Vulnerability  ·  2026-09-16

Google Threat Intelligence Group discloses autonomous AI-agent-driven mass credential harvesting campaign

VulnerabilityHigh impactGlobal
Google Threat Intelligence Group (GTIG) published 'From Prompting to Autonomy: The Evolution of Adversarial AI,' documenting a Q2 2026 Mandiant investigation where a threat actor used an autonomous multi-agent AI framework to compromise cloud infrastructure and harvest thousands of third-party credentials in under six hours, plus a separate exposed 'Recon' credential-management dashboard holding over 23,800 secrets. Widely covered across security press on Sept 14-15, 2026.
This is a concrete, disclosed instance of attackers operationalizing agentic AI to compress the entire intrusion lifecycle (recon, exploitation, credential harvesting, error recovery) into hours instead of days, with reduced human-in-the-loop latency — directly shrinking defender response windows. It also confirms attackers are systematically targeting AI-service API keys and AI coding-assistant credentials as a distinct high-value asset class, and that state-linked actors are running stolen open-source AI models on victim infrastructure to evade telemetry.
A financially motivated actor compromised an organization's cloud environment, then deployed a multi-agent framework (an AI coding chatbot plus preconfigured Markdown 'playbook' instructions) that autonomously ran vulnerability scanning, credential harvesting, error troubleshooting, and IP rotation — planning, building, and executing a mass credential-harvesting operation in under six hours with minimal human direction. Separately, GTIG found an exposed C2 server ('Recon') managing 23,800+ harvested secrets including cloud and AI-service API keys, and documented China-linked actors running open-source AI models directly on stolen cloud infrastructure to evade monitoring.
N/A — attacker tradecraft against victim cloud environments; report also names AI dev-tool config files (.claude/, .cursor/, .vscode/) and MCP packages (e.g. trojanized tiktoken_mcp) as targets
Treat AI coding-assistant configuration files and cloud/AI-service credentials as high-value secrets; enforce least privilege and rotate credentials after any suspected exposure; monitor for anomalous scanning, new service accounts, and unusual public-service exposure; separate production from development cloud projects. See Google Cloud's report for full IOCs and detections.
Google Cloud Blog — GTIG AI Threat TrackerGBHackers — Hackers Weaponize Agentic AI to Automate Reconnaissance, Exploitation and Post-ExploitationCyber Security News — Hackers Use Autonomous AI Agents to Harvest Thousands of Credentials in Under 6 Hours
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →