Google says attackers used AI agents to steal credentials in under six hours

Threat actors used a multi-agent artificial intelligence framework to compromise thousands of credentials in under six hours, Google LLC’s Google Threat Intelligence Group said in a report released today.

Mandiant investigators traced the campaign to a suspected financially motivated actor that first broke into an organization’s cloud infrastructure. The attacker then assembled an autonomous framework out of an AI coding chatbot, a prompt and a set of agent instructions, with preconfigured markdown playbooks driving the scanning and harvesting that followed.

Troubleshooting and IP rotation ran without an operator. Traffic left the victim’s own addresses, so it looked legitimate on the way out.

The report, “From Prompting to Autonomy: The Evolution of Adversarial AI,” covers activity GTIG tracked over the second quarter. It follows the May edition, which documented the first confirmed case of criminals using AI to build a working zero-day exploit. What has changed since then is how little human involvement is left, GTIG said. Adversaries are handing multistep decisions to models, which shrinks the window defenders have to react.