Google warns cyber attackers are moving to agentic AI
Wed, 9th Sep 2026 (Today)
Google has warned that cyber attackers are moving from simple AI prompting to more autonomous, agent-based operations, according to research from Google Threat Intelligence Group.
Advanced adversaries are starting to incorporate agentic AI and AI-enabled automation into cyber operations, moving beyond the earlier use of large language models for reconnaissance, coding and social engineering. That shift could reduce the time defenders have to detect and respond to attacks.
One case observed in the second quarter of 2026 showed how quickly such operations can unfold. Threat actors compromised a cloud resource, then planned, built and executed an agent-enabled mass credential-harvesting campaign in less than six hours.
Attackers are testing multi-agent frameworks that can manage scanning pipelines, handle operational errors and conduct credential harvesting with far less human involvement. The research describes this as an incremental shift, not a sudden jump to fully autonomous cyber attacks.
State-backed groups and criminal operators are using AI across several stages of the attack chain, including target reconnaissance, social engineering lures, malware obfuscation, vulnerability research and troubleshooting after gaining access to systems.
Researchers said adversaries are using both commercial and open-weight AI models to support vulnerability research, build exploit prototypes and develop malware. Even so, Google has not yet seen attackers deploy fully autonomous zero-day exploitation pipelines against real-world targets.
Instead, AI appears to be layered onto existing methods to increase speed and reduce the need for direct human input during an operation. For security teams, that means familiar attack techniques may arrive faster and at greater scale, even if the underlying tactics remain broadly recognisable.
Supply chain risks
The research also points to rising risks in AI-assisted software development and open-source software ecosystems. Google has tracked the financially motivated threat actor UNC6780, also known as TeamPCP, carrying out large-scale compromises affecting ecosystems including PyPI, npm and Docker Hub.
Those attacks included efforts to manipulate AI coding assistants and security scanners based on large language models. The techniques included prompt injection designed to influence how AI systems analyse malicious code, adding a new twist to software supply chain attacks that already concern developers and security teams.
By targeting tools developers increasingly use to write or review code, attackers may be trying to interfere earlier in the software creation process. The activity suggests that AI systems embedded in development workflows can themselves become part of the attack surface.
AI as target
Attackers are not only using AI tools but also targeting AI infrastructure directly. Google observed attempts to steal proprietary AI models, source code, prompts, API credentials and research, while compromised cloud environments were also used to run unauthorised AI workloads.
That activity indicates AI assets are becoming valuable targets in their own right. Motivations cited in the research include cyber espionage, extortion and theft of computing resources.
The findings draw on Mandiant incident response work, Google's broader tracking of threat actors and activity detected through its platforms and security systems. Taken together, the evidence suggests a cyber threat landscape in which AI is becoming both a tool for intrusion and an asset attackers want to steal or misuse.
Google Threat Intelligence Group said the trend is still evolving gradually rather than through a single dramatic leap. But the documented shift from AI-assisted tasks to more self-directed attack operations points to a practical change in how some adversaries organise and run campaigns.
In the cloud-based credential-harvesting operation completed in under six hours, the speed of execution offers a clear sign of that shift.