​Automated AI Systems Streamline Vulnerability Discovery and Secret Theft for Hackers

Rinky Rai
By Rinky Rai - A freelance journalist
4 Min Read

Cybercriminals are increasingly adopting multi-agent artificial intelligence frameworks to execute complex, multi-stage cyberattacks with minimal human oversight, according to a new report from the Google Threat Intelligence Group. Threat actors have moved beyond basic prompt-based interactions with large language models, opting instead for interconnected AI systems capable of coordinating technical operations across the entire attack lifecycle. Based on data from Mandiant incident-response operations, threat tracking, and active defenses, researchers observed these automated frameworks identifying vulnerabilities, stealing credentials, troubleshooting errors, rotating Internet Protocol addresses, and concealing malicious network traffic.

Multi-Agent Systems Deploy Rapid Credential Theft

​In one documented case, a financially motivated attacker breached an organisation’s cloud environment and launched an automated credential-harvesting campaign in less than six hours. The attacker utilized an AI coding chatbot, a series of prompts, and Markdown-based agent instructions to organize and execute the operation. The deployed AI agents independently scanned systems for security flaws, extracted thousands of third-party credentials, resolved emerging technical glitches, and rotated IP addresses to evade security filters.

​To obscure the operation, the attackers directed network traffic through compromised but legitimate cloud infrastructures, allowing the campaign to proceed with far less human intervention than traditional intrusions. In a separate finding, security researchers discovered an exposed command-and-control server operating an automated reconnaissance framework named Recon. The server contained agent directives, knowledge files, and OpenClaw-related artifacts managing over 23,800 stolen secrets, including API keys that could facilitate unauthorized access to software platforms and cloud services.

​StateSponsored Groups Integrate AI into Exploitation Pipelines

​The analysis revealed that state-backed cyberespionage groups linked to China and Russia are also incorporating advanced AI into their operational toolkits. China-linked entities were observed using AI-driven development tools to construct automated pipelines for vulnerability exploitation and post-exploitation activity. Simultaneously, the Russia-based UNC5792 group embedded AI models into monitoring systems designed for automated bots tracking Telegram discussions relevant to government-aligned actors.

​Beyond reconnaissance and targeted data extraction, state-sponsored operators are experimenting with AI across diverse functions, including phishing preparation, malware development, data processing, and propaganda dissemination. However, the report emphasized that fully autonomous hacking has not yet emerged as a widespread reality. Researchers noted that threat actors have not deployed entirely autonomous systems capable of independently discovering zero-day vulnerabilities or penetrating secure enterprise networks without human steering.

Stolen Legitimate Credentials Weaken Enterprise Defenses

​The immediate security danger lies in the operational velocity enabled by AI, which allows systems to troubleshoot technical failures and sustain attack workflows without waiting for human operators. This autonomy sharply narrows the window available for defenders to detect and halt malicious intrusions. The threat is compounded once valid credentials are compromised, as conventional defensive controls often fail to stop attackers navigating systems using legitimate access credentials.

​A 2026 security assessment evaluating defensive controls across 338 million simulations in production environments highlighted that preventive barriers degrade rapidly once legitimate access keys are abused. In response to these developments, Google confirmed that its Gemini model detected instances of abusive behavior at an early stage, enabling the company to disrupt ongoing operations and terminate associated accounts. The broader shift indicates that enterprise defense strategies must move beyond signature-based malware detection to focus on real-time credential monitoring, behavioral anomalies, and automated attack coordination.

Stay Connected