Chinese Hackers Are Running AI Inside Stolen Networks

Targeting U.S. research.
Lily Morris
Contributing Writer
China Flag in Digital Binary Numbers cyber style matrix
PsM - stock.adobe.com

Google says China-linked hackers are moving from basic AI prompting to agents that automate large portions of cyber intrusions. Some campaigns can now be conducted in less than six hours, reducing the time human operators need to spend actively hacking.

Hackers are also installing open-source AI models on compromised cloud networks, allowing them to avoid commercial services that could monitor their activity or enforce safeguards.

One group tracked since 2023 has also targeted proprietary AI research in North America. China’s embassy rejected the hacking allegations.

Why It Matters: AI can shorten cyber operations while reducing the human effort behind them. Running models on compromised infrastructure creates another security risk by turning cloud environments into attacker-controlled AI infrastructure and moving malicious activity outside the monitoring and safeguards of commercial AI platforms.

  • AI Is Automating More of the Attack: Google says intelligence agencies and cybercrime groups are using agents to automate substantial parts of intrusions. Researchers have also observed China-linked hackers developing capabilities intended to remove humans from important tasks. Some campaigns can now be completed in less than six hours.
  • Stolen Networks Can Host Offensive AI: Google observed a China-linked group installing open-source models on compromised cloud networks. This lets attackers avoid the monitoring and safeguards of commercial AI platforms while using victims’ infrastructure to run the models.
  • AI Research Is an Espionage Target: One China-linked group tracked by Google since 2023 has targeted academic, medical and military research organizations in North America, including proprietary AI research. The U.S. has long accused China of cyberespionage for economic advantage. Beijing denies such allegations and says it opposes hacking.
  • AI Agents Are Getting More Capable: American and Chinese AI companies have developed agents for hacking and cybersecurity tasks. OpenAI and Anthropic have separately disclosed incidents where agents escaped evaluation sandboxes and reached third-party organizations, illustrating the containment challenges associated with more autonomous systems.
  • Fully Autonomous Hacking Has Yet to Be Observed: Google says it has not seen threat actors conduct completely automated hacking campaigns, and no government operation run entirely by AI agents has been publicly identified. Current activity involves adding AI automation to existing cyber operations while reducing human involvement in selected tasks.

Go Deeper -> Chinese hackers are running AI on stolen networks to avoid detection, Google says – NBC News

Cybersecurity updates, executive insights, and the stories shaping the enterprise.

Browse past editions of TNCR newsletters. 

Technology news, cybersecurity, & executive insights.

×
You have free article(s) left this month courtesy of the CIO Professional Network.

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Would You Like To Save Articles?

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Thanks for subscribing!

We’re excited to have you on board. Stay tuned for the latest technology news delivered straight to your inbox.

Save My Spot For TNCR LIVE!

Thursday April 18th

9 AM Pacific / 11 PM Central / 12 PM Eastern

Register for Unlimited Access

Already a member?

Digital Monthly

$12.00/ month

Billed Monthly

Digital Annual

$10.00/ month

Billed Annually

Would You Like To Save Books?

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Log In To Access Premium Features

Sign Up For A Free Account

Name
Newsletters