Tech News
← Home  ·  All topics

Google Threat Intelligence Group

2 GoKawiil briefs on this topic

Google Details AI-Driven Attack That Stole Thousands of Credentials in Under Six Hours

Google's Threat Intelligence Group disclosed a credential-harvesting operation where attackers compromised cloud infrastructure and deployed a multi-agent AI framework that scanned for vulnerabilities, fixed its own errors, and rotated IP addresses largely without human input. The entire campaign, which compromised thousands of third-party credentials, took less than six hours to execute. Separately, Microsoft found AI-assisted phishing messages reaching click-through rates of 54%, compared to roughly 12% for conventional campaigns.

Google flags autonomous AI agent framework used in mass credential-theft campaign

Google's Threat Intelligence Group reports that attackers are moving from simple AI-assisted coding to fully autonomous, multi-agent systems that plan and execute entire attacks with little human input. In one case, a financially motivated actor compromised cloud infrastructure and used an AI coding chatbot with markdown-based agent instructions to build and run a mass credential-harvesting operation in under six hours. Separately, researchers found an exposed command-and-control server running a framework called 'Recon' that autonomously managed reconnaissance and tens of thousands of harvested credentials.