst at Google Threat Intelligence Group.
"Like everyone else, we’re concerned about the vulnerability problem, but AI is being applied to several other areas, and it will be especially challenging as it is applied agentically, creating a scaled, faster adversary. Criminals, like the ones who conducted a mass exploitation campaign in just six hours, will gravitate to attacks that are faster than we can respond to."
In this example, a financially motivated threat actor compromised an organization’s cloud infrastructure to deploy an autonomous, multi-agent attack framework, allowing them to operate at the sort of scale and speed that's usually associated with larger and more resource-heavy groups.
In less than six hours, the attacker was able to leverage an AI coding chatbot, a simple prompt, and a set of agent instructions to plan, build, and execute a mass credential harvesting campaign.
Using preconfigured markdown instruction sets as operational playbooks, GTIG said the threat actor carried out automated scanning and credential harvesting, compromising thousands of third-party credentials.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
The agent instructions enabled the AI to autonomously manage the vulnerability scanning pipeline, perform real-time troubleshooting, and execute IP rotation logic without manual intervention.
Operating from the victim cloud infrastructure also allowed the threat actor route attack traffic through legitimate IP addresses.
State-backed groups are flocking to AI
GTIG said it has observed state-linked groups broadening their use of AI. In one example, PRC-nexus threat actor UNC6508 carried out a major intrusion campaign against US medical facilities, using compromised cloud environments to host a local model.
In April, meanwhile, Mandiant spotted a threat actor leveraging AI infrastructure access which was then used to sustain unauthorized AI workloads, utilizing hijacked cloud environments to provision high-performance GPU compute instances at the victim's expense.
Notably, TeamPCP has focused heavily on the AI supply chain, using malware designed to take advantage of emerging AI systems, and including malicious prompts that were used to execute commands surreptitiously.
The group has even poisoned open source package metadata to trick AI assistants, resulting in malicious dependencies being recommended to developers.
"The challenge for defenders is that these risks are evolving faster than many organizations can quantify, measure, and govern," said Ronald Lewis, head of cybersecurity governance at Black Duck.
"Security teams are no longer protecting only applications, users, and infrastructure. They must now secure AI models, agents, prompts, data pipelines, and an increasingly complex AI supply chain while also defending against adversaries using AI to accelerate attacks.”
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Trust your AI agents? New research shows ‘memory poisoning’ can dupe them into ‘remembering’ fake information – and it’s a huge security riskNews Memory poisoning allows hidden text on a webpage to be treated as fact and used to make harmful decisions
-
An ‘unprecedented cyber incident’: How OpenAI models breached Hugging Face – and why it could herald a ‘new phase of AI-powered cyber crime’News The incident should serve as a stark warning on the dangers of AI agents, according to cyber experts
-
Google says AI is now being used to build zero-days – and we just narrowly avoided a 'mass exploitation event'News Google cyber researchers think they’ve found the first AI-generated zero-day exploit
-
Five Eyes agencies sound alarm over risky agentic AI deploymentsNews Security agencies have urged organizations to establish clear boundaries and guardrails for AI agents
-
Enterprises are adopting agents faster than they can secure and govern them – experts warn it’s a disaster waiting to happenNews Identity systems developed for human interaction fail to cope with the new demands
-
UK firms left in the dark over what workers are sharing with AINews Security teams can’t keep track of what workers are sharing with AI applications, regardless of whether they’re approved or unauthorized
-
'The goal for this year will be to automate all security processes': Google Cloud is betting on Wiz to usher in a new era of AI securityNews Wiz wants to deploy its agents for continuous penetration testing, and in Google it’s found a parent company that can achieve this vision at scale
-
AI is now a ‘standard part of the attacker toolkit’News Cyber attacks are increasing in scale, intensity, and velocity thanks to AI, and it’s forcing defenders to react faster than ever before

