Threat actors are giving AI agents a bigger role in cyberattacks

According to the Google Threat Intelligence Group Q3 2026 AI Threat Tracker, cybercriminals are increasingly deploying autonomous AI agents to automate reconnaissance, credential harvesting, and vulnerability scanning with minimal human intervention.

During a Q2 2026 investigation conducted by Mandiant, researchers uncovered a financially motivated threat actor that deployed an autonomous multi-agent framework on a compromised corporate cloud infrastructure. Utilizing an AI coding chatbot combined with specific agent instructions, the attackers successfully planned and executed a mass credential-harvesting campaign in under six hours, compromising thousands of third-party credentials.

Google Threat Intelligence Group researchers noted that the underlying agent instructions permitted the AI to autonomously govern its vulnerability scanning pipeline, execute real-time troubleshooting, and handle IP rotation logic without manual oversight. By operating directly from the victimized cloud infrastructure, the malicious activity successfully blended traffic with legitimate IP addresses.

Further analysis revealed an exposed command-and-control server hosting an automated reconnaissance framework named Recon. The server exposed thousands of harvested secrets, including configuration and knowledge files alongside more than 23,800 validated credentials and API keys for cloud and AI services.

Nation-state actors have also begun experimenting with generative tools, with PRC-nexus espionage groups utilizing models like Gemini and Claude to design dynamic penetration testing frameworks and automated exploitation pipelines. While fully autonomous pipelines targeting live environments remain unobserved in the wild, researchers emphasize a steady maturation of adversarial tradecraft.

Leave a Reply

Your email address will not be published. Required fields are marked *