Six Hours, Thousands of Credentials, and Zero Surprise

Six hours. That's how long it took an autonomous agent setup to scan, harvest, and exfiltrate thousands of credentials, according to Google's Threat Intelligence Group. Not six weeks. Not six days. Six hours, with a human basically pressing "go" and checking back later.

Where this fits

This isn't a new attack technique wearing an AI costume. Credential harvesting, third-party token abuse, automated scanning against exposed endpoints, all of that is old-school opportunistic crime. What's changed is the labor cost of running the operation. A financially motivated actor took an AI coding chatbot, handed it preconfigured agentic instructions, and let it do the grunt work that used to require either a skilled operator babysitting scripts or a botnet-for-hire.

The other two pieces in the report matter just as much, arguably more, even though they're getting less headline space. DUSTMAKER used prompt injection against AI coding assistants specifically for defense evasion. That's a shift from "AI helps attackers write malware" to "AI assistants are now part of the attack surface being manipulated mid-operation." And nation-state groups are apparently using the same mainstream coding assistants for exploit dev, phishing content, and recon. Not bespoke offensive tooling. The same chatbots developers use to unstick a regex.