AI Agents: Threat Actors’ Rising Role in Cyberattacks
Threat actors are increasingly integrating AI agents into cyberattack operations, according to findings from the Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker.
The report highlights a shift toward automation in attack workflows, with AI systems handling tasks such as vulnerability identification, credential extraction, and real-time troubleshooting with minimal human oversight. This evolution is based on data from Mandiant incident response cases, threat actor tracking efforts, and analysis of active defense mechanisms. Researchers noted a progression from basic AI prompts to complex, multi-step processes where AI-driven agents manage interconnected functions.
Shift Toward Automation in Attack Workflows
A notable example involved a financially motivated threat group that exploited cloud infrastructure in Q2 2026 to execute a credential-harvesting campaign within six hours. The attackers utilized an AI coding chatbot alongside custom prompts and agent instructions to design, develop, and deploy the operation. The attack compromised thousands of third-party credentials, with the AI system autonomously managing vulnerability scans, troubleshooting issues, and implementing IP rotation to avoid detection. The attackers leveraged the victim’s cloud environment to route traffic through legitimate IP addresses, masking their activities.
Notable Example: Credential-Harvesting Campaign
Access to AI tools and computational resources has become a critical component of threat actor operations. The report emphasizes that acquiring premium AI models and high-performance computing infrastructure remains a significant barrier for adversaries seeking to scale AI-driven attacks. Researchers also identified an exposed command-and-control server containing a framework named “Recon,” which hosted over 23,800 harvested secrets, including API keys for cloud and AI services. The server’s directories, such as AGENTS.md and KNOWLEDGE.md, detailed configurations for autonomous agents capable of vulnerability research, infrastructure scanning, and targeted exploitation.
Access to AI Tools and Computational Resources
Cyber espionage groups have also experimented with AI-powered frameworks. A threat actor linked to the People’s Republic of China (PRC) developed a dynamic penetration testing system using Gemini, designed to analyze targets, adapt to unpredictable environments, and execute tasks. While the project remained in the development phase, researchers disabled the associated assets. Another PRC-linked group utilized AI development tools to create automated exploitation pipelines, leveraging models like Claude, Gemini, and Codex to generate exploit code, spear-phishing content, and debug scripts. Tools such as Burp Suite and Phalanx were employed for web application probing and automated exploitation, with Shai-Hulud used for command-and-control and credential extraction.
Cyber Espionage and AI-Powered Frameworks
Despite these advancements, the Google Threat Intelligence Group reported no confirmed instances of fully autonomous AI-driven attacks in the wild. However, the report notes a gradual shift in adversarial tactics, with threat actors using commercial and open-source AI models to convert public disclosures and delayed patches into exploit code. Researchers observed refinement of payloads in controlled environments, leading to the development of multi-stage exploit chains. The group reiterated efforts to enhance AI model security by incorporating threat intelligence into safety mechanisms and guardrails.
No Fully Autonomous AI-Driven Attacks
The findings underscore the growing intersection of AI capabilities and cybercrime, with threat actors increasingly adopting automated frameworks to enhance efficiency and evade detection. As AI tools become more accessible, the cybersecurity landscape faces evolving challenges in mitigating risks associated with autonomous attack systems.
