AI Agents Engineering: AI-агенти на Google ADK 2.0 + Go SDK ➡️

Hackers are creating AI frameworks for mass credential theft

Attackers are increasingly abandoning simple AI-based coding assistants in favor of multi-agent frameworks that can fully automate every stage of a cyberattack.

Leave a comment
Hackers are creating AI frameworks for mass credential theft

Attackers are increasingly abandoning simple AI-based coding assistants in favor of multi-agent frameworks that can fully automate every stage of a cyberattack.

According to a new report from the Google Threat Intelligence Group (GTIG), which relies on data from Mandiant, hackers have begun using AI agents to coordinate tasks, self-correct errors, and adapt actions with minimal human involvement, BleepingComputer reports .

“Over the past quarter, attackers have moved beyond simple LLM prompts and begun integrating AI into various stages of the attack cycle. They are creating highly autonomous systems capable of analyzing complex tasks and making dynamic decisions without human control,” GTIG notes.

Massive attacks in a matter of hours

In one documented incident, hackers compromised an organization’s cloud infrastructure and launched an autonomous multi-agent framework. In less than six hours, they planned and launched a massive credential harvesting campaign using an AI chatbot, a single prompt, and Markdown instructions.

AI agents independently managed vulnerability scans, stole thousands of third-party passwords, remediated outages in real time, changed IP addresses, and rerouted traffic through other compromised cloud environments to bypass protections, critically reducing the time cybersecurity professionals typically had to respond.

In another investigation, researchers discovered a command and control server with an automated Recon system. This framework managed over 23,800 stolen secrets, including API keys, in real time.

Source: BleepingComputer

Espionage and state hackers

GTIG also noted the use of AI by state-sponsored groups:

  • Chinese cyberspies experimented with AI tools to create pipelines for automated exploitation of vulnerabilities;

  • the Russian group UNC5792 integrated AI models into bots to automatically monitor Telegram channels and search for information needed by the government;

  • The UNC6780 (TeamPCP) group used AI in compromised supply chains.

In addition, cases of distillation of the Gemini AI model through over 100 million prompts have been recorded, and demand for stolen AI service accounts and API keys is growing on the shadow market.

Current situation and countermeasures

Despite the rapid development of technology, Google emphasizes that fully autonomous hacking has not yet become a mass phenomenon. Researchers have not yet observed large-scale fully autonomous systems searching for 0-day vulnerabilities or building attack chains against real targets.

Additionally, the company's proprietary model, Gemini, detected most abuse attempts early and responded according to security protocols, allowing Google to block linked accounts and stop the attackers' campaigns in a timely manner.

Hacker used AI agents for the entire attack chain, then mocked the victim company by leaving behind an 80-page security audit
Hacker used AI agents for the entire attack chain, then mocked the victim company, leaving behind an 80-page security audit
On the topic
Hacker used AI agents for the entire attack chain, then mocked the victim company, leaving behind an 80-page security audit
Cursor helped Russian hackers hack 7 companies under the guise of simulation
Cursor helped Russian hackers hack 7 companies under the guise of simulation
On the topic
Cursor helped Russian hackers hack 7 companies under the guise of simulation
Chinese hackers launched a fully autonomous AI cyberattack against Taiwan. Why it surprised even seasoned cyber experts
Chinese hackers launched a fully autonomous AI cyberattack against Taiwan. Why it surprised even seasoned cyber experts
On the topic
Chinese hackers launched a fully autonomous AI cyberattack against Taiwan. Why it surprised even seasoned cyber experts
Chinese hacker used DeepSeek via Telegram for autonomous cyberattacks
Chinese hacker used DeepSeek via Telegram for autonomous cyberattacks
On the topic
Chinese hacker used DeepSeek via Telegram for autonomous cyberattacks
Read the country's main IT news in our Telegram
Read the country's main IT news in our Telegram
On the topic
Read the country's main IT news in our Telegram
Also Read
Roosh запускає нову освітню платформу AI HOUSE CLUB для ML/AI-спеціалістів та дата сайнтистів. Розповідаємо, як подати заявку та чому навчатимуть
Roosh запускає нову освітню платформу AI HOUSE CLUB для ML/AI-спеціалістів та дата сайнтистів. Розповідаємо, як подати заявку та чому навчатимуть
Roosh запускає нову освітню платформу AI HOUSE CLUB для ML/AI-спеціалістів та дата сайнтистів. Розповідаємо, як подати заявку та чому навчатимуть
Як нейромережі бачать вільну та незалежну Україну? Тест dev.ua
Як нейромережі бачать вільну та незалежну Україну? Тест dev.ua
Як нейромережі бачать вільну та незалежну Україну? Тест dev.ua
Нейронні мережі для генерації зображень бачать світ по-своєму, їхню логіку зрозуміти часом зовсім неможливо. Але таки хочеться. На честь Дня Незалежності України редакція dev.ua вирішила провести невеликий експеримент. Ми задали чотирьом різним нейронним мережам п’ять однакових запитів: «прапор України», «День Незалежності України», «український Крим», «перемога України» та «українці». Отриманими результатами ми ділимося з вами нижче.
У TikTok тепер можна генерувати фон за допомогою нейромережі. Ми протестували її та ділимося результатами
У TikTok тепер можна генерувати фон за допомогою нейромережі. Ми протестували її та ділимося результатами
У TikTok тепер можна генерувати фон за допомогою нейромережі. Ми протестували її та ділимося результатами
У TikTok з’явилася нова функція «Розумний фон». З її допомогою як фон для тіктоків можна підставляти згенеровані нейромережею зображення. Редакція dev.ua протестувала цю технологію і ділиться своїми враженнями.
1 comment
Які IT-спеціальності будуть потрібні в найближчі п'ять років? Ми з'ясували у голови американського стартапу ADAM Дениса Гурака
Які IT-спеціальності будуть потрібні в найближчі п'ять років? Ми з'ясували у голови американського стартапу ADAM Дениса Гурака
Які IT-спеціальності будуть потрібні в найближчі п'ять років? Ми з'ясували у голови американського стартапу ADAM Дениса Гурака

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.