MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-08 · via BleepingComputer

Cybercriminals deploy autonomous multi-agent AI systems to automate credential theft at scale

Image via BleepingComputer
Image via BleepingComputer

Google's Threat Intelligence Group reports that threat actors are moving beyond simple AI coding assistants to deploy multi-agent frameworks that autonomously plan, execute, and troubleshoot attacks. In one incident, a financially motivated attacker compromised cloud infrastructure and used an AI chatbot with markdown instructions to build a mass credential-harvesting campaign in under six hours, managing vulnerability scanning, rotating IPs, and routing traffic through compromised environments. Another exposed command-and-control server, named Recon, was found managing over 23,800 harvested secrets in real time, while China-linked espionage groups are also experimenting with AI-assisted exploitation pipelines.

Expanded Detail

Google's Threat Intelligence Group documented a financially motivated actor who compromised cloud infrastructure and deployed an autonomous framework to build a mass credential-harvesting operation in under six hours. The system managed vulnerability scanning, rotated IP addresses, and routed traffic through legitimate compromised environments to evade detection.

Separately, an exposed command-and-control server named "Recon" was found managing over 23,800 harvested secrets, including API keys, with embedded AI agent instructions. While state-linked groups experiment with exploitation pipelines, GTIG notes fully autonomous zero-day discovery remains unobserved. Google's Gemini model detected several abuses, leading to account bans, though supply-chain attacks and stolen AI credentials persist.

Context

The shift toward autonomous multi-agent AI systems could significantly lower the technical barrier for launching large-scale credential theft, potentially accelerating the frequency and speed of breaches. Organizations may face shrinking response windows as attacks adapt in real time, while individuals could see a rise in identity theft stemming from harvested API keys and passwords. Defenders may need to leverage AI-driven countermeasures to keep pace with these evolving automated threats.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
CISA Issues Emergency Directive for Industrial Control Systems Under Threat · Cybersecurity
This summary is AI-generated and original to Mobble; the linked article is the authoritative source. Original headline: “Hackers build AI frameworks for widescale credential theft.” Browse more stories.