Google reports AI agents automate credential
Google's threat intelligence group reports threat actors are using AI agents to automate cyberattack tasks like credential harvesting and vulnerability

Threat actors are automating parts of cyberattacks with less human involvement, including vulnerability scanning, credential harvesting, and troubleshooting. This is according to the Q3 2026 AI Threat Tracker from Google's Threat Intelligence Group (GTIG). The report draws on Mandiant incident response engagements, threat actor tracking, and live platform defenses.
Researchers observed attackers moving from basic prompts toward workflows where AI systems handle several connected tasks. Access to AI services and the computing resources needed to run them has become a key part of the tracked threat activity.
A six-hour credential theft campaign
In Q2 2026, Mandiant investigated a financially motivated threat actor that compromised an organization's cloud infrastructure. The attacker deployed an autonomous multi-agent framework.
Using an AI coding chatbot, a prompt, and agent instructions, the attacker planned, built, and executed a mass credential-harvesting campaign in less than six hours. Thousands of third-party credentials were compromised. The attacker operated from the victim's own cloud infrastructure, allowing attack traffic to pass through legitimate IP addresses.
GTIG researchers wrote that "the agent instructions enabled the AI to autonomously manage the vulnerability scanning pipeline, perform real-time troubleshooting, and execute IP rotation logic without manual intervention." The cost of premium model access and high-performance compute remains a primary barrier for threat actors seeking to operationalize AI.
Automated frameworks and harvested secrets
GTIG identified an exposed command-and-control server hosting an automated reconnaissance and credential management framework called "Recon." The server exposed configuration and knowledge files.
Shortly after detection, the exposed directory became a production dashboard. It was designed to organize, validate, and manage more than 23,800 harvested secrets in real time. These included API keys for cloud and AI services.
GTIG said autonomous agents can research vulnerabilities, scan server-side infrastructure, and execute targeted exploits. Researchers described this as a transition from passive, endpoint-focused information stealers to offensive agentic harvesting.
Cyber espionage experiments
A PRC-nexus cyber espionage threat actor used Gemini to design a dynamic, automated penetration testing framework. It was intended to observe a target's state, reason through actions, and execute tasks in unpredictable environments. Planned discovery functions included port scanning and service parsing. This activity was limited to attempts to build the framework, and GTIG disabled the associated assets.
In a separate case, another PRC-nexus cyber espionage threat actor experimented with AI development tools for an AI-assisted automated exploitation and post-exploitation pipeline. Using CC Switch, it queried models like Claude, Gemini, or Codex to write custom exploit scripts, generate spear-phishing lures, and debug errors.
The operation also involved Burp Suite to probe web applications and identify vulnerabilities. It used Phalanx, an open-source penetration testing framework, for automated exploitation routines. During post-exploitation activity, the actor deployed Shai-Hulud for command-and-control and credential harvesting.
No fully autonomous pipelines yet
GTIG says it "has not yet observed threat actors deploying fully autonomous pipelines against targets in the wild." However, adversarial adoption of agentic AI suggests threat actor use of AI could be evolving toward this use case.
The group describes a gradual maturation of tradecraft. Adversaries are using commercial and open-weight models to turn public disclosures and patch delays into working n-day exploit code. They refine payloads in controlled environments and progress toward constructing functional, multi-stage exploit chains. Researchers concluded that they continuously harden AI models against misuse by feeding insights from active threat monitoring directly into safety classifiers and guardrails.





