Hackers are creating AI frameworks for mass credential theft
Attackers are increasingly abandoning simple AI-based coding assistants in favor of multi-agent frameworks that can fully automate every stage of a cyberattack.
Attackers are increasingly abandoning simple AI-based coding assistants in favor of multi-agent frameworks that can fully automate every stage of a cyberattack.
Attackers are increasingly abandoning simple AI-based coding assistants in favor of multi-agent frameworks that can fully automate every stage of a cyberattack.
According to a new report from the Google Threat Intelligence Group (GTIG), which relies on data from Mandiant, hackers have begun using AI agents to coordinate tasks, self-correct errors, and adapt actions with minimal human involvement, BleepingComputer reports .
“Over the past quarter, attackers have moved beyond simple LLM prompts and begun integrating AI into various stages of the attack cycle. They are creating highly autonomous systems capable of analyzing complex tasks and making dynamic decisions without human control,” GTIG notes.
In one documented incident, hackers compromised an organization’s cloud infrastructure and launched an autonomous multi-agent framework. In less than six hours, they planned and launched a massive credential harvesting campaign using an AI chatbot, a single prompt, and Markdown instructions.
AI agents independently managed vulnerability scans, stole thousands of third-party passwords, remediated outages in real time, changed IP addresses, and rerouted traffic through other compromised cloud environments to bypass protections, critically reducing the time cybersecurity professionals typically had to respond.
In another investigation, researchers discovered a command and control server with an automated Recon system. This framework managed over 23,800 stolen secrets, including API keys, in real time.

GTIG also noted the use of AI by state-sponsored groups:
Chinese cyberspies experimented with AI tools to create pipelines for automated exploitation of vulnerabilities;
the Russian group UNC5792 integrated AI models into bots to automatically monitor Telegram channels and search for information needed by the government;
The UNC6780 (TeamPCP) group used AI in compromised supply chains.
In addition, cases of distillation of the Gemini AI model through over 100 million prompts have been recorded, and demand for stolen AI service accounts and API keys is growing on the shadow market.
Despite the rapid development of technology, Google emphasizes that fully autonomous hacking has not yet become a mass phenomenon. Researchers have not yet observed large-scale fully autonomous systems searching for 0-day vulnerabilities or building attack chains against real targets.
Additionally, the company's proprietary model, Gemini, detected most abuse attempts early and responded according to security protocols, allowing Google to block linked accounts and stop the attackers' campaigns in a timely manner.




