Chinese Hackers Are Putting AI On Networks They Breach. Google Says It Helps Them Stay Hidden Google Threat Intelligence Group reported that Chinese hackers are installing open-source AI models on compromised cloud networks to evade detection, with one China-linked group using AI development tools to build an exploitation pipeline that switches among Claude, Gemini, and Codex. In a second-quarter case, attackers used autonomous agents to execute a mass credential-harvesting campaign in under six hours, organizing over 23,800 stolen secrets. John Hultquist, chief analyst at Google's Threat Intelligence Group, said attackers compromise third parties to run models locally, avoiding commercial services where their activities are observed. Chinese Hackers Are Putting AI On Networks They Breach. Google Says It Helps Them Stay Hidden Google said some threat actors are moving beyond basic chatbot prompts and building automated systems that can carry out large parts of an intrusion with less human involvement. Hackers linked to China https://www.ibtimes.com/topic/china are installing artificial-intelligence https://www.ibtimes.com/social-tags/artificial-intelligence models on compromised cloud networks, allowing them to use the technology while making their activity harder to detect as AI becomes more deeply integrated into cyber operations, Google https://www.ibtimes.com/company/google researchers said. The Google Threat Intelligence Group https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai?utm source=chatgpt.com said in a report that sophisticated threat actors are moving beyond using AI for individual tasks such as writing code or researching targets. Some groups are building systems capable of automating several stages of an attack with substantially less human involvement. In one case during the second quarter, attackers compromised a cloud resource and planned, built and executed an AI-assisted mass credential-harvesting campaign in less than six hours. The attackers used autonomous agents to research vulnerabilities, scan infrastructure and carry out targeted exploits, while a dashboard was used to organize more than 23,800 stolen secrets, including API keys for cloud and AI services. Chinese cyberespionage groups were among those testing more automated operations. One China-linked group used AI development tools to build an exploitation and post-exploitation pipeline that could switch among models including Claude, Gemini and Codex to write exploit scripts, create phishing material and debug errors. Another China-linked group compromised third-party cloud environments and installed open-source AI models directly on the stolen infrastructure. Running models this way can help attackers avoid the monitoring and safeguards attached to commercial AI services, John Hultquist, chief analyst at Google's Threat Intelligence Group, told NBC News https://www.nbcnews.com/tech/security/chinese-hackers-are-running-ai-stolen-networks-avoid-detection-google-rcna596155 . "They compromise a third party and they put models on that third party," Hultquist said. "They do that instead of using, say, a commercial option where their activities are observed." Chinese hackers are also targeting AI technology itself. A group known as UNC6508 has pursued proprietary AI research during a multiyear espionage campaign against academic, medical and military research institutions in North America. A separate GTIG investigation published in June https://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-research?utm source=chatgpt.com found that UNC6508 remained undetected in some environments for more than a year while targeting research involving AI, national defense, cyber operations, uncrewed vehicle systems and medicine. Researchers also observed suspected UNC6508 activity in which compromised cloud environments were used to deploy local large-language-model infrastructure. China has rejected the broader hacking allegations, with Liu Chang, a spokesperson for the Chinese Embassy in Washington, telling NBC News that the country opposes hacking and fights such activity under its laws. He also rejected what he called "vilification and smears under the pretext of cybersecurity." Google had already documented growing interest among China- and North Korea-linked groups in using AI for vulnerability discovery in a May assessment of adversarial AI use https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access/?utm source=chatgpt.com . Researchers also identified a criminal threat actor using a zero-day exploit that they believed had been developed with AI. Despite the increased automation, researchers have not seen threat actors deploy completely autonomous attack pipelines against real-world targets. Human operators remain involved in campaigns even as more individual tasks are handed to AI. Hultquist told the outlet that researchers had seen attackers trying to develop systems that could remove people from some important stages of an operation. The activity observed so far shows hackers progressively automating parts of their work rather than handing entire campaigns over to AI. © Copyright IBTimes 2026. All rights reserved.