Autonomous Multi-Agent AI Hacked Thousands of Credentials in Six Hours, Google Report Finds
A financially motivated threat group deployed an autonomous AI framework to execute a mass credential-harvesting campaign in under six hours, according to Google's Threat Intelligence Group.
- Threat Intelligence Analysts
- Focus on tracking the evolution of adversary tactics and the deployment of multi-agent frameworks.
- Enterprise Defenders
- Focus on mitigating the shrinking response window through behavioral detection and identity governance.
Perspectives this story doesn't cover
- AI Model Providers
- Open-Source Repository Maintainers
Fast facts
- A financially motivated threat actor used an autonomous AI framework to harvest thousands of credentials in under six hours.
- The AI agents autonomously managed vulnerability scanning, real-time troubleshooting, and IP rotation without human oversight.
- Google's Q3 2026 AI Threat Tracker highlights a shift from simple AI prompting to fully agentic adversarial workflows.
- Threat groups like UNC6780 are actively poisoning the open-source AI supply chain across platforms like PyPI and npm.
- State-linked actors are experimenting with AI to build automated penetration testing frameworks.
Why this matters
As hackers transition from using AI as a simple coding assistant to deploying multi-agent frameworks that automate the entire attack lifecycle, the window for defenders to detect and respond to intrusions is shrinking from days to hours.
The outcome of the intrusion was determined the moment the threat actor deployed an autonomous multi-agent framework into a compromised cloud environment, handing multistep operational decisions over to artificial intelligence. Operating entirely without human oversight, the AI agents planned, built, and executed a mass credential-harvesting campaign that compromised thousands of third-party credentials in under six hours. This shift from human-driven attacks to machine-speed automation is the central finding of the Q3 2026 AI Threat Tracker report released Tuesday by the Google Threat Intelligence Group (GTIG).[1][2]
According to incident response telemetry from Mandiant, the financially motivated attacker assembled the autonomous framework using an AI coding chatbot, a core prompt, and a set of agent instructions. Using preconfigured markdown playbooks—specifically files named AGENTS.md and KNOWLEDGE.md—the AI agents autonomously managed the vulnerability-scanning pipeline and harvested credentials at scale. The system was capable of troubleshooting errors in real time and executing IP rotation logic without requiring an operator to intervene.[2][3]
To evade detection, the attack traffic was routed directly through the victim's own compromised cloud infrastructure, allowing the malicious activity to pass through legitimate IP addresses. This approach dramatically reduced the human-in-the-loop latency that traditionally slows down cyberattacks. "Over the past quarter, threat actors have moved beyond simple prompt-based LLM interactions to integrate AI capabilities into multiple stages of an attack lifecycle," GTIG researchers noted in the report.[1][2][3]
The speed of the autonomous framework represents a significant challenge for enterprise security teams, as a six-hour execution window is often faster than standard incident response cycles can begin. John Hultquist, chief analyst at Google Threat Intelligence Group, emphasized that the working assumption is now that every threat actor is utilizing AI in some capacity. "Criminals, like the ones who conducted a mass exploitation campaign in just six hours, will gravitate to attacks that are faster than we can respond to," Hultquist said.[2][3]
Beyond credential harvesting, the GTIG report details how threat actors are increasingly targeting the AI supply chain itself. A criminal group tracked as UNC6780, also known as TeamPCP, has conducted large-scale compromises across major open-source repositories including PyPI, npm, and Docker Hub. After poisoning the LiteLLM gateway in March 2026, the group began publishing trojanized forks of Model Context Protocol (MCP) servers and injecting malicious code into GitHub repositories that AI coding assistants frequently clone.[1][2]
Beyond credential harvesting, the GTIG report details how threat actors are increasingly targeting the AI supply chain itself.
