On September 8, Google Threat Intelligence Group (GTIG) detailed several attacks that show how quickly AI is changing the economics of cybercrime.
In one credential-harvesting campaign, a threat actor first compromised an organization’s cloud infrastructure, then built and deployed a multi-agent attack framework. The operation took less than six hours in total and resulted in thousands of third-party credentials being compromised.
The AI even managed parts of the vulnerability-scanning pipeline, troubleshot problems as they arose and rotated IP addresses with minimal human intervention.
One of the main benefits of AI for organizations is the productivity gains it can deliver. Unfortunately, threat actors can use those same capabilities to make attacks faster and easier to scale. Credentials are already routinely harvested through infostealers, and AI simply removes some of the work required to carry attacks out.
As credentials are becoming easier to steal at scale, security teams must ensure their current authentication processes are robust enough to confidently establish that users and devices connecting to internal networks are trustworthy.
AI is Automating the Credential Theft Playbook
Microsoft reported in April that AI-assisted phishing campaigns it observed were achieving click-through rates as high as 54%, compared with around 12% for traditional campaigns.
If attackers can make the same campaign more convincing without spending proportionally more time creating it, the economics of phishing start to shift in their favor. For credential theft, that’s especially important as it’s partly a numbers game. Not every recipient will click, and even those accounts that do become compromised may not provide useful access.
With AI, attackers can generate targeted messages more quickly, adapt them for different languages or industries, and create variations without writing each one from scratch. Improving the success rate at the start of that process gives attackers more credentials to test and more opportunities to find the accounts that matter.
AI therefore doesn’t need to introduce a new way to steal credentials to change the risk for organizations. Making established techniques more efficient is enough.
... continue reading