AI Agents Are Taking Over More of the Cyberattack Workflow

In six hours.
Lily Morris
Contributing Writer
A flip clock. Passing of time concept. 1-6.
brave rabbit - stock.adobe.com

Cybercriminals are giving AI more control over attack workflows. Google Threat Intelligence Group (GTIG) says adversaries are moving from using models for isolated tasks to deploying agents that can scan targets, respond to errors, and continue operating with limited human input.

One Q2 2026 case shows the difference.

A suspected financially motivated actor compromised a cloud environment, then used an AI coding chatbot and agent instructions to build and execute a mass credential-harvesting campaign in less than six hours.

Attackers are also targeting enterprise AI infrastructure, turning proprietary models and access credentials into valuable assets for theft.

Why It Matters: Cyber defense depends partly on the time attackers spend moving from one task to the next. AI agents can reduce those pauses and allow smaller groups to automate more of an operation. They also create new security exposure inside development environments and cloud infrastructure.

  • AI Agents Are Starting to Run Meaningful Portions of Cyberattacks: In the six-hour credential campaign, the agent managed vulnerability scanning, fixed operational problems, and handled IP rotation without constant human input. GTIG separately found an agent-enabled system managing more than 23,800 stolen secrets. These cases show how AI can connect previously separate attack tasks into a continuous workflow. GTIG has yet to observe fully autonomous zero-day exploitation against live targets, but attackers are already reducing the human effort required to operate existing techniques.
  • AI Coding Tools Are Creating Another Route Into the Software Supply Chain: GTIG documented UNC6780 compromising developer accounts and software packages, then using project files to target AI assistants inside development environments. Its malware hid in directories used by coding tools and inserted instructions intended to make assistants execute attacker-controlled commands. The group also embedded hostile prompts in JavaScript that appeared designed to interfere with LLM security scanners. This creates a new trust problem. An AI tool can encounter malicious instructions simply by reading the repository it was asked to analyze.
  • Proprietary AI Is Becoming a Theft and Extortion Target: Mandiant investigated incidents where attackers stole AI models, research, prompts, source code, and related assets. A healthcare organization lost a proprietary model alongside drug research, while an AI media company had internal AI material taken for extortion. Google is also fighting model-distillation campaigns intended to reproduce proprietary capabilities. Some campaigns exceeded 100 million prompts and used thousands of compromised or fraudulent accounts. AI security now includes protecting the intellectual property and operating knowledge surrounding a model.
  • AI Is Reducing the Work Required Across Existing Attack Techniques: State-backed groups and cybercriminals are using models for reconnaissance, social engineering, malware development, exploit research, post-compromise troubleshooting, and analysis of stolen information. Information-operation actors are also experimenting with AI-generated personas and interactive bots, though GTIG says these efforts have yet to produce breakthrough capabilities. The current advantage comes from efficiency. Tasks that once required repeated human research and coding can be completed with more automation and less operator time.
  • Attackers Are Stealing AI Access When Buying It Is Too Expensive: GTIG reports growing underground demand for compromised AI accounts and developer credentials, with marketplace prices more than doubling in 2026. Malware is also targeting configuration files that can expose paid API access. In one cloud intrusion, an attacker used a leaked GitHub token to provision AI services and high-performance compute inside the victim’s environment, then sought additional GPU capacity. This form of LLMJacking turns stolen cloud access into subsidized AI infrastructure. Google says it is responding through stronger model defenses, account disruption, security testing, and automated threat-defense systems.

Go Deeper -> GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI – Google Threat Intelligence Group

Cybersecurity updates, executive insights, and the stories shaping the enterprise.

Browse past editions of TNCR newsletters. 

Technology news, cybersecurity, & executive insights.

×
You have free article(s) left this month courtesy of the CIO Professional Network.

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Would You Like To Save Articles?

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Thanks for subscribing!

We’re excited to have you on board. Stay tuned for the latest technology news delivered straight to your inbox.

Save My Spot For TNCR LIVE!

Thursday April 18th

9 AM Pacific / 11 PM Central / 12 PM Eastern

Register for Unlimited Access

Already a member?

Digital Monthly

$12.00/ month

Billed Monthly

Digital Annual

$10.00/ month

Billed Annually

Would You Like To Save Books?

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Log In To Access Premium Features

Sign Up For A Free Account

Name
Newsletters