Published on September 8, 2026

Hackers Build AI Frameworks for Widescale Credential Theft


Severity
Medium

Detail

Threat actors are increasingly moving from AI-powered coding assistants to multi-agent frameworks capable of automating multiple stages of cyberattacks. According to the Google Threat Intelligence Group (GTIG), threat actors have been observed using AI agents to coordinate attack tasks, troubleshoot failures, and adapt their activities with limited human intervention.

GTIG observed that threat actors are integrating AI capabilities into multiple stages of the attack lifecycle. These systems can reason through complex tasks and make dynamic decisions without requiring continuous human oversight.

In one incident, a financially motivated attacker compromised an organization’s cloud infrastructure and deployed an autonomous multi-agent framework. Within less than six hours, the attacker planned, developed, and deployed a mass credential-harvesting campaign using an AI coding chatbot, a prompt, and markdown agent instructions.

The AI agents managed the vulnerability-scanning process, harvested thousands of third-party credentials, troubleshot issues in real time, rotated IP addresses, and routed attack traffic through legitimate but compromised cloud environments to evade detection.

How?

The attacker used an autonomous multi-agent framework supported by an AI coding chatbot, a prompt, and markdown-based agent instructions. The AI agents were responsible for managing the vulnerability-scanning pipeline and credential-harvesting activities. They were also able to troubleshoot problems during the operation, rotate IP addresses, and route malicious traffic through legitimate compromised cloud environments.

In another incident, researchers discovered an exposed command-and-control server hosting an automated reconnaissance and credential-management framework named Recon. The framework contained instructions for AI agents, knowledge files, and OpenClaw artifacts. It was managing more than 23,800 harvested secrets, including API keys in real time.

GTIG also identified China-linked cyberespionage actors experimenting with AI-powered development tools to create automated exploitation and post-exploitation pipelines. Other espionage groups, including Russia-based UNC5792, used AI models to automate monitoring bots that searched Telegram channels for information of interest to the government.

Impact

The use of AI-driven multi-agent frameworks significantly reduces the need for human involvement during cyberattacks and shortens the response window available to defenders.

The observed framework could conduct vulnerability scanning, harvesting thousands of credentials, troubleshooting operational problems, rotating IP addresses, and routing attack traffic through compromised cloud environments. The Recon framework was managing more than 23,800 harvested secrets including API keys.

AI has also been used by state-backed groups for reconnaissance, phishing, malware development, exploitation, post-exploitation, data processing, and propaganda. However, GTIG stated that fully autonomous hacking has not yet become widespread. Researchers did not observe threat actors using fully autonomous pipelines for zero-day discovery and network exploitation against real-world targets.

Conclusion

Threat actors are increasingly incorporating AI into multi-agent frameworks to automate and coordinate different stages of cyberattacks. The observed activity demonstrates that AI agents can manage vulnerability scanning, credential harvesting, troubleshooting, infrastructure changes, and other attack tasks with limited human intervention.

Despite these developments, GTIG noted that fully autonomous hacking remains uncommon and that it has not observed fully autonomous pipelines being used for zero-day discovery and network exploitation against real-world targets. The use of AI by threat actors nevertheless continues to expand across credential theft, reconnaissance, phishing, malware development, exploitation, post-exploitation, data processing, supply-chain attacks and propaganda.

Source
https://www.bleepingcomputer.com/news/security/hackers-build-ai-frameworks-for-widescale-credential-theft/
https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai