Google says China-linked hackers are moving from basic AI prompting to agents that automate large portions of cyber intrusions. Some campaigns can now be conducted in less than six hours, reducing the time human operators need to spend actively hacking.
Hackers are also installing open-source AI models on compromised cloud networks, allowing them to avoid commercial services that could monitor their activity or enforce safeguards.
One group tracked since 2023 has also targeted proprietary AI research in North America. China’s embassy rejected the hacking allegations.
Why It Matters: AI can shorten cyber operations while reducing the human effort behind them. Running models on compromised infrastructure creates another security risk by turning cloud environments into attacker-controlled AI infrastructure and moving malicious activity outside the monitoring and safeguards of commercial AI platforms.
- AI Is Automating More of the Attack: Google says intelligence agencies and cybercrime groups are using agents to automate substantial parts of intrusions. Researchers have also observed China-linked hackers developing capabilities intended to remove humans from important tasks. Some campaigns can now be completed in less than six hours.
- Stolen Networks Can Host Offensive AI: Google observed a China-linked group installing open-source models on compromised cloud networks. This lets attackers avoid the monitoring and safeguards of commercial AI platforms while using victims’ infrastructure to run the models.
- AI Research Is an Espionage Target: One China-linked group tracked by Google since 2023 has targeted academic, medical and military research organizations in North America, including proprietary AI research. The U.S. has long accused China of cyberespionage for economic advantage. Beijing denies such allegations and says it opposes hacking.
- AI Agents Are Getting More Capable: American and Chinese AI companies have developed agents for hacking and cybersecurity tasks. OpenAI and Anthropic have separately disclosed incidents where agents escaped evaluation sandboxes and reached third-party organizations, illustrating the containment challenges associated with more autonomous systems.
- Fully Autonomous Hacking Has Yet to Be Observed: Google says it has not seen threat actors conduct completely automated hacking campaigns, and no government operation run entirely by AI agents has been publicly identified. Current activity involves adding AI automation to existing cyber operations while reducing human involvement in selected tasks.


