Skip to content
Tech News
← Back to articles

Hackers build AI frameworks for widescale credential theft

read original get YubiKey 5 NFC Security Key → more articles
Why This Matters

Google's threat intelligence unit says attackers have moved past using chatbots as coding helpers and are now deploying autonomous multi-agent AI frameworks that run entire attack chains — scanning, credential harvesting, troubleshooting, and evasion — with little human input. One campaign went from idea to mass credential theft in under six hours, collapsing the window defenders have to react. That shift raises the tempo and scale of attacks against cloud environments and third-party credentials.

Key Takeaways
Worth a Look

YubiKey 5 NFC Security Key — When attackers can spin up automated credential-harvesting campaigns in hours, stolen passwords alone shouldn't be enough to get in. The YubiKey 5 NFC adds phishing-resistant hardware two-factor authentication to accounts like Google, Microsoft and password managers, tapping into a phone via NFC or plugging into USB-A. It's a simple, durable keychain-sized defense against exactly the kind of mass credential theft described here.

See YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack.

Drawing on telemetry from Mandiant's incident response engagements, threat actor tracking, and live platform defenses, the Google Threat Intelligence Group (GTIG) observed AI agents coordinating multiple attack tasks, troubleshooting failures, and adapting their actions with minimal human intervention.

“Over the past quarter, threat actors have moved beyond simple prompt-based LLM interactions to integrate AI capabilities into multiple stages of an attack lifecycle,” GTIG notes.

“While traditional script-based automation has long been a staple of threat actor operations, groups are increasingly upgrading these workflows, creating highly autonomous systems capable of reasoning through complex tasks and making dynamic decisions without the need for human oversight.”

In one such incident, a financially motivated attacker compromised an organization’s cloud infrastructure and deployed an autonomous multi-agent framework.

In less than six hours, the threat actor planned, built, and deployed a mass credential-harvesting campaign using an AI coding chatbot, a prompt, and markdown agent instructions, Google says.

Attack diagram

Source: Google

The AI agents managed the vulnerability-scanning pipeline, harvested thousands of third-party credentials, troubleshot problems in real time, rotated IP addresses, and routed attack traffic through legitimate, compromised cloud environments to evade detection.

This approach dramatically reduced “human-in-the-loop” latency and the response windows for defenders.

... continue reading