cd /news/artificial-intelligence/google-says-attackers-used-ai-agents… · home topics artificial-intelligence article
[ARTICLE · art-123298] src=siliconangle.com ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

Google says attackers used AI agents to steal credentials in under six hours

Google LLC's Google Threat Intelligence Group reported that threat actors used a multi-agent AI framework to steal thousands of credentials in under six hours, marking a shift to more autonomous cyberattacks. The campaign, traced to a financially motivated actor, involved an AI coding chatbot and preconfigured playbooks that ran without operator intervention, according to a report released today. Google also detailed supply-chain attacks by group UNC6780 and noted that AI assets and compute are increasingly targeted by adversaries.

read4 min views4 publishedSep 8, 2026
Google says attackers used AI agents to steal credentials in under six hours
Image: Siliconangle (auto-discovered)

Google says attackers used AI agents to steal credentials in under six hours

Threat actors used a multi-agent artificial intelligence framework to compromise thousands of credentials in under six hours, Google LLC’s Google Threat Intelligence Group said in a report released today.

Mandiant investigators traced the campaign to a suspected financially motivated actor that first broke into an organization’s cloud infrastructure. The attacker then assembled an autonomous framework out of an AI coding chatbot, a prompt and a set of agent instructions, with preconfigured markdown playbooks driving the scanning and harvesting that followed.

Troubleshooting and IP rotation ran without an operator. Traffic left the victim’s own addresses, so it looked legitimate on the way out.

The report, “From Prompting to Autonomy: The Evolution of Adversarial AI,” covers activity GTIG tracked over the second quarter. It follows the May edition, which documented the first confirmed case of criminals using AI to build a working zero-day exploit. What has changed since then is how little human involvement is left, GTIG said. Adversaries are handing multistep decisions to models, which shrinks the window defenders have to react.

GTIG said it has not observed fully autonomous attack pipelines deployed against targets in the wild. Adversary intent is not in doubt. An alleged China-linked espionage group used Gemini to design an automated penetration testing framework meant to run port scanning, service parsing and other early intrusion work by itself. The group got no further than trying to build it, and Google disabled the assets tied to the effort.

On the open-source supply chain, the report’s main subject is a criminal group Google labels UNC6780. The same actor, which Google also tracks as TeamPCP, poisoned the LiteLLM gateway in March.

Since then, it has run large-scale compromises across PyPI, npm and Docker Hub, publishing trojanized forks of Model Context Protocol servers and injecting malicious code into GitHub repositories that AI coding assistants clone. Its DUSTMAKER credential stealer drops files into hidden project directories such as .claude and .cursor, where AI tooling reads them as ordinary developer clutter.

Some samples went further. Malware s carried prompt injections written as extreme requests about biological and nuclear weapons, text likely intended to make large language model security scanners refuse the file and skip the malicious JavaScript beneath it.

AI assets themselves are now a target. Mandiant worked several data theft extortion cases last quarter in which attackers took proprietary models, source code and prompts from technology, healthcare and media companies in North America and Europe. One healthcare victim lost drug research and a proprietary model to a group that threatened to publish both unless it was paid.

Compute is being stolen the same way. UNC6508, an alleged China-linked group tied to a multiyear campaign against academic, medical and military research institutions, is also behind suspected activity GTIG observed deploying open-weight models inside compromised cloud environments, keeping its prompting away from commercial application programming interface monitoring. An exposed GitHub access token let another attacker provision high-performance graphics processing unit instances in April at a victim’s expense.

John Hultquist, chief analyst at Google Threat Intelligence Group, said the working assumption now is that every threat actor is using AI in some capacity and benefiting from it. Speed is what worries him most.

“Criminals, like the ones who conducted a mass exploitation campaign in just six hours, will gravitate to attacks that are faster than we can respond to,” he said. Groups such as TeamPCP are a newer category, he added, going after AI systems as they get built into the enterprise stack rather than simply using them.

Image: SiliconANGLE/GPT Image 2

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos , powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network

Are you an AWS customer?  Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/

About SiliconANGLE Media

SiliconANGLE,

theCUBE Network,

theCUBE Research,

CUBE365,

theCUBE AIand theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @google llc 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/google-says-attacker…] indexed:0 read:4min 2026-09-08 ·