Hackers build AI frameworks for widescale credential theft
Recorded: Sept. 8, 2026, noon
| Original | Summarized |
Hackers build AI frameworks for widescale credential theft News Featured Trezor data breach impact now reaches 81,000 customers BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations N-able patches max severity N-central flaw amid ongoing attacks Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain Microsoft: Windows Server 2025 changes causing app crashes Get GPT, Gemini & Claude in one app for a one-time $99.99 220 million traveler records exposed in Vietnam-linked APIS leak Magento StyleSmuggler zero-day exploited to deploy Linux backdoor Tutorials Latest How to access the Dark Web using the Tor Browser How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to use the Windows Registry Editor How to backup and restore the Windows Registry How to start Windows in Safe Mode How to remove a Trojan, Virus, Worm, or other Malware How to show hidden files in Windows 7 How to see hidden files in Windows Webinars Latest Qualys BrowserCheck STOPDecrypter AuroraDecrypter FilesLockerDecrypter AdwCleaner ComboFix RKill Junkware Removal Tool Deals Categories eLearning IT Certification Courses Gear + Gadgets Security VPNs Popular Best VPNs How to change IP address Access the dark web safely Best VPN for YouTube Forums Virus Removal Guides HomeNewsSecurityHackers build AI frameworks for widescale credential theft Hackers build AI frameworks for widescale credential theft By Bill Toulas September 8, 2026 Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. Attack diagramSource: Google The Recon panelSource: Google Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Related Articles: Agentic AI Bill Toulas Previous Article Post a Comment Community Rules You need to login in order to post a comment You may also like: Upcoming Webinar Popular Stories OpenAI admits it didn't disclose rogue AI wiki hijacking incident Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain Attackers conceal phishing lures using invisible Unicode characters Sponsor Posts See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance. Can you trust every session? See how session enrichment enables better authentication decisions. CTI Starter Kit + 2026 SANS CTI Survey Unify ransomware protection and recovery for every client Upcoming Webinar Follow us: Main Sections News Community Forums Useful Resources Welcome Guide Company About BleepingComputer Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved Login Username Password Remember Me Sign in anonymously Sign in with Twitter Not a member yet? Register Now Help us understand the problem. What is going on with this comment? Spam Abusive or Harmful Inappropriate content Strong language Other Read our posting guidelinese to learn what content is prohibited. Submitting... |
Threat actors are increasingly leveraging AI not just for single tasks but for building multi-agent frameworks that automate every phase of an attack lifecycle, moving beyond simple prompt-based interactions with large language models. Drawing from telemetry gathered by the Google Threat Intelligence Group (GTIG), research indicates that threat groups are upgrading traditional script-based automation to create highly autonomous systems capable of complex reasoning and dynamic decision-making without continuous human oversight. This evolution allows AI agents to coordinate multiple attack tasks, troubleshoot operational failures in real time, and adapt their methods autonomously across various stages of an engagement. One significant observation involves incidents where threat actors deployed these sophisticated frameworks for large-scale credential harvesting. For instance, a financially motivated attacker demonstrated the capability to plan, develop, and deploy a mass credential-harvesting campaign within six hours by utilizing an AI coding chatbot alongside specific prompt instructions and markdown agent guidelines. These AI agents managed an entire attack pipeline, including vulnerability scanning, the harvesting of thousands of third-party credentials, real-time troubleshooting, IP address rotation, and routing malicious traffic through legitimate and compromised cloud environments to effectively evade detection mechanisms. This automation significantly reduced the latency between action and response for defenders. Further evidence points to the existence of automated reconnaissance and credential management systems that rely on AI agents. Researchers discovered an exposed command-and-control server hosting a framework named Recon, which contained instructions for AI agents, knowledge files, and artifacts related to OpenClaw that managed over twenty-three thousand harvested secrets, such as API keys. This demonstrates how AI is integrated directly into post-exploitation activities to manage sensitive stolen data automatically. State-backed cyberespionage groups have also utilized similar methodologies by integrating AI development tools to construct automated exploitation and post-exploitation pipelines. For example, Russia-based actors, such as UNC5792, have incorporated AI models to automate the operation of monitoring bots tasked with searching Telegram channels for relevant governmental information. The abuse of these tools is not limited to espionage; AI tool abuse has also been observed in broader security contexts, including supply-chain attacks and in AI distillation operations involving hundreds of millions of prompts, contributing to a growing market for stolen AI account credentials and API keys. While the potential for fully autonomous hacking pipelines is recognized, GTIG noted that widespread deployment of such systems for zero-day discovery and network exploitation against live targets has not yet been observed. Furthermore, the defensive side has shown some resilience; Google's Gemini model successfully caught many of these AI abuses early by responding according to its built-in safety protocols, which allowed Google to take action to disrupt the campaigns and ban associated accounts. Overall security posture is also highlighted, noting that once attackers possess valid credentials, prevention effectiveness drops sharply, as only thirty-seven percent of their actions are successfully blocked. These findings underscore the necessity for defenses that focus on post-initial access protection when dealing with adversaries employing advanced, autonomous AI techniques. |