Cybercriminals deploy autonomous multi-agent AI systems to automate credential theft at scale

Google's Threat Intelligence Group reports that threat actors are moving beyond simple AI coding assistants to deploy multi-agent frameworks that autonomously plan, execute, and troubleshoot attacks. In one incident, a financially motivated attacker compromised cloud infrastructure and used an AI chatbot with markdown instructions to build a mass credential-harvesting campaign in under six hours, managing vulnerability scanning, rotating IPs, and routing traffic through compromised environments. Another exposed command-and-control server, named Recon, was found managing over 23,800 harvested secrets in real time, while China-linked espionage groups are also experimenting with AI-assisted exploitation pipelines.
Google's Threat Intelligence Group documented a financially motivated actor who compromised cloud infrastructure and deployed an autonomous framework to build a mass credential-harvesting operation in under six hours. The system managed vulnerability scanning, rotated IP addresses, and routed traffic through legitimate compromised environments to evade detection.
Separately, an exposed command-and-control server named "Recon" was found managing over 23,800 harvested secrets, including API keys, with embedded AI agent instructions. While state-linked groups experiment with exploitation pipelines, GTIG notes fully autonomous zero-day discovery remains unobserved. Google's Gemini model detected several abuses, leading to account bans, though supply-chain attacks and stolen AI credentials persist.
The shift toward autonomous multi-agent AI systems could significantly lower the technical barrier for launching large-scale credential theft, potentially accelerating the frequency and speed of breaches. Organizations may face shrinking response windows as attacks adapt in real time, while individuals could see a rise in identity theft stemming from harvested API keys and passwords. Defenders may need to leverage AI-driven countermeasures to keep pace with these evolving automated threats.