Hackers now use AI agent teams to run entire attacks on their own
Google researchers found criminal groups using autonomous AI agents to plan, build, and run credential-theft campaigns in hours, with little human input.
What happened: Google's Threat Intelligence Group says hackers are moving past simply asking chatbots for help and are now building networks of AI agents that run whole attacks with little human input. In one case tracked by Google's Mandiant unit, a financially motivated attacker used an AI coding chatbot plus a set of written instructions to plan, build, and launch a mass credential-theft campaign in under six hours. Separately, researchers found an exposed control server running a framework called 'Recon' that was managing more than 23,800 stolen secrets, like API keys, in real time.
Why it matters: These AI agents handled jobs that used to take a human team: scanning for weaknesses, harvesting credentials, fixing their own errors, rotating IP addresses, and routing traffic through hacked-but-legitimate cloud accounts to dodge detection. Google says this cuts the 'human-in-the-loop' delay that used to slow attackers down, shrinking the window defenders have to notice and respond. State-linked groups from China and Russia were also seen testing AI for exploitation pipelines and for automatically monitoring Telegram channels.
How it works, plainly: Instead of a hacker typing prompts one step at a time, these setups chain several AI agents together, each handling a stage of the attack, with markdown files acting like a playbook the agents follow and adapt on the fly. When one step fails, the system troubleshoots itself rather than waiting for a person. Google stresses this is still short of fully autonomous hacking: it says it has not seen agents independently finding brand-new software flaws and breaking into real-world targets end to end without human direction.
The rollout: Google says its own Gemini model flagged many of these abuse attempts early, letting the company disrupt campaigns and ban the accounts behind them, which is how several of these incidents came to light. The report also flags other AI-linked abuse patterns Google is tracking, including supply-chain attacks, large-scale attempts to copy Gemini's capabilities using around 100 million prompts, and a growing underground market for stolen AI account logins and API keys.
