LmCast :: Stay tuned in

Hackers build AI frameworks for widescale credential theft

Recorded: Sept. 8, 2026, noon

Original Summarized

Hackers build AI frameworks for widescale credential theft

News

Featured
Latest

Trezor data breach impact now reaches 81,000 customers

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

N-able patches max severity N-central flaw amid ongoing attacks

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

Microsoft: Windows Server 2025 changes causing app crashes

Get GPT, Gemini & Claude in one app for a one-time $99.99

220 million traveler records exposed in Vietnam-linked APIS leak

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityHackers build AI frameworks for widescale credential theft

Hackers build AI frameworks for widescale credential theft

By Bill Toulas

September 8, 2026
08:03 AM
0

Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack.
Drawing on telemetry from Mandiant's incident response engagements, threat actor tracking, and live platform defenses, the Google Threat Intelligence Group (GTIG) observed AI agents coordinating multiple attack tasks, troubleshooting failures, and adapting their actions with minimal human intervention.
“Over the past quarter, threat actors have moved beyond simple prompt-based LLM interactions to integrate AI capabilities into multiple stages of an attack lifecycle,” GTIG notes.
“While traditional script-based automation has long been a staple of threat actor operations, groups are increasingly upgrading these workflows, creating highly autonomous systems capable of reasoning through complex tasks and making dynamic decisions without the need for human oversight.”
In one such incident, a financially motivated attacker compromised an organization’s cloud infrastructure and deployed an autonomous multi-agent framework.
In less than six hours, the threat actor planned, built, and deployed a mass credential-harvesting campaign using an AI coding chatbot, a prompt, and markdown agent instructions, Google says.

Attack diagramSource: Google
The AI agents managed the vulnerability-scanning pipeline, harvested thousands of third-party credentials, troubleshot problems in real time, rotated IP addresses, and routed attack traffic through legitimate, compromised cloud environments to evade detection.
This approach dramatically reduced “human-in-the-loop” latency and the response windows for defenders.
In another incident, the researchers found an exposed command-and-control (C2) server hosting an automated reconnaissance and credential-management framework called “Recon.”
Its files included instructions for AI agents, knowledge files, and OpenClaw artifacts related to the framework that managed in real-time more than 23,800 harvested secrets, such as API keys.

The Recon panelSource: Google
GTIG's report notes other examples where China-linked cyberespionage actors experimented "with AI-powered development tools to build an AI-assisted, automated exploitation and post-exploitation pipeline."
The researchers say that other espionage groups, such as the Russia-based UNC5792, integrated AI models to automate monitoring bots searching Telegram channels for information of interest to the government.
However, GTIG underlined that fully autonomous hacking has not become widespread yet, and did not observe threat actors deploying fully autonomous pipelines for zero-day discovery and network exploitation against real-world targets.
The company also noted that Gemini, its AI model, caught many of these abuses early and responded in accordance with its safety protocols, allowing Google to take additional action, disrupt the campaigns, and ban the associated accounts.
AI tool abuse has also been observed in supply-chain attacks conducted by UNC6780 (TeamPCP), Gemini AI distillation operations involving 100 million prompts, and a growing market for stolen AI account credentials and API keys.
Also, state-backed groups continue to use AI for reconnaissance, phishing, malware development, exploitation, post-exploitation, data processing, and propaganda.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Get the report

Related Articles:
Google Gemini CLI abused as a hacking agent, malware botnet operatorJadePuffer ransomware used AI agent to automate entire attackNearly 700 rogue AI agents coordinated in the Hugging Face attackHow Anthropic plans to watermark Claude's AI-generated textGoogle says AI helped Chrome fix 1,072 security bugs in two releases

Agentic AI
AI
AI Agent
Artificial Intelligence
Gemini
Gemini AI
Google
Google Gemini

Bill Toulas
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment
Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

OpenAI admits it didn't disclose rogue AI wiki hijacking incident

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

Attackers conceal phishing lures using invisible Unicode characters

Sponsor Posts

See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance.

Can you trust every session? See how session enrichment enables better authentication decisions.

CTI Starter Kit + 2026 SANS CTI Survey

Unify ransomware protection and recovery for every client

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Threat actors are increasingly leveraging AI not just for single tasks but for building multi-agent frameworks that automate every phase of an attack lifecycle, moving beyond simple prompt-based interactions with large language models. Drawing from telemetry gathered by the Google Threat Intelligence Group (GTIG), research indicates that threat groups are upgrading traditional script-based automation to create highly autonomous systems capable of complex reasoning and dynamic decision-making without continuous human oversight. This evolution allows AI agents to coordinate multiple attack tasks, troubleshoot operational failures in real time, and adapt their methods autonomously across various stages of an engagement.

One significant observation involves incidents where threat actors deployed these sophisticated frameworks for large-scale credential harvesting. For instance, a financially motivated attacker demonstrated the capability to plan, develop, and deploy a mass credential-harvesting campaign within six hours by utilizing an AI coding chatbot alongside specific prompt instructions and markdown agent guidelines. These AI agents managed an entire attack pipeline, including vulnerability scanning, the harvesting of thousands of third-party credentials, real-time troubleshooting, IP address rotation, and routing malicious traffic through legitimate and compromised cloud environments to effectively evade detection mechanisms. This automation significantly reduced the latency between action and response for defenders.

Further evidence points to the existence of automated reconnaissance and credential management systems that rely on AI agents. Researchers discovered an exposed command-and-control server hosting a framework named Recon, which contained instructions for AI agents, knowledge files, and artifacts related to OpenClaw that managed over twenty-three thousand harvested secrets, such as API keys. This demonstrates how AI is integrated directly into post-exploitation activities to manage sensitive stolen data automatically.

State-backed cyberespionage groups have also utilized similar methodologies by integrating AI development tools to construct automated exploitation and post-exploitation pipelines. For example, Russia-based actors, such as UNC5792, have incorporated AI models to automate the operation of monitoring bots tasked with searching Telegram channels for relevant governmental information. The abuse of these tools is not limited to espionage; AI tool abuse has also been observed in broader security contexts, including supply-chain attacks and in AI distillation operations involving hundreds of millions of prompts, contributing to a growing market for stolen AI account credentials and API keys.

While the potential for fully autonomous hacking pipelines is recognized, GTIG noted that widespread deployment of such systems for zero-day discovery and network exploitation against live targets has not yet been observed. Furthermore, the defensive side has shown some resilience; Google's Gemini model successfully caught many of these AI abuses early by responding according to its built-in safety protocols, which allowed Google to take action to disrupt the campaigns and ban associated accounts. Overall security posture is also highlighted, noting that once attackers possess valid credentials, prevention effectiveness drops sharply, as only thirty-seven percent of their actions are successfully blocked. These findings underscore the necessity for defenses that focus on post-initial access protection when dealing with adversaries employing advanced, autonomous AI techniques.