AI Business

Google Reveals AI-Powered Credential Theft Campaign Executed in Hours

Attackers leveraged autonomous AI agents to harvest thousands of credentials within six hours, according to Google's threat intelligence division, signaling a shift toward faster, less human-dependent cyberattacks.

·4 min read
Google says attackers used AI agents to steal credentials in under six hours
Google says attackers used AI agents to steal credentials in under six hours

A coordinated assault involving autonomous artificial intelligence agents compromised thousands of user credentials in just six hours, according to findings released today by Google LLC's Google Threat Intelligence Group. Mandiant's investigation linked the operation to a financially motivated threat actor who initially infiltrated an organization's cloud environment, then deployed an autonomous system built from an AI coding chatbot, custom prompts and predefined agent instructions. The framework included preconfigured markdown playbooks that orchestrated the scanning and credential harvesting phases.

The attack required minimal human oversight once deployed. Troubleshooting and IP rotation occurred automatically, and outbound traffic originated from the victim's own network addresses, making the malicious activity appear legitimate. The campaign is documented in Google's latest report, From Prompting to Autonomy: The Evolution of Adversarial AI, which examines threat activity tracked during the second quarter. This follows May's disclosure of the first confirmed instance of criminals using AI to develop a functional zero-day exploit. The key distinction now, according to GTIG, is the dramatic reduction in human involvement—adversaries are delegating complex multistep decisions to AI models, compressing the timeframe available for defenders to intervene.

While GTIG has not yet documented fully autonomous attack pipelines operating against live targets in the wild, adversary motivation is unmistakable. A suspected China-linked espionage group attempted to use Gemini to construct an automated penetration testing framework capable of executing port scanning, service enumeration and other reconnaissance activities independently. The effort stalled before deployment, and Google disabled the associated infrastructure.

Open-Source Supply Chain Under Siege

The report's primary focus centers on UNC6780, a criminal organization that Google also identifies as TeamPCP. This group previously compromised the LiteLLM gateway in March and has since orchestrated extensive attacks across PyPI, npm and Docker Hub. The operation involved distributing trojaned copies of Model Context Protocol servers and embedding malicious code into GitHub repositories that AI coding assistants routinely access. The group's DUSTMAKER credential stealer places harvested files in concealed project directories such as .claude and .cursor, locations where AI development tools naturally scan for configuration data.

Some malware variants incorporated additional sophistication. Certain loaders embedded prompt injections formatted as extreme requests concerning biological and nuclear weapons—text designed to trigger refusals from large language model security filters, allowing malicious JavaScript payloads to bypass detection.

AI Systems Become Direct Targets

Attackers are now directly targeting AI infrastructure itself. During the most recent quarter, Mandiant investigated multiple data theft extortion incidents where adversaries stole proprietary models, source code and prompts from organizations in the technology, healthcare and media sectors across North America and Europe. One healthcare company fell victim to theft of drug research data and a proprietary model; the attackers demanded payment under threat of public disclosure.

Computational resources are being stolen with similar tactics. UNC6508, an alleged China-linked group conducting a sustained campaign against academic, medical and military research institutions, has deployed open-weight models within compromised cloud infrastructure while keeping its prompting activities away from commercial API monitoring systems. In a separate incident, an exposed GitHub access token enabled an attacker to spin up high-performance GPU instances in April, charging the costs to the victim's account.

The Speed Problem

John Hultquist, chief analyst at Google Threat Intelligence Group, emphasized that the operational assumption has shifted: "Criminals, like the ones who conducted a mass exploitation campaign in just six hours, will gravitate to attacks that are faster than we can respond to," he said. The prevailing view within GTIG is that every threat actor now employs AI in some form and derives tangible benefit from it. Hultquist highlighted speed as the primary concern. Groups such as TeamPCP represent an emerging threat category—rather than simply using AI tools, they are targeting AI systems as these technologies become embedded in enterprise infrastructure.