{"slug": "google-says-attackers-used-ai-agents-to-steal-credentials-in-under-six-hours", "title": "Google says attackers used AI agents to steal credentials in under six hours", "summary": "Google LLC's Google Threat Intelligence Group reported that threat actors used a multi-agent AI framework to steal thousands of credentials in under six hours, marking a shift to more autonomous cyberattacks. The campaign, traced to a financially motivated actor, involved an AI coding chatbot and preconfigured playbooks that ran without operator intervention, according to a report released today. Google also detailed supply-chain attacks by group UNC6780 and noted that AI assets and compute are increasingly targeted by adversaries.", "body_md": "### Google says attackers used AI agents to steal credentials in under six hours\n\nThreat actors used a multi-agent artificial intelligence framework to compromise thousands of credentials in under six hours, Google LLC’s Google Threat Intelligence Group said in a report [released today](https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai).\n\nMandiant investigators traced the campaign to a suspected financially motivated actor that first broke into an organization’s cloud infrastructure. The attacker then assembled an autonomous framework out of an AI coding chatbot, a prompt and a set of agent instructions, with preconfigured markdown playbooks driving the scanning and harvesting that followed.\n\nTroubleshooting and IP rotation ran without an operator. Traffic left the victim’s own addresses, so it looked legitimate on the way out.\n\nThe report, “From Prompting to Autonomy: The Evolution of Adversarial AI,” covers activity GTIG tracked over the second quarter. It follows the [May edition](https://siliconangle.com/2026/05/11/google-says-criminals-used-ai-build-working-zero-day-exploit-first-time), which documented the first confirmed case of criminals using AI to build a working zero-day exploit. What has changed since then is how little human involvement is left, GTIG said. Adversaries are handing multistep decisions to models, which shrinks the window defenders have to react.\n\nGTIG said it has not observed fully autonomous attack pipelines deployed against targets in the wild. Adversary intent is not in doubt. An alleged China-linked espionage group used Gemini to design an automated penetration testing framework meant to run port scanning, service parsing and other early intrusion work by itself. The group got no further than trying to build it, and Google disabled the assets tied to the effort.\n\nOn the open-source supply chain, the report’s main subject is a criminal group Google labels UNC6780. The same actor, which Google also tracks as TeamPCP, poisoned the LiteLLM gateway [in March](https://siliconangle.com/2026/05/18/forcepoint-details-teampcp-supply-chain-attack-turned-litellm-credential-stealer/).\n\nSince then, it has run large-scale compromises across PyPI, npm and Docker Hub, publishing trojanized forks of Model Context Protocol servers and injecting malicious code into GitHub repositories that AI coding assistants clone. Its DUSTMAKER credential stealer drops files into hidden project directories such as .claude and .cursor, where AI tooling reads them as ordinary developer clutter.\n\nSome samples went further. Malware loaders carried prompt injections written as extreme requests about biological and nuclear weapons, text likely intended to make large language model security scanners refuse the file and skip the malicious JavaScript beneath it.\n\nAI assets themselves are now a target. Mandiant worked several data theft extortion cases last quarter in which attackers took proprietary models, source code and prompts from technology, healthcare and media companies in North America and Europe. One healthcare victim lost drug research and a proprietary model to a group that threatened to publish both unless it was paid.\n\nCompute is being stolen the same way. UNC6508, an alleged China-linked group tied to a multiyear campaign against academic, medical and military research institutions, is also behind suspected activity GTIG observed deploying open-weight models inside compromised cloud environments, keeping its prompting away from commercial application programming interface monitoring. An exposed GitHub access token let another attacker provision high-performance graphics processing unit instances in April at a victim’s expense.\n\nJohn Hultquist, chief analyst at Google Threat Intelligence Group, said the working assumption now is that every threat actor is using AI in some capacity and benefiting from it. Speed is what worries him most.\n\n“Criminals, like the ones who conducted a mass exploitation campaign in just six hours, will gravitate to attacks that are faster than we can respond to,” he said. Groups such as TeamPCP are a newer category, he added, going after AI systems as they get built into the enterprise stack rather than simply using them.\n\n##### Image: SiliconANGLE/GPT Image 2\n\n# A message from John Furrier, co-founder of SiliconANGLE:\n\nSupport our mission to keep content open and free by engaging with theCUBE community. **Join theCUBE’s Alumni Trust Network**, where technology leaders connect, share intelligence and create opportunities.\n\n- **15M+ viewers of theCUBE videos** , powering conversations across AI, cloud, cybersecurity and more\n- **11.4k+ theCUBE alumni** — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network\n\n### Are you an AWS customer?  Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: [https://siliconangle.com/aws-marketplace/](https://siliconangle.com/aws-marketplace/)\n\n##### **About SiliconANGLE Media**\n\n[SiliconANGLE](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fsiliconangle.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=SiliconANGLE&index=9&md5=646b1b564e2259100a2b8638aab0a552),\n\n[theCUBE Network](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.thecube.net%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+Network&index=10&md5=7de2a85f95ab4a4a495cede20b8cb1da),\n\n[theCUBE Research](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fthecuberesearch.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+Research&index=11&md5=7bb33676722925eb57d588ec343e4f6f),\n\n[CUBE365](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.cube365.net%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=CUBE365&index=12&md5=d310fb35919714e66ad8d42c9c0c1bc6),\n\n[theCUBE AI](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.thecubeai.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+AI&index=13&md5=b8b98472f8071b23ebb10ab9a8dd0683)and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.\n\nFounded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.", "url": "https://wpnews.pro/news/google-says-attackers-used-ai-agents-to-steal-credentials-in-under-six-hours", "canonical_source": "https://siliconangle.com/2026/09/08/google-says-attackers-used-ai-agents-to-steal-credentials-in-under-six-hours/", "published_at": "2026-09-08 12:00:51+00:00", "updated_at": "2026-09-08 12:59:33.842425+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-policy"], "entities": ["Google LLC", "Google Threat Intelligence Group", "Mandiant", "UNC6780", "TeamPCP", "Gemini", "John Hultquist"], "alternates": {"html": "https://wpnews.pro/news/google-says-attackers-used-ai-agents-to-steal-credentials-in-under-six-hours", "markdown": "https://wpnews.pro/news/google-says-attackers-used-ai-agents-to-steal-credentials-in-under-six-hours.md", "text": "https://wpnews.pro/news/google-says-attackers-used-ai-agents-to-steal-credentials-in-under-six-hours.txt", "jsonld": "https://wpnews.pro/news/google-says-attackers-used-ai-agents-to-steal-credentials-in-under-six-hours.jsonld"}}