Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
Threat actors are increasingly leveraging artificial intelligence to automate and scale cyberattacks, with a recent campaign demonstrating an attacker's ability to autonomously harvest thousands of credentials in under six hours using an AI-assisted framework. Google Threat Intelligence Group (GTIG) observed a China-nexus threat actor utilizing AI coding chatbots and agent instructions to conduct mass credential harvesting, alongside other groups leveraging AI for exploit development, reconnaissance, and social engineering across various countries. The rise of open-weight AI models is exacerbating these risks by democratizing access and enabling unmonitored deployments, requiring industry-wide safety baselines and platform policies to mitigate the growing threat.
Threat actors are increasingly utilizing artificial intelligence to streamline and amplify their operations, with a recent campaign demonstrating an attacker's ability to autonomously harvest thousands of credentials in under six hours using an AI-assisted framework. Google Threat Intelligence Group (GTIG) has observed a China-nexus threat actor employing an AI coding chatbot, a prompt, and a set of agent instructions to conduct a mass credential harvesting operation, bypassing traditional security measures. This highlights a growing trend of AI-powered automation in cyberattacks.
Several other threat actors are also leveraging AI in diverse ways. The China-nexus group known as UNC6508 compromised a cloud environment to deploy local LLM infrastructure, bypassing monitoring by commercial AI model providers. Groups like UNC6508, Basin Castle (aka Mustang Panda), Ravine Castle (aka APT24, COULEE, and Pitty Tiger), and Calanque Ion (aka APT42) have used LLMs for exploit development, reconnaissance, social engineering, and intelligence gathering, targeting government entities and conducting influence operations.
Threat actors are also utilizing AI to augment their malware development and toolset creation. The Russia-based group UNC5792 has integrated AI models to sift through Telegram channels for specific information of interest to Russian authorities, while Midnight Neptune (aka UNC1069) has used commercial and open-weight LLMs for social engineering and backdoor development. Groups like Sandworm (aka APT44 and Sandworm Relic) and UNC6240 (aka ShinyHunters) have used AI to bypass Cloudflare security guardrails and analyze exfiltrated directories for extortion.
The rise of open-weight AI models is a key factor driving these advancements. While commercial AI labs restrict access to their most powerful models, open-weight models are becoming increasingly accessible, allowing threat actors to deploy local, unmonitored versions without centralized defender visibility. This democratization of access is fueling innovation but also significantly increasing the risk of AI-enabled cyberattacks.
Google formalized its Frontier Safety Framework and Critical Capability Levels (CCLs) to evaluate model capabilities and determine when open deployment poses unacceptable security risks. The group emphasizes that simply gating access is impractical, and enterprise platforms like Gemini Enterprise provide a contained, safe environment for businesses to leverage open-source models securely. Mitigating these threats requires establishing enforceable, industry-wide safety baselines specifically for open-source AI, alongside coordinated platform policies to restrict uncensored checkpoints and raise the barrier to entry for adversaries.
