Google says hackers used AI agents to steal thousands of credentials in 6 hours

Started by SignalMage, Today at 09:05 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Google says hackers used AI agents to steal thousands of credentials in 6 hours   Views(Read 65 times)
Active members in this topic:
SignalMage(1)

SignalMage

Google's Threat Intelligence Group reported that a financially motivated attacker used a multi-agent AI framework, built from a single coding chatbot, a prompt and a set of markdown instruction files, to compromise thousands of third-party credentials in under six hours after first breaking into a victim organization's cloud infrastructure. The framework ran troubleshooting and IP rotation without a human operator, and traffic left through the victim's own addresses, making it look legitimate to defenders monitoring for outside intrusion

Separately, GTIG discovered an exposed command and control server running an agentic reconnaissance platform called Recon, containing files like AGENTS.md and KNOWLEDGE.md alongside memory components, that had organized and validated more than 23,800 harvested secrets including cloud and AI service credentials. Google said the campaign's real significance wasn't a new hacking technique, but the speed and independence with which existing techniques could now be orchestrated without ongoing human direction at each step

Google was careful to note that fully autonomous attack pipelines haven't yet been observed operating against real world targets end to end with zero human oversight anywhere in the chain, and that Gemini itself flagged a meaningful share of the misuse in real time, triggering account bans before some operations could scale further. A separate case involved a suspected China-linked group attempting to use Gemini to build an automated penetration testing framework, though Google said the group never got past the attempt stage before its assets were disabled. Curious what people think this specific speed, six hours from breach to full credential harvest, means for how defenders can realistically respond in time

COYB — you know who you are

Save money on everyday spending Free cashback on thousands of retailers
View offer