TeamPCP's operations deploy a credential stealer known as DUSTMAKER, which drops files into hidden project directories such as .claude and .cursor, disguising the malware as ordinary developer clutter. In some instances, the malware loaders carried prompt injections containing extreme requests about biological and nuclear weapons. This text was specifically designed to trigger large language model security scanners into refusing the file, thereby causing the scanner to skip the malicious JavaScript hidden beneath the prompt.[1][2]
Proprietary AI assets have also become high-value targets for extortion. During the second quarter of 2026, Mandiant investigated several data theft cases in which attackers exfiltrated proprietary models, source code, and prompts from technology, healthcare, and media companies across North America and Europe. In one notable case, a healthcare organization lost both drug research data and a proprietary AI model to a threat group that threatened to publish the intellectual property unless a ransom was paid.[1][2]
State-linked actors are similarly experimenting with agentic AI capabilities. GTIG observed a China-nexus cyber espionage group attempting to use Google's Gemini model to design a dynamic, automated penetration testing framework. The group aimed to build an architecture capable of observing a target's state, reasoning through actions, and executing tasks in unpredictable environments. While Google disabled the assets tied to the effort before it could be fully deployed, the attempt underscores the growing adversary interest in offensive AI automation.[1][2][3]
In another incident, researchers discovered an exposed command-and-control server hosting an automated reconnaissance and credential-management framework dubbed Recon. The server contained configuration files, AI agent instructions, and artifacts that managed more than 23,800 harvested secrets, including API keys, in real time. Another China-linked group, UNC6508, was observed deploying open-weight models inside compromised cloud environments to keep its prompting activity hidden from commercial API monitoring.[2][3]
For defenders, the transition from passive infostealers to offensive agentic harvesting means that traditional, static detection methods are becoming less effective. Because AI agents can dynamically alter their tactics and operate at machine speed, security teams are being forced to prioritize behavioral detection, robust identity controls, and strict governance over non-human identities like service accounts and API keys.[1][3]
Viewpoints in depth
Threat Intelligence Analysts
Analysts emphasize the rapid evolution of adversary tactics from simple prompting to autonomous workflows.
Security researchers note that the shift from using AI as a basic coding assistant to deploying multi-agent frameworks represents a fundamental change in the threat landscape. By handing orchestration and troubleshooting over to AI models, attackers can execute high-volume, low-effort campaigns that adapt dynamically to the target environment. This automation removes the human bottleneck, allowing attacks to proceed at machine speed and significantly lowering the barrier to entry for mass exploitation.
Enterprise Defenders
Defenders are focused on the shrinking response window and the need for behavioral detection.
For enterprise security teams, a six-hour attack lifecycle is often faster than standard incident response processes can triage and escalate an alert. Defenders argue that traditional perimeter security and static phishing detection are insufficient against agents that can dynamically alter their tactics. The focus is shifting toward behavioral detection—such as identifying unusual authentication patterns or impossible travel—and implementing strict identity governance for non-human accounts, API keys, and automated pipelines.
Sources
[1]Google Cloud BlogThreat Intelligence AnalystsGTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI
Read on Google Cloud Blog →
[2]SiliconANGLEEnterprise DefendersGoogle says attackers used AI agents to steal credentials in under six hours
Read on SiliconANGLE →
[3]BleepingComputerThreat Intelligence AnalystsHackers build AI frameworks for widescale credential theft
Read on BleepingComputer →
Comments
More in Artificial Intelligence
See all →Model Interpretability
How Concept Cones and In-Parameter Erasure Stop AI Models From Over-Refusing Safe Prompts
5 sources
Prompt Engineering
The 28.2% Accuracy Gain: How Chain-of-Thought Prompting Unlocks Reasoning in Large Language Models
7 sources
Search Algorithms
How Alpha-Beta Pruning Doubles the Search Depth of Adversarial AI
9 sources
PyTorch Ecosystem
Alibaba Cloud, Cambricon, and Ant Group Join PyTorch Foundation Governing Board
3 sources
Every angle. Every day.
Get Artificial Intelligence stories with full source coverage and perspective breakdowns delivered to your inbox.



