Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack.
Drawing on telemetry from Mandiant's incident response engagements, threat actor tracking, and live platform defenses, the Google Threat Intelligence Group (GTIG) observed AI agents coordinating multiple attack tasks, troubleshooting failures, and adapting their actions with minimal human intervention.
“Over the past quarter, threat actors have moved beyond simple prompt-based LLM interactions to integrate AI capabilities into multiple stages of an attack lifecycle,” GTIG notes.
“While traditional script-based automation has long been a staple of threat actor operations, groups are increasingly upgrading these workflows, creating highly autonomous systems capable of reasoning through complex tasks and making dynamic decisions without the need for human oversight.”
In one such incident, a financially motivated attacker compromised an organization’s cloud infrastructure and deployed an autonomous multi-agent framework.










