Attackers are deploying AI multi-agent credential theft frameworks that compress a full attack lifecycle into hours, stripping out the human decision-making that defenders once relied on to buy themselves time. According to Google’s Threat Intelligence Group (GTIG), drawing on telemetry from Mandiant incident response engagements and live platform defences, AI agents are now coordinating vulnerability scanning, credential harvesting, IP rotation, and real-time troubleshooting with minimal human oversight.
‘Over the past quarter, threat actors have moved beyond simple prompt-based LLM interactions to integrate AI capabilities into multiple stages of an attack lifecycle,’ GTIG notes. ‘Groups are increasingly upgrading these workflows, creating highly autonomous systems capable of reasoning through complex tasks and making dynamic decisions without the need for human oversight.’
Six Hours From Prompt to Mass Credential Harvest
One incident documented by GTIG illustrates the pace. A financially motivated attacker compromised an organisation’s cloud infrastructure and, using an AI coding chatbot, a prompt, and markdown agent instructions, planned, built, and deployed a mass credential-harvesting campaign in under six hours. The AI agents managed the vulnerability-scanning pipeline, harvested thousands of third-party credentials, and routed attack traffic through legitimate compromised cloud environments to evade detection. The effect on defenders was direct: reduced ‘human-in-the-loop’ latency means the window for catching and responding to an intrusion shrinks sharply.
That shrinking window matters more than ever. Google Cloud reports that the global median dwell time (the period an attacker sits undetected inside a network) has risen to 14 days, up from 11 days in the previous reporting period. Faster, more autonomous attack pipelines arriving into environments where defenders are already losing ground on dwell time is not a comfortable combination.
The AI Multi-Agent Credential Theft Infrastructure Behind ‘Recon’
In a separate incident, researchers found an exposed command-and-control (C2) server hosting an automated reconnaissance and credential-management framework called ‘Recon.’ The framework was managing more than 23,800 harvested secrets in real time, including API keys. According to Help Net Security, the server’s files included AGENTS.md, KNOWLEDGE.md, and agentic_vuln_research.md, alongside .openclaw/ and memory/ directories, a layout that suggests a structured, modular agentic system rather than a hastily assembled script. The presence of dedicated knowledge and memory files points to agents designed to accumulate context and refine their behaviour across operations, not just fire off single-shot commands.
Nation-state actors are running parallel experiments. GTIG observed China-linked cyberespionage groups using AI-powered development tools to build automated exploitation and post-exploitation pipelines. Russia-based UNC5792, meanwhile, integrated AI models to automate monitoring bots that search Telegram channels for information of interest to the government. Supply-chain attacks attributed to UNC6780 (TeamPCP), Gemini AI distillation operations involving 100 million prompts, and a growing market for stolen AI account credentials and API keys round out the threat picture for state-backed and financially motivated groups alike.
GTIG was careful to note that fully autonomous hacking has not yet become widespread. The researchers did not observe threat actors deploying fully autonomous pipelines for zero-day discovery and network exploitation against real-world targets. The distinction matters: what is being documented now is highly capable, largely autonomous tooling that still involves some human setup, not a fully lights-out attack machine.
Google noted that its Gemini model caught many of these abuses early, responding in line with its safety protocols and allowing the company to disrupt campaigns and ban associated accounts. State-backed groups continue to use AI across the full attack chain: reconnaissance, phishing, malware development, exploitation, post-exploitation, data processing, and propaganda.
Google’s Defensive Response
On 27 May 2026, Google Cloud introduced Google AI Threat Defense, an autonomous AI-powered security platform that brings together Wiz, CodeMender, Gemini, and Mandiant, according to Bitsight. The launch positions Google to counter AI-driven attacks with AI-driven defence, a response that mirrors the structure of the threat: autonomous, multi-component, and designed to operate at machine speed. Whether that symmetry holds in practice is the question the next set of GTIG incident reports will answer.

