Google flags autonomous AI agent framework used in mass credential-theft campaign
Google's Threat Intelligence Group reports that attackers are moving from simple AI-assisted coding to fully autonomous, multi-agent systems that plan and execute entire attacks with little human input. In one case, a financially motivated actor compromised cloud infrastructure and used an AI coding chatbot with markdown-based agent instructions to build and run a mass credential-harvesting operation in under six hours. Separately, researchers found an exposed command-and-control server running a framework called 'Recon' that autonomously managed reconnaissance and tens of thousands of harvested credentials.